Privacy Policy
Last updated: July 2, 2026
1. Overview
This policy explains how PDF To Book ("we", "us") collects and processes personal data when you use our PDF-to-EPUB conversion service. We act as the data controller for the data described here. Contact: support@pdftobook.ai.
2. Data we collect
- Account data — email address, name, and authentication identifiers, managed through our identity provider (Clerk).
- Your documents — the PDF files you upload and the EPUB files we generate from them.
- Conversion metadata — file names, page counts, job status, timestamps, and processing costs.
- Payment data — purchases and credit balance. Card details are handled entirely by Stripe; we never receive or store your card number.
- Technical data — server logs (IP address, request metadata) used for security and troubleshooting.
We use only essential cookies: authentication session cookies set by Clerk. Your theme preference is stored locally in your browser. We do not use advertising or third-party analytics cookies.
3. How your documents are processed
Conversion is fully automated. Your PDF is stored in Google Cloud Storage (United States), its text is extracted by Mistral AI's OCR service, and the content is restructured by Google's Gemini models via Vertex AI. These providers do not use your content to train their models; Mistral may retain content for up to 30 days for abuse-monitoring purposes. Our staff does not read your documents except where strictly necessary to resolve a support request you raise or to investigate abuse.
4. Why we process your data (legal bases)
- Contract — operating your account, converting your documents, processing payments.
- Legitimate interest — securing the Service, preventing abuse, measuring and improving conversion quality in aggregate.
- Legal obligation — keeping billing and tax records.
5. Service providers
We share data with the following processors, only to the extent needed to run the Service:
| Provider | Purpose | Location |
|---|---|---|
| Clerk | Account authentication and management | United States |
| Stripe | Payment processing | United States |
| Google Cloud Platform | File storage, conversion infrastructure, and AI processing (Vertex AI / Gemini) | United States (storage and infrastructure); AI requests routed on Google's global infrastructure |
| Mistral AI | OCR text extraction from your documents | European Union |
| Neon | Application database | United States company; database hosted in the EU (Frankfurt, Germany) |
| Ably | Realtime conversion progress updates | United Kingdom (global delivery infrastructure) |
We do not sell personal data and do not share it with advertisers.
6. International transfers
Your files are stored in the United States, our database is hosted in the European Union, and AI processing requests are routed on Google's global infrastructure, so data moves between regions as described above. Transfers outside the EU/UK rely on recognized safeguards: the EU–US Data Privacy Framework where the provider is certified, or Standard Contractual Clauses.
7. How long we keep data
- Documents — uploaded PDFs and generated EPUBs are kept while your account is active so you can re-download them. When you delete a conversion, its files are permanently removed within 30 days.
- Account data — kept while your account is active. When you delete your account, your documents and personal data are erased within 30 days.
- Billing records — retained for as long as required by applicable tax and accounting law, in anonymized form where possible.
- Technical logs — retained for a limited period for security and cost-accounting purposes, then deleted.
8. Your rights
Subject to applicable law (including the GDPR if you are in the EU/UK), you have the right to access, correct, delete, and receive a copy of your personal data, to restrict or object to processing, and to withdraw consent where processing is based on consent. To exercise any right, email support@pdftobook.ai — we respond within 30 days. You can also delete individual conversions directly from your dashboard. If you believe we have mishandled your data, you may lodge a complaint with your local supervisory authority.
9. Security
Data is encrypted in transit (TLS) and at rest. Access to production systems is limited to what is necessary to operate the Service. File downloads use short-lived signed URLs scoped to your account.
10. Children
The Service is not directed at children under 16, and we do not knowingly process their data.
11. Changes to this policy
We may update this policy as the Service evolves. For material changes we will give notice through the Service or by email. The date above always reflects the current version. See also our Terms of Service.