Privacy policy
What PDFMint stores, for how long, and who else touches it. This was written from the database schema and the code that deletes things, not from a template.
1. Controller
The controller for the processing described here is:
| Company | productivity-boost.com Betriebs UG (haftungsbeschränkt) & Co. KG |
|---|---|
| Address | Reichenbergerstr. 2, 94036 Passau, Germany |
| Represented by | Florian Standhartinger |
| info@productivity-boost.com | |
| Telephone | +49 178 1981631 |
See also the imprint.
2. What is stored, and for how long
Everything below is in one PostgreSQL database. The only analytics on this site is the first-party visitor statistics described below. There is no advertising network, tracking pixel or third-party script. The public pages serve their fonts from this site.
Visitor statistics
The server counts page loads of its own pages as daily totals, per page and per referring website (host name only). What is stored is the date, the page path, the referring host and two counters. Not stored: your IP address, your user agent, a cookie, an identifier, your account or a fingerprint. No profile is built and unique visitors are not counted. Nothing is placed on your device. Browsers that send Global Privacy Control or Do Not Track are not counted. Automated clients are filtered as far as they are recognisable. Totals are deleted after 13 months. Only the operator can see them.
| Data | Why | Kept for |
|---|---|---|
| Email address, password hash | To let you sign in and to identify your account. The password is stored only as a bcrypt hash; the password itself is never written down. | Until you ask for the account to be deleted. |
| API keys | Stored only as a SHA-256 hash plus the first 16 characters, so a key can be recognised and listed but never read back — not by support, not by the operator. | Until revoked; revoked keys keep a timestamp. |
| The content you send to be rendered (HTML, Markdown, a URL, or a template) | For a normal synchronous request it is held in memory only for the render and is never written to the database. For an asynchronous request ("async": true) the whole request body is stored, because the job has to survive a restart. |
Synchronous: not stored. Asynchronous: deleted 7 days after the job finishes. |
| Generated files (PDFs, images) | Only when you ask for a hosted link instead of the bytes. The file itself is stored so the link works. | 60 minutes by default, at most 7 days, whichever you set. A reaper deletes expired files continuously. |
| Saved templates | The HTML you chose to store under a name. | Until you delete the template. |
| Usage records | One row per request: what kind, page count, duration, whether it succeeded, the error code if not, and a coarse label for the kind of client it came from (for example curl, n8n or browser; derived from the user agent, which itself is not stored). No document content and no request body. | Kept, so quota and the status page are accurate. |
| Login sessions | A random session id in a cookie so the dashboard knows who you are. | 30 days, or until you sign out. |
| Stripe customer and subscription ids | To connect your account to your subscription. | Until the account is deleted. |
| Visitor statistics (daily totals) | Page loads of this site's own pages, counted per page and per referring host. No IP address, no user agent, no identifier is stored — see Visitor statistics above. | Deleted after 13 months. |
| Password-reset data | When a password reset is requested: a hash of the one-time token, its expiry, and the time of the request (used to allow at most one reset email per minute). | The link works for 30 minutes. Token hash and expiry are cleared when the link is used; an unused one stays on the account, unusable, until the next reset request replaces it. The request time stays with the account. |
| Demo usage counter | Your IP address and the hour, only when you use the keyless demo without an API key, to enforce the limit of 5 renders per hour. | Deleted after 3 hours. |
| Password-reset attempt limiter | A one-way hash of your IP address, and a one-way hash of the address the reset was requested for. | Deleted after 25 hours. |
The application does not write IP addresses or user agents to its logs. The only places an IP address is kept are the two short-lived rate-limit entries in the table above. Render keeps HTTP request logs (which include IP addresses) for requests to the old address pdfmint-b9tt.onrender.com; that is described under processors below.
3. Card details
Card numbers never reach this service. Payment is handled entirely by Stripe on Stripe's own pages. PDFMint stores only the Stripe identifiers, the plan, and whether the subscription is active.
4. Email
PDFMint sends exactly one kind of email: the password-reset message. It is sent only when a reset is requested for an account (on the forgot-password page or through the API), only to that account's email address, and contains a one-time link that is valid for 30 minutes. There is no newsletter, no marketing mail and no confirmation email. This email is relayed through Google's SMTP service — see the processors below.
5. Processors
These companies process data on behalf of this service:
| Processor | What they do | Where |
|---|---|---|
| Hetzner Online GmbH | Provides the server that runs the application and the PostgreSQL database in which everything in section 2 is stored. | Helsinki, Finland |
| Google (Google Ireland Limited / Google LLC) | Relays the password-reset email (smtp.gmail.com), so it sees the recipient address and the message. | Chosen by Google; not limited to the EU |
| Render Services, Inc. | Only serves the old address pdfmint-b9tt.onrender.com as a redirect to pdf.mintapis.com, and keeps HTTP request logs (which include IP addresses) for requests to that old address. | Frankfurt, Germany |
| Stripe, Inc. | Takes payments and stores card details. Stripe is the controller for the card data itself. | Ireland / United States |
The public website serves its fonts from PDFMint, so viewing these pages does not contact a font
provider. Separately, a PDF render can fetch external assets requested by the submitted document;
the googleFonts option specifically loads a stylesheet from Google Fonts.
6. Rendering a URL you supply
If you ask PDFMint to render a URL, this service fetches that URL from its own server in Helsinki, Finland. The operator of that URL will see a request from this service, not from you. Private, loopback and link-local addresses are refused.
7. Your rights
Under the GDPR you may request access to your data, correction, deletion, restriction of processing, portability, and you may object to processing. Write to info@productivity-boost.com. You may also complain to a supervisory authority; for this controller that is the Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Ansbach.
Being straight about deletion: there is currently no self-service account deletion in the dashboard. A deletion request has to be handled by hand by the operator. That is a gap, and it is named here rather than implied away.
8. Legal basis
- Art. 6(1)(b) — performing the contract: your account, your API keys, rendering your documents, quota accounting.
- Art. 6(1)(c) — legal obligation: records connected to payments.
- Art. 6(1)(f) — legitimate interest: rate limiting and the operational logs needed to keep the service standing and to stop abuse, including the demo and password-reset rate limits.
9. Changes
If this policy changes materially, the change will be visible in this page's git history — the repository is public at github.com/fstandhartinger/pdfmint.