Privacy Policy
This policy explains how RevPDF processes documents, what it stores locally, when it connects to external services, and what those services may receive.
RevPDF does not automatically upload your documents, scanned pages, annotations, signatures, or recognised text to RevPDF-operated servers for processing. Document processing is performed locally on your device. If you intentionally share, export, open, or save a document using another application or cloud service, the selected provider may receive the document under its own privacy policy.
1. Summary of Local Processing
PDF editing, page organisation, merging, compression, conversion, redaction, comparison, scanning, and OCR recognition are performed locally on macOS, Windows, Linux, Android, and iOS. RevPDF does not operate a document-processing server and does not automatically send document content to RevPDF for those operations.
Local processing does not mean the app makes no network connections. Update checks, fonts, mobile advertising, app-store services, scanner components, and OCR model downloads can connect to the providers listed in Section 3. Those connections normally expose routine connection information and the requested resource, but are not designed to send the open PDF or its recognised text.
2. Information Stored on Your Device
RevPDF stores the following information locally to provide app features. RevPDF cannot remotely read or delete these local items.
| Locally stored information | Purpose | Retention |
|---|---|---|
| Documents and exported files | Open, edit, save, share, or export files at locations you choose. | Until you delete them from the selected device, drive, app, or cloud location. |
| Crash-recovery copies and a recovery manifest | Restore unsaved desktop work after an interruption. While editing, a recovery copy may be refreshed periodically. | Until a successful save, dismissal of the recovery prompt, deletion of app data, or uninstall. |
| OCR text cache | Avoid repeating recognition for the same page. | Older entries are removed after the on-disk cache exceeds 500 files. Remaining entries persist until cache or app-data deletion or uninstall. |
| Page thumbnails | Show previews and speed up document navigation. | Automatically limited to 50 files or 20 MB, whichever limit is reached first; the operating system may reclaim them, and app-data deletion or uninstall removes them. |
| Saved signatures and initials | Let you reuse a signature or initials. | Until you delete each saved item or uninstall or clear the app’s data. |
| Recent file paths, starred file paths, and macOS security-scoped bookmarks | Provide Recent and Starred lists and reopen selected files. | Recent files are limited to eight. Entries remain until removed or cleared by you, app-data deletion, or uninstall. |
| Downloaded fonts and OCR models | Improve font compatibility and allow offline OCR after setup. | Until the relevant cache or app data is deleted or the app is uninstalled. |
| Premium status and last store-sync time | Remember purchase entitlement and decide when to check it again. | While the app is installed, unless its local data is cleared. |
| Update-check time, skipped version, review-prompt counters and status, and app preferences | Throttle update checks, honour skipped versions, decide when to offer a store-review prompt, and remember settings such as theme and language. | Until the preference or app data is cleared or the app is uninstalled. |
| Website theme preference | Remember whether you selected the light or dark website theme in browser local storage. | Until you clear the site’s browser storage. The website does not use a RevPDF analytics service or RevPDF advertising cookies. |
3. Network Connections & Service Providers
The following table distinguishes automatic connections from connections caused by a feature you choose. “Potentially received” describes ordinary information visible to a provider; the provider may describe additional details in its own policy.
| Connection | When it happens | Purpose | Information potentially received |
|---|---|---|---|
| GitHub Releases API | Automatic: after app launch, subject to a six-hour throttle when a last-check timestamp has been stored. If no newer release is returned, some current builds may repeat the check on a later launch. You can also check manually. | Retrieve the current release version, notes, and download links. | IP address, request time, request headers, app/network information, and the requested RevPDF repository and release. |
| Google Fonts and GitHub’s Google Fonts hosting | Automatic and user-initiated: RevPDF checks its on-device font cache first; it does not search operating-system fonts. Opening a document starts background downloads of common compatibility fonts when they are not cached, and some script fallbacks download when needed. Choosing some uncached fonts displays a confirmation dialog. | Display and edit text with compatible fonts and cache those fonts for offline reuse. | IP address, request time, request headers, requested font family or file, and connection diagnostics. |
| Google Play services document scanner (Android) | User-triggered: when you start the scanner. Google Play services may then download scanner models, logic, interface components, or updates. | Provide the Android document-scanning interface and on-device image processing. | IP address, device and app information, requested scanner components, and service diagnostics. The component download is not a document upload. |
| Google AdMob (Android and iOS) | Automatic: the AdMob SDK is initialised on every mobile app launch, including while Premium status is still being loaded and for Premium users. Ad request: a non-Premium user completes certain operations for which an ad is enabled. | Initialise advertising services and deliver, measure, secure, and diagnose mobile ads. | IP address and IP-derived general location; advertising, app-set, device, account, or app identifiers where available; app launches; ad impressions, taps, clicks and interactions; and performance, crash, and diagnostic information. |
| Apple App Store or Google Play (mobile) | Automatic: product information is requested at app startup. Premium status may be synchronised on startup based on the locally stored status, pending-payment state, and last-sync time. User-triggered: when you buy or restore Premium. A purchase/restore action may also perform a connectivity check for google.com. | Display the local price, determine purchase availability, process or restore a purchase, and synchronise entitlement. | Store-account context, device and app information, product identifier, purchase status, transaction or purchase identifier, and store diagnostics. Apple or Google receives payment information; RevPDF does not receive full payment-card details. |
| Apple or Google in-app review service (mobile) | Automatic availability check: after certain successful actions when RevPDF evaluates whether to show its review prompt. User-triggered: if you choose to open the platform review flow. | Determine whether in-app review is supported and show the store-managed review interface. | IP address, store-account context, device and app information, review-service availability and diagnostics, and any rating or review you choose to submit. |
| Tesseract OCR model repository on GitHub (Windows and Linux) | User-triggered: on first OCR use if the English model is missing and you accept the download dialog. | Download the approximately 4 MB eng.traineddata model for offline OCR. | IP address, request time, request headers, requested model, and connection diagnostics. Document content and recognised text are not part of the request. |
| Google Firebase Hosting and GitHub release metadata | Automatic when you visit: Firebase Hosting delivers revpdf.com. The download page also requests public release metadata from GitHub. | Deliver the website, release links, and aggregate GitHub release-asset download counts. | IP address, browser user agent, requested URL or release, request time, and routine connection metadata. |
| External destinations you choose | User-triggered: when you open a web link, follow a link embedded in a PDF, share, export, or save through another application or cloud service. | Carry out the action you selected. | The destination receives routine connection metadata and may receive the document or other content you selected. |
Relevant provider policies include the GitHub General Privacy Statement, Google Privacy Policy, and Apple App Store & Privacy notice.
4. Advertising
On supported Android and iOS versions, RevPDF uses Google AdMob. The Google Mobile Ads SDK may automatically collect and share IP address and IP-derived general location, device and application identifiers, advertising identifiers where permitted, app launches and other product interactions, ad impressions and interactions, and diagnostic or performance information. Google describes the purposes as advertising, analytics, and fraud prevention. See Google’s Mobile Ads SDK data disclosure.
RevPDF submits a standard AdMob ad request. Depending on region, device and account settings, available consent signals, and Google’s configuration, Google may return personalised, non-personalised, or limited ads. Non-personalised and limited ads can still use an IP address and other information needed to deliver, measure, secure, and report the ad.
The current app initialises the AdMob SDK at mobile startup before Premium status is fully known. This means initialization may occur for a Premium user even though RevPDF does not request or display an ad after Premium status is recognised. Current builds also do not expose a dedicated in-app Google “Privacy choices” control or an App Tracking Transparency prompt. You can use your device’s advertising and privacy settings and Google My Ad Center to manage available Google advertising controls. This policy is a disclosure and is not a substitute for consent where consent is legally required.
5. Purchases & Premium Status
On mobile, RevPDF connects to Apple’s App Store or Google Play to retrieve product information, determine billing availability, process and complete a purchase, restore purchases, and synchronise Premium status. Product information is requested when the app starts. Entitlement checks may also occur on later app starts based on the locally stored status, pending-payment state, and last-sync time; that timestamp is used to avoid unnecessary checks for recently confirmed Premium users.
The store sends product and purchase status and may provide a transaction or purchase identifier. RevPDF processes those identifiers while handling the purchase update but does not send them to a RevPDF-operated purchase server. RevPDF stores the resulting Premium status and last synchronisation time locally. Apple or Google processes the store account and associated payment information; RevPDF does not receive full payment-card details.
6. Scanning & OCR
OCR recognition and scan image processing are performed locally on the device. Scanned pages are returned to RevPDF as local files so you can create or save a PDF.
- Android scanner: RevPDF uses Google Play services’ document scanner. Google Play services may download scanner models, interface components, logic, or other resources before first use or when those components are updated. This download does not mean that RevPDF uploads the scanned document for processing. If the Google scanner is unavailable, the app may use its local fallback scanner.
- Android OCR: Recognition uses Google ML Kit on the device. OCR results may be stored in the local OCR cache described in Section 2.
- iOS and macOS OCR: Recognition uses Apple’s on-device Vision framework.
- Windows and Linux OCR: Recognition uses Tesseract. If the English OCR model is missing, RevPDF asks before downloading it from the Tesseract repository on GitHub. After download, recognition runs locally and the model is reused offline.
7. Sharing, Exporting & Annotation Metadata
When you intentionally share, export, open, or save a document through another application, email provider, file-sync service, cloud drive, printer, or website, the selected destination may receive the document and related metadata under its own privacy policy. RevPDF does not control that provider’s retention or further use.
On desktop platforms, RevPDF may read the operating-system account name and use it as the default author name for newly created annotations. The name is embedded in annotation metadata inside the PDF and may be visible to anyone who receives the document or opens it in another PDF viewer. It is not sent separately to RevPDF.
8. Retention & Deletion
The retention criteria for local information appear in Section 2. RevPDF provides item-level controls for removing recent-file entries and saved signatures or initials. The current app does not provide one control that clears every private-data category at once. Your operating system’s app-data controls or uninstall process can remove app-private caches, models, recovery data, preferences, and saved reusable items; documents saved outside the app’s private storage must be deleted from their chosen location separately.
RevPDF does not receive copies of provider network logs and cannot delete them. GitHub, Google, Apple, email providers, cloud services, and other destinations retain information according to their own policies. Support emails are kept only as long as reasonably needed to respond, maintain necessary records, resolve disputes, prevent abuse, or meet legal obligations.
9. Purposes, Legal Bases & International Processing
The purposes for each external connection are listed in Section 3. GitHub, Google, Apple, email providers, and destinations you choose may process information outside your country, including in the United States and other locations where they or their service providers operate. Their privacy notices describe their safeguards and retention practices.
Where applicable law requires a legal basis, actions you specifically request, such as a purchase, restore, scanner launch, manual model or font download, share, export, or external link, are processed as necessary to carry out your request or perform the relevant purchase contract. Consent is used where RevPDF expressly asks for it and where the law requires it. Automatic update checks are used to provide version, compatibility, and security information. Advertising may require consent or another valid basis depending on your location and the type of ad. Because the current app initialises AdMob without an in-app consent gate, this policy does not represent that the existing behaviour satisfies every jurisdiction’s consent requirements.
10. Your Privacy Rights
Depending on your location, you may have rights to request access to or correction or deletion of personal information, object to or restrict certain processing, withdraw consent, or complain to a privacy regulator. Most document and app data is held only on your device, so RevPDF cannot access, correct, or delete it remotely; use the controls described in Section 8.
Send a request to editor@revpdf.com with enough detail to identify the relevant interaction.
11. Children
RevPDF is not designed to collect personal information directly from children and does not ask users to create an account or state their age. Because document content is processed locally, RevPDF does not knowingly receive a child’s document contents for processing. The ad-supported mobile version uses Google AdMob and does not currently include an in-app age gate. A parent or guardian should supervise a child’s use and review the relevant device, store, and Google advertising settings.
12. Security
RevPDF uses app-private or app-support storage locations for recovery data, caches, downloaded resources, purchase status, and saved reusable items, and supported external requests use encrypted HTTPS connections. RevPDF does not claim to add its own encryption to every local file or cache. Device security, operating-system storage protections, backups, and the security of export destinations remain important. No storage or transmission method is completely risk-free.
13. Policy Changes
RevPDF may update this policy when app behaviour, providers, or legal requirements change. Updates will be published on this website. You should review this policy from time to time to stay informed about any changes.
14. Contact Details
Privacy email: editor@revpdf.com
If you email RevPDF, the email address, message, attachments, and related delivery metadata are received through the relevant email providers and used to answer the enquiry, keep necessary support records, prevent abuse, and meet legal obligations.