DaydayPDF
Privacy Policy
DaydayPDF processes PDF documents on your device. Free tools require no account, and basic traffic measurement never includes your documents or editing activity.
1. Scope and controller
This policy applies to the DaydayPDF website and progressive web app. The controller is operator or legal business name required before launch. Third-party websites are governed by their own policies.
2. Purposes, data and legal bases
| Activity | Data and purpose | Legal basis |
|---|---|---|
| Access and security | IP address, time, requested route, browser and OS, error and security logs | Service delivery and legitimate interests in security and reliability |
| On-device storage | PDF bytes, edits, shared files, viewing and shortcut settings | Performance of the user-requested editing and recovery service |
| Basic traffic measurement | Allowlisted route and fixed title, time, browser/device, approximate country or region, consent state | Legitimate interests in minimal service statistics; users may opt out in this browser |
| Advertising | Ad request, approximate region, browser/device and consent state; personalized identifiers only with consent | Legitimate interests in funding free service and consent where required |
| Google account | Firebase UID, Google provider ID, email, display name, photo URL, verification, creation and last sign-in times, IP and user agent | Subscription and account contract |
| Subscription and payment | Plan, status, period, payment provider customer/subscription/transaction IDs, amount, currency, time and terms version | Contract, legal obligations and dispute handling |
| Support | Email and content you submit | Responding to requests and legitimate dispute handling |
Google sign-in requests only basic profile information, not Google Drive, Gmail, or Contacts. We do not link PDFs to Firebase accounts and do not store raw card numbers or security codes.
3. PDFs, autosave and PWA sharing
- Selected files and generated results are processed in your browser and are not sent to our file storage servers.
- When autosave is enabled, source files and edits may be stored in IndexedDB on that device for recovery.
- A file shared to the PWA may remain temporarily in Cache Storage until the editor receives it, after which it is removed.
- Closing all documents or turning off autosave removes session data. You may also clear the site's browser data.
- Local storage is not cloud backup and can be lost if the browser or device is reset or cleaned.
4. Minimal traffic measurement
We use Google Analytics 4 only to estimate visitor counts and users active in the last few minutes. analytics_storage defaults to denied, so Analytics cookies and device identifiers are not created; only cookieless signals are sent. Counts are approximate.
- Query strings, URL fragments, referrers, filenames, document titles/content and PDF metadata are removed.
- The editor is always recorded as
/editor/with the fixed titleDaydayPDF Editor. - We send no custom click, editing, file-size or page-count events.
- Firebase UID and other account identifiers are never sent as Analytics
user_id. - Approximate country or region may be inferred from the connection; we do not request precise location or GPS.
Traffic measurement on this browser
5. Ads and consent
- Free pages may show Google AdSense ads. Without consent for identifiers, we use contextual or limited advertising.
- Where required, including the EEA, UK and Switzerland, a Google-certified consent management platform provides Accept all, Reject all and settings choices.
- Reject all disables analytics and ad cookies, user identification, personalized ads, ad storage, ad user data and ad personalization. Under advanced Consent Mode, identifier-free page pings may still contribute to approximate visit, active-user and country/region statistics. Use “Stop statistics” in Section 4 to stop those pings as well. Security, authentication, payment and on-device editor storage needed for a requested service are not optional consent purposes.
- Rejecting optional purposes does not block PDF tools. Ads are hidden while a valid ad-removal subscription is signed in.
6. Retention
| Data | Retention |
|---|---|
| On-device document session | Until all documents are closed or autosave is disabled |
| PWA shared file | Until received by the editor |
| Local settings and analytics choice | Until site data is cleared |
| Firebase Authentication | IP addresses generally for a few weeks; other account data until deletion, then normally removed from backups within 180 days |
| Contracts and payments | As required by applicable tax, accounting, consumer and dispute laws; in Korea, typically 5 years for contracts/payments, 3 years for disputes and 6 months for advertising records |
| Access/security logs | final Cloudflare and operator settings required |
| Support records | retention period required before launch |
7. Processors and international transfers
| Provider | Purpose | Location/retention |
|---|---|---|
| Cloudflare, Inc. | Hosting, delivery and security | contract and actual settings required |
| Google LLC — Firebase Authentication | Google sign-in and authentication | United States / Section 6 |
| Google LLC — Firestore and Cloud Functions | Account management and subscription entitlement | deployment region and retention required |
| Google LLC — Google Analytics | Minimal traffic measurement | Google processing locations / configured retention |
| Google LLC — AdSense and CMP | Ads and consent management | Google processing locations / actual ad settings |
| payment provider required | Recurring payment and refunds | contract and processing regions required |
| Google Fonts and jsDelivr | Fonts and fixed-version libraries | hosting and transfer details required |
These providers may process data outside your country under their applicable transfer mechanisms. You may avoid optional analytics and advertising transfers; refusing required authentication or payment processing means the optional account or subscription feature cannot be supplied.
8. Sharing and payment data
We do not sell personal data. We disclose it only to processors needed to provide the service, when you consent, or when law requires it. The payment provider handles raw card details; DaydayPDF retains only transaction references and subscription status.
9. Your rights and account deletion
Depending on your location, you may request access, correction, deletion, restriction, objection, portability, withdrawal of consent, or complain to a supervisory authority. Files stored only on your device must be removed using browser site-data controls.
Disconnecting Google access is not the same as deleting a DaydayPDF account. You may need to cancel an active subscription first. Records required by law may be retained separately for the required period.
10. Security
- On-device PDF processing rather than server file uploads
- HTTPS, content security policy, least privilege and access controls
- Allowlisted analytics fields and separation of accounts from documents
- Dependency version, license and security update management
11. Children
DaydayPDF is not directed to children. Accounts and subscriptions are intended for users aged 18 or the age of legal capacity in their country. A parent or guardian must be involved where local law requires it.
12. Contact and complaints
- Controller
- operator or legal business name required
- Privacy contact
- DaydayPDF operations
- daydaypdf@dayday.kr
You may also complain to the data protection authority in your country.
13. Changes
We normally provide 7 days' notice, or 30 days for material adverse changes. A notice does not replace separate consent where consent is legally required.