Privacy Policy
The short version: tools marked as browser-based never send your document anywhere, and we do not sell data about you.
Your documents
Every tool page shows a badge saying how that tool handles your file, and the badge is generated from the tool's actual processing mode rather than written by hand — a tool cannot display "processed on your device" while uploading your file.
For browser-based tools, your file is read by JavaScript running in your own browser tab. It is not transmitted to iBuildPDF, and we have no technical means of seeing it, its name, or its contents.
If a server-processed tool is ever published, its page will say so plainly before you select a file, the upload will use an encrypted connection, the file will be stored under a random name in a non-public location, and it will be deleted automatically after a short, stated retention window.
What we do collect
If analytics are enabled on this site, we record coarse usage events: which tool page was viewed, whether processing succeeded or failed, roughly how large the input was as a bucket such as "10-50mb", and roughly how long it took. These exist so we can find tools that are failing for people.
Filenames, file contents, extracted text and PDF metadata are never included in those events. That restriction is enforced in code by an allow-list of permitted fields, not only by policy.
Standard web server logs (IP address, user agent, requested URL, timestamp) are retained by our hosting provider for operational and security purposes.
Messages you send us
If you use the contact form, the name, email address, topic and message you type are stored so we can reply. Alongside them we store a salted, one-way hash of your IP address — not the address itself — which is only used to limit how many messages one sender can submit in an hour, and a numeric score estimating how spam-like the message looks.
The notification email sent to us when you submit the form also includes the technical details of that single request: your IP address, your browser and operating system as your browser reported them, the page you came from, and the country your network provider is in if our CDN supplied it. That is the same information any web server records about a visit, it is not added to the stored record, and we do not look it up anywhere or combine it with anything else.
None of this is used for marketing and none of it is shared with third parties.
Cookies and third parties
iBuildPDF does not set advertising or tracking cookies of its own. The PDF libraries the tools depend on are loaded from a public CDN, which will see your IP address as part of serving those files — this is the same arrangement used by a very large share of the web.
If advertising is enabled, the ad provider may set its own cookies and is governed by its own privacy policy.
Signing in with Google or Apple
If you choose "Continue with Google" or "Continue with Apple", we ask that provider for two things and nothing else: a permanent identifier for your account with them, and your name and email address. We do not ask for, and cannot obtain, access to your Calendar, your Contacts, your Gmail, your iCloud or anything else you keep with them. Google Drive is the one exception, it is not part of signing in, and the next paragraph is about it.
Google Drive is separate, optional, and asked for only when you use it. If you press a Google Drive button on a tool page, Google asks you to grant one permission, called drive.file. It allows this site to open the files you hand it through Google's own picker, and the files it creates. It does not allow this site to list, browse or search your Drive: there is no request we can make that returns a file you did not choose. Signing in with Google does not grant it, and you can use every tool here without ever granting it.
The permission produces an access token. That token is created by Google's script inside your browser tab, is held in a variable there, and is never sent to our server, never written to a cookie or to your browser's storage, and discarded when you close the tab. For a tool that runs in your browser, the file goes from Google to your browser and back, and our server is not in the path at any point. For a tool that runs on a server, the file is sent to the processing server exactly as it would be if you had chosen it from your device, and the note on that tool's own page says so. Nothing from Google loads on a page until you press one of those buttons.
We store the identifier, the address, and whether the provider told us the address was verified. The identifier is what actually signs you in — the email address is only a label, which is why changing your address at Google does not lose you your account here.
Apple lets you hide your real address and give us a @privaterelay.appleid.com one instead. That works completely; we store the relay address exactly as we would any other and do not attempt to resolve it. If you give us no address at all, the account still works.
We never receive your password at the provider. The sign-in itself gives us no token that can act on your account there; the only token that ever exists is the Drive one described above, it is created only if you ask for it, and it stays in your browser. Signing out of iBuildPDF signs you out of iBuildPDF only — it does nothing to your Google or Apple account. Disconnecting a provider from your sign-in settings, or deleting your iBuildPDF account, removes what we hold about that connection. To withdraw the Drive permission itself, remove iBuildPDF from the third-party access list in your Google account.
Choosing this is entirely optional: you can use an email address and password instead, and every tool on the site works with no account at all.
Your rights and how to reach us
You can ask what we hold about you, ask for it to be deleted, or object to processing, by writing to us through the contact page. Because browser-based tools never receive your documents, there is usually nothing of yours for us to hold in the first place.
Last reviewed: September 16, 2026