Privacy Policy
Zero Document Retention
PDFKite V4 is designed so PDFKite application servers do not receive or store your document bytes. Standard tools process the selected file inside your browser. Native features use the optional PDFKite Local Agent running on your own device or organization-managed computer.
What can reach PDFKite servers?
Normal web requests can include ordinary technical metadata such as IP address, browser information, requested URL, and security logs. If an organization uses PDFKite Enterprise signing workflows, the metadata service can retain envelope IDs, document names, SHA-256 hashes, signer email addresses, consent events, timestamps, IP addresses, user agents, and audit events. It does not accept the PDF itself.
Customer-controlled storage
Enterprise workflows can point signers to a document stored in the customer's own SharePoint, S3, Azure Blob, file portal, or another customer-controlled location. PDFKite stores a cryptographic hash and workflow metadata so the browser can verify the signer selected the intended document.
Local Agent
The Local Agent binds to the loopback interface and processes files on the user's computer. Some native command-line tools may use the operating system temporary directory during processing; PDFKite's hosted systems are not involved.
Analytics and advertising
Analytics or advertising scripts, if enabled by the site owner, must not be given document contents. PDFKite's document-processing code does not expose selected file bytes to those services.