Privacy

Privacy Policy

PDF2MD is designed as a lightweight, privacy-conscious utility. It does not require an account, does not use a database, does not use OCR, and does not send documents to AI or LLM APIs.

This page is a practical privacy notice for the project. It is not legal advice. If you operate PDF2MD for a business or public audience, review it with your own legal/privacy adviser.

What data is processed?

Uploaded PDFs

When you convert a file, the PDF is sent to the backend API for temporary processing. The app returns Markdown and deletes the temporary upload after the request finishes.

Technical request data

The hosting providers may process technical data such as IP address, request time, browser information, error logs, and security logs.

Document content

A PDF may contain personal data if you upload names, addresses, emails, reports, contracts, or other identifiable information.

Purpose and legal basis

The purpose of processing is to provide the PDF to Markdown conversion service, keep the service secure, debug errors, prevent abuse, and maintain basic operational reliability.

If you operate this website in the EU or offer it to users in the EU/EEA, GDPR/AVG may apply. The likely legal basis for core conversion processing is that the processing is necessary to provide the requested service. Security and abuse-prevention logs may rely on legitimate interests. If you add optional analytics or marketing scripts later, review whether consent is required.

Hosting providers

Cloudflare Pages

The frontend is hosted as a static website on Cloudflare Pages. Cloudflare may process visitor IP addresses and technical request data to deliver and secure the website.

Render

The conversion API is hosted on Render. Uploaded PDFs are processed by the Render-hosted backend during conversion. Render may also keep platform logs for operational purposes.

Cloudflare and Render may process data outside the EU/EEA depending on their infrastructure and account settings. If GDPR applies to your deployment, review their data processing terms and international transfer safeguards.

Retention

PDF2MD does not intentionally store uploaded PDFs after conversion. Temporary files are deleted when the request finishes. Technical logs may be retained by the hosting providers according to their platform settings and policies.

Analytics and cookies

The default project does not include Google Analytics and does not require analytics cookies to run. The codebase includes placeholders for Plausible Analytics or Cloudflare Web Analytics, but they are not required for the converter to work.

If analytics are added later, the privacy policy should be updated. If cookies or similar tracking technologies are used, EU cookie/ePrivacy rules may require clear information and, for non-essential tracking, consent before tracking starts.

Security and sensitive documents

Do not upload sensitive, confidential, medical, financial, legal, or business-critical documents unless you trust the specific deployment and hosting setup. For sensitive workflows, self-host both the frontend and backend in an environment you control.

Your rights

If GDPR/AVG applies, users may have rights to access, correction, deletion, restriction, objection, portability, and complaint with a supervisory authority. Because PDF2MD does not use accounts or a database, there may be little or no stored user content after a conversion request completes.

Add your contact email here before production launch:

Contact: replace-with-your-email@example.com

Related pages