Pagekind privacy note — engineering preview, September 11, 2026 THE DESKTOP APP PDF operations run on your computer. The app has no account system, upload endpoint, analytics SDK, advertising SDK or automatic crash reporting service. Automatic updates are disabled. The interface exchanges requests with a local worker through anonymous pipes. It rejects network file paths and URLs. No document content is sent by our code. PDFs, temporary working files and saved copies are local files. Applied changes are stored as local working snapshots until the document is closed normally. After a crash or interruption, unsaved workspaces remain available through Recover. The state file does not store PDF passwords. Text still being checked may not have reached a stored snapshot. Your chosen folder may be managed by third-party backup or sync software; Pagekind does not control Windows, OneDrive, other programs or an administrator's policies. Saving into a synced folder is not a Pagekind document-upload service, but that other software may transmit the file. Use an ordinary local folder when that matters. Automated core tests reject Python network calls. Native-library traffic has not been exhaustively instrumented. Physical network-disconnection validation and full clean-machine installation coverage remain release checks. We do not claim certification. Unplaced Add text and Annotate values: each open PDF keeps separate words and settings for these tools in application memory. Changing tools or pages, saving and PDF Undo/Redo retain them. They are not PDF content until placed, are not included in a saved copy, and are not stored as recovery drafts. Closing asks before discarding pending values; they do not survive application exit. Find also keeps its current query in memory for explicit refresh, clearing it when the document session changes. Neither feature adds a persistent history file. THE WEBSITE The website distributes the installer and explains the app. It does not process PDFs. It contains no custom analytics, advertising pixels, email signup or document form. The hosting provider necessarily receives ordinary web requests, including IP address and requested URL. Any hosting access controls are separate from the desktop app. Do not send confidential documents to a public issue tracker or review site. Use a synthetic sample when reporting a problem. Printing: Pagekind prepares page images locally. Only choosing Print in the Windows dialog submits them to your chosen destination. A network printer can receive the document over the network. Print/spool data and temporary page images are not protected by the PDF password. Pagekind removes its temporary image directory after preparation/submission finishes or is cancelled, when Windows permits. Printer spool storage is managed by Windows and the selected printer, not by Pagekind. Favorites: the app saves only tool identifiers and their order in LocalAppData/Pagekind/Preferences/tools.json. No document filenames, extracted text or passwords are saved there. The file is not synced or transmitted. Application uninstallation preserves these personal preferences and unsaved PDF workspaces. Batch tools: local TEMP/Pagekind-Batches-v1 stores selected local paths, hashes, settings and result messages, with no passwords. Each running job stages a copy inside a marked .pk-... folder in the chosen output directory. Normal completion, verified cancellation and explicit New queue cleanup remove these owned copies. A crash may leave them until Recover an interrupted queue verifies and cleans them. Completed outputs are kept. Text/image exports and result reports have no PDF password protection; reports contain local filenames and paths. Selected files on disk, not unsaved edits in another workspace, are batch inputs. There are no batch uploads, recursive folder scans, scripts or print jobs. Uninstall preserves queues and unsaved work for recovery. Document tabs: page/zoom settings, tab records and remembered passwords remain in application memory. Applied PDF edits and undo history use the existing owned local workspaces; no new persistent tab file or password store is added. Closing a tab clears its remembered snapshot keys. After a window exits, unsaved workspaces can be recovered into separate tabs; passwords must be supplied again. A workspace that cannot be checked can be explicitly retained while closing the application. Redacted image copies: the engine reads the source into bounded local memory and builds a new PDF using only masked RGB page pixels. Original PDF objects and hidden payloads are not copied. The exported file is unencrypted, and visible content outside your marks remains. Source files and editing history are unchanged; this does not sanitize or erase them from disk. Unredacted raster intermediates are not written to disk. A hard-killed worker can leave an unpublished temporary file of partial redacted output. Marks and their local undo history stay in memory only while the document tab remains open; they are not recovered after the app exits. Lost export replies are checked against the actual selected output before success is claimed. Existing files are never overwritten by this feature. Interrupted saves: local workspace records contain the chosen output path, snapshot identifier, revision, byte count and hash, without passwords. Exact byte checks verify a completed copy before its saved state is recovered. Saved PDFs retain their snapshot encryption. An abrupt stop can leave a temporary PDF copy containing unredacted content until cleanup. Recovery preserves working copies after an unverified result. Uninstall does not erase recoverable workspaces. New OCR workspace operations keep page counts and completion metadata in their recovery receipt, without a recognized-text transcript. The searchable PDF keeps its existing password encryption. Older previews could retain an OCR transcript in their plaintext workspace receipt; this change does not erase older records. Reply drafts: TEMP/Pagekind-Workspaces-v2 keeps reply words, the local display name, an exact parent target and a short parent preview in the owned workspace state file. These drafts are local plain text without PDF password protection; reply drafting for encrypted PDFs is not offered in this preview. A pause in typing or a successful draft keep stores the current valid draft. Invalid text or an unconfirmed keep may remain only in memory, with feedback in the app. Choosing to keep a reply while closing retains its workspace, including the working PDF and history, for Recover. This also applies to otherwise unchanged PDFs. Uninstall preserves that recoverable work. Posting clears the matching draft in the same state commit that records its PDF snapshot and result. The PDF then contains the reply words, display name and dates as unverified metadata. Undoing a post does not restore its old draft; an existing separate draft stays kept. No reply content is uploaded or sent to another reviewer by Pagekind. Review decisions: The reviewer label, choice and conversation context stay in memory while navigating an open document. Unrecorded choices are not retained for restart recovery. Record decision writes the exact label, standard decision, date and previous-record reference into the working PDF, which is retained with its local undo/recovery history. Save a copy writes those records to your chosen PDF file. Names and dates are unverified metadata, not authenticated identities. No decision content is uploaded or sent to another reviewer by Pagekind. Posted-reply corrections: A kept correction stores its new words, original reply text, original author label and short parent context in the local workspace for recovery. It is separate from a new-reply draft. Apply reply correction changes the working PDF and consumes its matching draft; discarding removes the draft from the current workspace state. Save a copy writes applied changes to a PDF. Reply correction and leaf removal preserve earlier PDF bytes and Undo history; removal from the current comment list is not confidential-content erasure. No reply text is uploaded or sent to other reviewers by Pagekind. XFDF comment exchange: Inspection reads a chosen local XFDF file as data and keeps its inspection in that document tab while it is open. It does not open referenced files or URLs, execute actions or import comments into the PDF. Export writes supported plain-text comments, author labels, dates, relationships and document filename/ID hints to a new local XFDF file. The PDF and its Undo history are unchanged. Pagekind does not upload or send the exported file; its comment text and metadata are included for the person you choose to share it with. Deliberate XFDF import: Choosing Review an XFDF import keeps a local, unencrypted copy of the chosen packet and its analysis with the receiving document workspace. The stored records include comment words, author labels, dates, relationships and position metadata. Explicit receiving-page review is required before Apply. Kept reviews can survive closing the document and recovery; they are not applied on recovery. Discard removes the task-owned kept review, leaving the external XFDF and original PDF unchanged. Pagekind does not send any of this data elsewhere. Applied comments remain in working PDF revisions and Undo history; Discard is not a secure erasure operation. Referenced URLs and files are not opened. Saved reading places: only explicitly kept references are written to LocalAppData/Pagekind/Preferences/places.json. These contain the document path, file hash and byte count, page, zoom, position, fit and continuous-view settings, and update time. They do not contain PDF text, thumbnails or passwords. Remove and Clear saved places remove references without deleting the PDF. These local preferences survive uninstall. Saved PDF groups: only explicitly saved groups are written to LocalAppData/Pagekind/Preferences/groups.json. Each contains a chosen name, member order, local PDF paths, saved-file hashes and byte/page counts, with no PDF contents or passwords. Renaming, reordering or removing a group changes this list only. Checking a member reads its saved bytes without opening a PDF workspace. Opening selected files copies verified bytes into owned local workspaces. Per-window opening records under TEMP/Pagekind-Workspaces-v2/owners contain request and workspace identifiers, hashes, byte counts and completion states; they omit passwords and plaintext source paths. They help reconcile interrupted openings without duplication. Finished dead windows' records can be removed; uncertain records and workspace files are kept. Group lists are preserved on uninstall. Ordinary PDF opening and closing do not add members automatically. 0.50 and earlier OCR receipts: applying OCR can keep a recognized-text transcript in the local plaintext workspace receipt, even when the PDF remains password protected. Avoid OCR on sensitive password-protected documents in these previews. A later correction removes transcripts from new receipts; it does not erase older records. OCR word review (0.54): TEMP/Pagekind-OCR-Reviews-v1 stores an independent copy of the scan with its original PDF encryption and a protected recognition/correction record for the current Windows account. It is separate from the ordinary document workspace and remains after closing a document so Keep for later can be recovered. PDF passwords remain transient and are required again after restarting. The recognition image and review preview are processed in memory without a temporary raster file. Protected word records are authenticated; unavailable protection does not fall back to plaintext. This does not promise secure memory erasure. Opening the kept scan creates an ordinary owned PDF workspace. Its opening and application receipts contain local source metadata, hashes and counts, without the recognized transcript, corrections or password. Completed reviews remain available to manage or discard. Discard first records a protected terminal result, then removes only its own scan and protected temporary writes; a failed removal can be retried from Recover. It is normal file deletion, not secure erasure. Uninstall preserves these local reviews. Operating-system temporary-file cleanup can remove them; keep a saved PDF for a durable copy. A hard stop before review preparation finishes can leave an uncommitted local scan, and no automatic global storage eviction is performed. Earlier preview OCR records are not retroactively erased by this version. PDF access and password settings (0.54): PDF reading and owner passwords remain in memory for the session. They are not written into workspace records. Supported edited copies retain the original PDF encryption credentials and permissions; saved settings are checked before output is published. Explicit replacement or removal requires owner access. PDF owner access is separate from Windows account access. Print and export restrictions are checked; low-resolution printing is limited to 150 DPI. Existing weak PDF encryption is retained unless the owner explicitly changes protection. Unusual security filters that cannot be safely retained are refused. Password choices and access guidance (0.54) Reading and owner passwords for new protection remain in memory. Workspace records do not contain these passwords or the submitted password-setting options. Permission-only reading can use an empty reading password; reopening such a PDF does not recover owner access. Selected-text copying follows the PDF permissions. Opening settings and selecting protected text do not remove protection. Creating or changing form fields requires both content and comment permissions; filling existing fields is checked separately. Signed structures are not redesigned.