// security & privacy
Security at PDFized
Your documents stay yours. You upload files to PDFized precisely because they contain sensitive data – a responsibility we take literally: encrypted, private, never sold, and yours to delete. This page explains exactly how.
$ encrypted · private · deletable
// how it works
What Happens to a File You Upload
Four steps, from the moment you add a file to the moment you remove it.
- 01
Encrypted in transit
Your file travels from your browser to PDFized over an encrypted connection (TLS), so it can't be read on the way.
- 02
Stored privately, encrypted at rest
It lands in your personal dashboard, hosted on Google Cloud and Supabase. Only your account can open it, along with anyone you choose to give access to. Nothing is public by default.
- 03
Redacted in a new copy – your original stays with you
PDFized scans the document for names, numbers, and other sensitive details and shows you each finding to review. When you apply the redaction, a new version is created in which that data is deleted from the file itself, not covered. Your original and the findings stay in your dashboard, so you can adjust and export again – until you delete them.
- 04
Deleted on your command
Delete any document whenever you like. It leaves your dashboard right away and is then permanently removed from our storage on a scheduled basis.
// transparency
What We Store – and Why
To redact your documents and let you come back to them, PDFized keeps the following.
- 01documents
Your documents
The PDFs you upload and the processed versions created from them – including the redacted copies – plus basic file details such as name, size, and page count.
- 02findings
Analysis results
What was found in each document: the sensitive items flagged, how they were classified, and the processing history. This is what lets you review, adjust, and keep an audit trail.
- 03account
Account details
Your profile, your organization membership and roles, and your subscription and billing information.
- 04logs
Technical records
Logs of automated processing runs and of how the service is used, kept for debugging, security, billing, and improving the service.
// the promises
What We Never Do – and What We Always Do
- 01never
Sell your documents or your data
We don't sell, rent, or trade your files or personal information – not to advertisers, not to data brokers, not to anyone.
- 02never
Make your files public by default
Files live in your private dashboard; nobody else sees them unless you give access or export them yourself.
- 03never
Hold on to deleted files indefinitely
Deleted documents are scheduled for permanent removal – not archived.
- 04never
Leave redacted text recoverable
Redaction removes the text itself from the file – it doesn't just draw a black box over it.
- 01always
Encrypt in transit and at rest
TLS on the way in, encryption where it rests.
- 02always
Use contracted, enterprise-grade infrastructure
Google Cloud and Supabase act as our data processors under data processing agreements and handle your data only on our instructions.
- 03always
Leave you in control
Delete any document, any time; organization admins can set retention policies for their teams.
- 04always
Keep you the owner
You retain all rights to what you upload. We process your documents only to provide the service.
Questions about security? Write to team@pdfized.com – a real person answers.
// access & visibility
Who Can See Your Documents
Your files are private to your account. Access beyond that is something only you can grant.
- 01always
You
Your documents live in your own dashboard, behind your sign-in.
- 02only if you choose
People you give access to
Invite a colleague or export a file – it's your decision, every time.
- 03never by default
Everyone else
Nothing is public, and nothing is passed to advertisers or data brokers.
Behind the scenes, Google Cloud and Supabase host the service as our data processors, under data processing agreements, and handle your data only on our instructions.
// deletion
What Happens When You Delete a Document
Deleting a document happens in stages, and you start it whenever you like.
- [01]You delete a document. Any document, any time, from your dashboard.
- [02]It's gone from your dashboard. Right away – it no longer appears in your account.
- [03]It's permanently removed. From our storage, on a scheduled basis. A limited set of records may be kept where law or audit requirements demand it.
Organization admins can set retention policies for their teams. If you close your account, your documents are scheduled for deletion the same way.
// compliance
For Teams With Compliance Obligations
PDFized is built with GDPR, UK GDPR, and CCPA requirements in mind. Our infrastructure providers act as data processors under data processing agreements, and international transfers rely on the UK Extension to the EU–US Data Privacy Framework and International Data Transfer Agreements.
You can request access to, correction of, or deletion of your personal data at any time by writing to team@pdfized.com. And redacting a document before it leaves your hands is itself the data-minimization step these laws point toward. The full detail is in Sections 5–7 of our Terms & Conditions.
// private by design
Redact with confidence
Upload a document knowing exactly where it lives, who can see it, and how to remove it. Free, in your browser.
// get started
Email us at
team@pdfized.com