What we do not collect
- Any PDF content or filenames you open, merge, encrypt, or convert
- PDF passwords you enter
- Your AI service API keys (kept only in your phone's secure storage, never backed up to any cloud)
- The questions you ask AI and the answers it gives
This app has no account system and no server of ours that could receive the data above.
Where your document goes
Only when you actively use an AI summary or Q&A feature does that document travel directly from your phone to the AI provider you selected, using your own API key. The transfer never passes through us. How each provider handles the document depends on its own terms, which are outside our control; the app tells you this clearly before your first use.
- Google Gemini: small files are sent inline with the request; larger files are first staged in Google's Files service (under your own Google account) and may be retained by the provider under its own policy for up to 48 hours before automatic deletion — the app also actively requests deletion after receiving the response. Terms
- OpenAI: the document is first uploaded to your own OpenAI account (Files); the app actively requests deletion after receiving the response, and requests are sent with "do not store the response" (store=false). Separately, OpenAI also applies its own abuse-monitoring retention to data submitted via the API, which may be retained by the provider under its own policy for up to 30 days, independent of the app's deletion request. Privacy Policy
- Anthropic Claude: larger files are first staged in your own Anthropic account (Files); Anthropic's staged files do not expire automatically — the app actively requests deletion after receiving the response, and will warn you if that deletion fails so you can remove it yourself from the Anthropic console. Anthropic may likewise retain data for up to 30 days for abuse-monitoring purposes under its own policy. Privacy Policy
All three AI providers have their own retention rules for data submitted via their APIs (beyond the file-staging above, there is typically a separate, short-term retention layer used for abuse detection); details are governed by each provider's current terms. We deliberately avoid claiming that no data is retained at all, which we cannot guarantee — instead we always say data "may be retained by the provider under its own policy."
Signature strokes, on-device video, and signing metadata never leave your device
This is a separate matter from "where your document goes" above. The signature strokes (pen-stroke coordinates), on-device video recording of the signing process, and signing metadata (timestamp, optional location) produced by the image-signature feature stay on your phone only — they never leave your device, are never sent to any AI provider, and are never sent to us or any third-party server. Even if you later run an AI summary or Q&A on the same PDF, the AI only ever sees the document content — never the signature strokes, the recording, or the signing metadata. The recording is only written to your photo library if you actively tap "Save to Photos" on the playback screen; even after that, it still never gets sent to any server.
What we do actually receive
Full disclosure: in the two situations below, the app connects to our own server or a service we use, and that connection leaves a log.
- Version check: on launch, the app reads a configuration file (`app_config.json`) from pdfgenie.autoit.studio, used to warn you about a critical issue or to temporarily tighten the file-size limit. This request carries ordinary connection metadata (IP address, User-Agent, device type, app version), which our web server logs. This request never includes any document content.
- Crash diagnostics: when the app crashes or hits a serious error, diagnostic data is sent to Sentry (Functional Software, Inc.; data stored in the United States), our crash-reporting service. This includes: device model, OS version, app version, the error stack trace, and an event ID; because this is a network connection, Sentry's servers also receive your IP address just like any website would. The app is designed so a crash report never contains document content, filenames, passwords, or API keys; any recorded action is limited to a coarse level such as "what action was performed, roughly how many pages." We use crash notifications only to fix bugs, never for anything else.
These connection logs are used for operations and abuse prevention only — never to analyze your behavior, and never shared with any third party.
Advertising
This version contains no advertising and does not use any advertising identifier (such as a Google Advertising ID).
Permissions
The app requests the following permissions from your device's OS the first time the related feature is used; here is exactly what each one is for:
- File access: opening and saving PDFs goes through the system file picker, a built-in OS mechanism that does not require a separate runtime permission.
- Camera (in use): used by the image-signature feature — to record video of the signing process, and to photograph a stamp/seal image.
- Microphone (in use): records audio together with the signing video, as part of the signing evidence; it is never transcribed or used for speech recognition.
- Location (in use, optional, off by default): only activates if you turn it on yourself in Settings, and is used solely to write location information into the on-device signing metadata; as described above, this information never leaves your device.
- Photo library (in use): lets you pick a stamp image or an existing signature image; an exported PNG is saved back to your photo library (PDF files go through ordinary file storage, not the photo library). The signing video recording is only written to your photo library if you actively tap "Save to Photos" on the playback screen.
- Network (in use): used only for the AI service you actively choose to use, the version check, and crash diagnostics, all described above.
Data retention and deletion
The documents, passwords, keys, signature strokes, and recordings that live on your phone are removed once you delete the app. We never hold a copy of your document, so there is no "request us to delete your document" process to speak of. Crash diagnostic data is automatically deleted from Sentry after 90 days; to request earlier deletion, email info@autoit.studio with the event ID shown in the app. Files staged in your own AI provider account (see "Where your document goes" above) expire under that provider's own policy, or you can delete them yourself from that provider's account console — deleting the app has no effect on them.
Children
This app is not directed at children and does not knowingly collect personal data from children.
You may be handling someone else's personal data
Reminder: documents you send to an AI provider may contain another person's personal data. How you collect, retain, and use such data is your own responsibility under the laws that apply to you; please confirm you are entitled to do so before sending.
Changes
If this policy changes, we will update the "last updated" date on this page. Material changes will also be announced inside the app.