PDFBro privacy policy

Last updated

PDFBro processes your documents on your device and never uploads them. It has no account, no analytics, no telemetry, no crash reporting and no ads. The only time it goes online is for the Pro license, with 0d.ae; without a license activated on your device it makes no network requests at all, except loading prices when you open the Upgrade screen.

What stays on your device

  • Your documents. Every PDF and image you open is processed on your device by the libraries built into the app (PDFium, qpdf, Tesseract on Windows and Android, Apple's Vision framework on iPhone, iPad and Mac). Files are never uploaded: not to 0d.ae, not to anyone.
  • Working copies. While a tool runs, PDFBro writes intermediate and result files into its own temporary folder. Results stay there after you save or share them, and so do copies of your files: on phones the files you choose, on Android also a copy of each result you share or open, on a Mac the files you drag in from Mail or a browser. Every temporary file is deleted at the first start after it is a day old. Files that other apps hand to PDFBro on a phone ("Open with", the share sheet) are copied into PDFBro's private cache and removed when PDFBro starts again (on Android also when you close it).
  • Text recognition data. On Windows and Android, the language data for text recognition (Tesseract) is copied from the app into its own folder on your device on the first start (on Windows, the local application data folder).
  • Settings. Theme, language, where to save results and the default OCR languages are stored in the app's local preferences (on Windows, a file in the local application data folder, never the roaming profile that some company networks copy to other computers).
  • Saved signatures. If you choose to keep a signature for reuse, it stays on your device only (on Windows in the settings file in the local application data folder, on Android in the app's local preferences, on iPhone, iPad and Mac in the Keychain, for this device only). You can delete it at any time under "Your signatures" in Sign PDF.
  • License state. After activation, the license token and the last license details are kept in protected storage: on Windows encrypted with your Windows account (DPAPI), on Android encrypted with a key in the Android Keystore, on Apple devices in the Keychain, for this device only. The license key itself is not stored. A device key (a cryptographic key pair) is created in the platform's keystore; its private half cannot be exported (on Apple devices without a Secure Enclave, it is kept in the Keychain for this device only).
  • Android backups are disabled for PDFBro, so none of the above is copied to cloud backups.

What PDFBro sends, and when

PDFBro has no analytics, no telemetry, no crash reporting, no ads and no account. It does not check for updates by itself. The only network traffic is the 0d.ae license protocol, over HTTPS to https://0d.ae/api/v1:

When Request What is sent
You open the Upgrade screen GET /products/pdfbro/plans Nothing personal (the app's language, for the plan names)
You activate a license key POST /activate The license key you typed; the device key's public key and its id; a device fingerprint (a one-way hash of the system's device identifier, specific to PDFBro); the platform (Windows, macOS, Android or iOS); the device name; the app version; the operating system's name and version; a time stamp, a random nonce and a signature
Once a day while a license is activated on this device, also after it expired or stopped covering PDFBro, so that a renewal is picked up ("Deactivate on this device" stops it); at start when the last check is over an hour old; after a failed check, again after 1, 5 and 30 minutes; and when you press "Check now" POST /validate The license token, the app version, a time stamp, a nonce and a signature
You open the list of devices on the License screen POST /status The license token, a time stamp, a nonce and a signature
You open "Your license also includes" POST /entitlements The license token, a time stamp, a nonce and a signature
You deactivate or move this device POST /deactivate The license token, a time stamp, a nonce and a signature

Every request also carries the app name and version (User-Agent: PDFBro/<version>) and the product code (pdfbro).

Without a license activated on this device, PDFBro makes no network requests at all, except loading prices when you open the Upgrade screen. Buying opens your web browser on 0d.ae; the purchase happens there, not in the app. The App Store and Google Play versions never load prices: they show no prices and no purchase links, so without an activated license they make no network requests at all.

Like any web server, 0d.ae sees the IP address of each request. What the license server keeps (licenses, and activations with the device key's public key, the device fingerprint, the device name, platform, app version, operating system and last check time) is described in the 0d.ae privacy policy. You can see and release your devices in your account.

Permissions

  • Windows and macOS: no special permissions. On macOS, PDFBro runs in the App Sandbox with network access (for the license) and access to the files you choose.
  • Android: Internet (for the license) only. Files are opened and saved through the system file picker.
  • iOS: no permissions, except that iOS asks once before PDFBro adds images to Photos when you choose Save Image in the share sheet. Files come from the Files app, the share sheet or the system picker.