PagekindPRIVACY & YOUR DATA

PRIVACY & YOUR DATA

Privacy, in plain language.

Your PDF is your business. Here is what stays on your computer, what happens when you visit this website, and the choices you control.

Last updated 11 September 2026 · Desktop preview 0.65.0

Documents stay local.

The desktop app processes PDFs on your computer.

Recovery stays with you.

Working copies and preferences are local files you manage.

Website visits are different.

Hosting providers receive the requests needed to serve these pages.

Preview privacy notice

This notice describes the public website and current desktop preview. Business address details, retention schedules, and the applicable hosting and email transfer arrangements remain to be finalized. This notice will be updated as those details are confirmed. See Operator and contact.

1. About this notice.

This notice covers the Pagekind Windows desktop preview and this Pagekind website. In this notice, “Pagekind”, “we” and “our” refer to the business operating the Pagekind product. Business and contact details are listed below. The website operator is responsible for personal information processed through the site; hosting does not transfer that responsibility to the hosting provider.

The desktop app and website have different roles. The app edits documents on your computer. This website explains the product and distributes the installer; it does not open, edit or accept uploads of your PDFs.

2. Your documents and local data.

Pagekind processes PDFs locally. The current desktop preview has no Pagekind account system, document-upload service, app analytics, advertising SDK, automatic crash-reporting service or enabled automatic updater.

Add text and Annotate keep unplaced words and settings in memory while their PDF stays open. They are separate from PDF content, saved copies and recovery drafts. Closing asks before discarding pending values, and they do not survive app exit. Find also keeps its current query in memory for an explicit refresh. Read how to place and save new text.

Editing, Undo and recovery require local working files. The following information can remain on your computer:

Desktop information and its purpose
InformationWhy it is usedWhat to know
PDFs, edits and historyDisplay, edit, undo and recover your work.Working copies can contain the document and previous edits. Interrupted work may remain for Recover.
Preferences, reading places and saved groupsRemember favorite tools and PDF references you explicitly save.Groups can include document paths, names, order, hashes and page counts. Reading places also record file size, page, zoom, position, view settings and update time. Remove or Clear removes those references, not your PDFs. Preferences survive uninstall.
Comments, imports and reportsKeep drafts, review feedback and record batch results.Some companion records contain plain-text words, author labels, filenames or paths. A PDF password does not protect every related file.
OCR review recordsLet you review recognized words and resume a kept review.Current word-review records use Windows-account protection. Older preview OCR transcripts may still exist in plain-text receipts.
PDF passwordsOpen a protected document or apply authorized changes.Passwords remain in application memory for the session and are not written into the workspace state records. You may need to enter them again after restarting.

We cannot retrieve documents held only on your computer through the Pagekind website. Local-only processing does not prevent another program, a shared Windows account, an administrator or backup software from accessing local files.

3. Website visits, downloads and email.

When your browser requests a page, image or installer, hosting infrastructure receives technical information such as your IP address, requested URL, request time and browser information. That information is used to deliver the response, operate the service and protect it from abuse.

This public website is hosted through OpenAI Sites using Cloudflare infrastructure. Visitors do not need a Pagekind account to read these pages or download the preview. The desktop app also does not require a Pagekind account. The Pagekind page code does not collect an account profile or provide a sign-up, newsletter, contact or document-upload form.

Downloading Pagekind sends a request for the installer. It does not send a PDF from your computer. The current downloaded preview does not automatically check for later versions. If that changes, this notice will describe the update connection and its controls before the change is released.

Emailing Pagekind

When you email us, we receive your email address, any name you provide, your message and attachments, and technical email details such as sending time and routing headers. We use this information to answer general enquiries, help with Pagekind problems and handle privacy requests.

Sending an attachment is optional. An attachment you email leaves your computer and is received by us and the email providers involved. Pagekind’s local PDF processing does not apply to files you choose to email. Describe the issue first and use a synthetic or redacted example when possible.

4. Cookies and tracking.

Pagekind’s active website code does not add analytics cookies, advertising pixels or cross-site tracking. It does not use browser storage to build a visitor profile.

The hosting and access-control services may use cookies or similar technologies for their own delivery, authentication and security functions. Their behavior is separate from the Pagekind page code. This is not a claim that visiting the hosted site creates no cookies.

You can review or remove stored site data in your browser. Blocking technologies needed for site delivery may prevent pages or downloads from opening. Any future optional analytics or marketing technology will need an updated notice and the choices required by applicable law before it is enabled.

5. Why information is used.

Desktop data is used on your device to carry out the PDF task you choose and support local history, preferences and recovery. Website technical information is used to provide pages and downloads, maintain availability, enforce access controls and investigate abuse.

For processing covered by the GDPR, the proposed basis for necessary website delivery and security is legitimate interests in operating a reliable, secure product website (Article 6(1)(f)). Confirmation and documentation of the applicable basis and balancing assessment remain outstanding. Any processing required by a specific legal obligation would use that obligation as its basis.

For correspondence covered by the GDPR, the proposed basis for general enquiries and support is our legitimate interest in answering requests and helping people use Pagekind (Article 6(1)(f)). Handling statutory privacy requests relies on the applicable legal obligation (Article 6(1)(c)). Confirmation and documentation of the applicable bases remain outstanding.

The current Pagekind implementation does not use your document content or visitor information for advertising, audience profiling or automated decisions that produce legal or similarly significant effects.

6. Providers and actions you choose.

OpenAI Sites and its hosting infrastructure process website requests to serve this site. Providers may operate in countries other than yours. We have not selected a Pagekind-specific hosting region or confirmed a particular international-transfer mechanism; confirmation of the applicable hosting agreement and safeguards remains outstanding.

For the providers’ own processing and their contact options, see the OpenAI privacy policy and Cloudflare privacy policy. These provider policies do not replace the Pagekind operator’s responsibilities for this site.

We use Fastmail Pty Ltd to receive, store and send email. Fastmail processes message content, attachments and related technical information to provide this service. Its operations include processing outside the EEA. See the Fastmail privacy policy and data protection agreement for its processing arrangements and safeguards. Confirmation of the applicable arrangements for Pagekind remains outstanding.

Some actions can send information outside your computer.

  • Copying text. Copy selection and page-text copying place text on the Windows clipboard. Other applications and your Windows clipboard history or synchronization settings may retain or share that content.
  • Printing. Choosing Print sends pages to the Windows destination you select. A network printer or print service may receive them. Windows and the destination manage print and spool records.
  • Opening a website link. Choosing Open website for a PDF link opens the selected address in your default browser. The destination receives that web request, and the address itself may contain document-specific information. Pagekind does not attach the PDF to the request.
  • Saving into a synced folder. OneDrive, backup software or another service may transmit a file saved in a folder it manages. Use an ordinary local folder if you do not want that synchronization.
  • Sharing an exported file. A PDF, XFDF packet, text report or image can include content and metadata you choose to share. Pagekind creates the file locally; the service you use to send it has its own practices.

There is no Pagekind advertising-data sale or advertising-sharing feature in this preview. Hosting providers may disclose information as described in their terms or where legally required.

7. Keeping and deleting data.

Your saved files: saved PDFs, exports and reports remain in the folders you choose until you or other software remove them. Pagekind does not remotely expire or delete them.

Working files and recovery: ordinary cleanup removes eligible temporary files when an operation finishes or a document closes normally. Crashes, failed cleanup and explicitly kept work can leave records available for recovery. Local preferences, saved groups, queues and recoverable work are preserved on uninstall. Kept OCR reviews may also survive closing and uninstall, but operating-system temporary-file cleanup can remove them.

Use the relevant Recover, Discard or Remove action to manage kept work, and keep a saved PDF for a durable copy. Removing a saved group removes its list entry, not the PDFs. Avoid deleting a workspace while Pagekind is using it.

Website and hosting records: this static website does not maintain a separate Pagekind visitor database. Hosting-log retention follows the provider configuration and applicable agreement. A site-specific retention period has not yet been confirmed; we do not promise an unverified number of days.

Email messages and replies can remain in our mailbox, and separate copies may remain with you and your email provider. A Pagekind-specific review and deletion schedule has not yet been finalized. The operator still needs to document retention periods or criteria that consider request completion, necessary follow-up and applicable legal obligations. Fastmail may retain separate recovery copies and operational records under its policies.

Ordinary file deletion is not secure erasure. Backups, earlier PDF revisions, Windows print data and other software may retain separate copies.

8. Protecting your information.

The website is served over HTTPS. Locally, Pagekind keeps edited output separate from the original and checks supported saved results. Neither behavior makes every local record encrypted: text reports, comment drafts, imports and some recovery metadata may be plain text.

PDF encryption protects the PDF where supported; it does not automatically protect exported images, print/spool data or companion files. Current OCR word-review records have Windows-account protection, while older preview records are not retroactively erased or protected.

Use a secured Windows account, control access to shared folders and backups, and avoid posting confidential documents in a public issue tracker or review. A synthetic sample is usually a better way to describe a problem.

9. Your rights and choices.

Depending on the law that applies, you may have rights to access, correct or delete personal information, receive a portable copy, restrict or object to processing, and withdraw consent where processing depends on it. These rights have conditions and exceptions. You may also complain to your local data protection authority; people in the EEA can find their authority through the European Data Protection Board.

Your right to object: where the GDPR applies, you can object to processing based on legitimate interests for reasons relating to your particular situation. That processing must stop unless the operator demonstrates overriding legitimate grounds or needs it for legal claims. To exercise your right to object, email [email protected].

For documents and records that exist only on your device, use Pagekind and Windows to manage them. The website operator cannot remotely retrieve or erase those local files. Requests about information processed by a hosting provider for its own purposes can be directed through that provider’s privacy policy.

For a privacy request, email [email protected]. Start with a description of your request; do not include passwords or identity documents in an initial message.

10. Operator and contact.

BUSINESS DETAILS TO COMPLETE
Business name
Pagekind
Country
United States
Business address
[Business postal address]
Privacy contact
[email protected]
Product support
[email protected]
General enquiries
[email protected]

These addresses reach the same Pagekind operator mailbox. Mailing-address and other required business disclosures remain to be completed.

11. Changes to this notice.

We will update the date at the top when this notice changes. New hosting, an update service, contact channels or optional measurement tools must be described before they are introduced. Where required, a material change will also be explained when you use the affected feature.

This notice covers the current engineering preview. It does not claim legal certification or guarantee the behavior of other software on your computer.

Detailed preview notes.

The original engineering record contains additional storage locations and feature-specific recovery details. Its version references describe the preview in which each behavior was introduced; the sections above describe the current notice.

Local storage and feature details

Pagekind privacy note — engineering preview, September 11, 2026

THE DESKTOP APP PDF operations run on your computer. The app has no account system, upload endpoint, analytics SDK, advertising SDK or automatic crash reporting service. Automatic updates are disabled. The interface exchanges requests with a local worker through anonymous pipes. It rejects network file paths and URLs. No document content is sent by our code.

PDFs, temporary working files and saved copies are local files. Applied changes are stored as local working snapshots until the document is closed normally. After a crash or interruption, unsaved workspaces remain available through Recover. The state file does not store PDF passwords. Text still being checked may not have reached a stored snapshot. Your chosen folder may be managed by third-party backup or sync software; Pagekind does not control Windows, OneDrive, other programs or an administrator's policies. Saving into a synced folder is not a Pagekind document-upload service, but that other software may transmit the file. Use an ordinary local folder when that matters.

Automated core tests reject Python network calls. Native-library traffic has not been exhaustively instrumented. Physical network-disconnection validation and full clean-machine installation coverage remain release checks. We do not claim certification.

Unplaced Add text and Annotate values: each open PDF keeps separate words and settings for these tools in application memory. Changing tools or pages, saving and PDF Undo/Redo retain them. They are not PDF content until placed, are not included in a saved copy, and are not stored as recovery drafts. Closing asks before discarding pending values; they do not survive application exit. Find also keeps its current query in memory for explicit refresh, clearing it when the document session changes. Neither feature adds a persistent history file.

THE WEBSITE The website distributes the installer and explains the app. It does not process PDFs. It contains no custom analytics, advertising pixels, email signup or document form. The hosting provider necessarily receives ordinary web requests, including IP address and requested URL. Any hosting access controls are separate from the desktop app.

Do not send confidential documents to a public issue tracker or review site. Use a synthetic sample when reporting a problem.

Printing: Pagekind prepares page images locally. Only choosing Print in the Windows dialog submits them to your chosen destination. A network printer can receive the document over the network. Print/spool data and temporary page images are not protected by the PDF password. Pagekind removes its temporary image directory after preparation/submission finishes or is cancelled, when Windows permits. Printer spool storage is managed by Windows and the selected printer, not by Pagekind.

Favorites: the app saves only tool identifiers and their order in LocalAppData/Pagekind/Preferences/tools.json. No document filenames, extracted text or passwords are saved there. The file is not synced or transmitted. Application uninstallation preserves these personal preferences and unsaved PDF workspaces.

Batch tools: local TEMP/Pagekind-Batches-v1 stores selected local paths, hashes, settings and result messages, with no passwords. Each running job stages a copy inside a marked .pk-... folder in the chosen output directory. Normal completion, verified cancellation and explicit New queue cleanup remove these owned copies. A crash may leave them until Recover an interrupted queue verifies and cleans them. Completed outputs are kept. Text/image exports and result reports have no PDF password protection; reports contain local filenames and paths. Selected files on disk, not unsaved edits in another workspace, are batch inputs. There are no batch uploads, recursive folder scans, scripts or print jobs. Uninstall preserves queues and unsaved work for recovery.

Document tabs: page/zoom settings, tab records and remembered passwords remain in application memory. Applied PDF edits and undo history use the existing owned local workspaces; no new persistent tab file or password store is added. Closing a tab clears its remembered snapshot keys. After a window exits, unsaved workspaces can be recovered into separate tabs; passwords must be supplied again. A workspace that cannot be checked can be explicitly retained while closing the application.

Redacted image copies: the engine reads the source into bounded local memory and builds a new PDF using only masked RGB page pixels. Original PDF objects and hidden payloads are not copied. The exported file is unencrypted, and visible content outside your marks remains. Source files and editing history are unchanged; this does not sanitize or erase them from disk. Unredacted raster intermediates are not written to disk. A hard-killed worker can leave an unpublished temporary file of partial redacted output. Marks and their local undo history stay in memory only while the document tab remains open; they are not recovered after the app exits. Lost export replies are checked against the actual selected output before success is claimed. Existing files are never overwritten by this feature.

Interrupted saves: local workspace records contain the chosen output path, snapshot identifier, revision, byte count and hash, without passwords. Exact byte checks verify a completed copy before its saved state is recovered. Saved PDFs retain their snapshot encryption. An abrupt stop can leave a temporary PDF copy containing unredacted content until cleanup. Recovery preserves working copies after an unverified result. Uninstall does not erase recoverable workspaces.

New OCR workspace operations keep page counts and completion metadata in their recovery receipt, without a recognized-text transcript. The searchable PDF keeps its existing password encryption. Older previews could retain an OCR transcript in their plaintext workspace receipt; this change does not erase older records.

Reply drafts: TEMP/Pagekind-Workspaces-v2 keeps reply words, the local display name, an exact parent target and a short parent preview in the owned workspace state file. These drafts are local plain text without PDF password protection; reply drafting for encrypted PDFs is not offered in this preview. A pause in typing or a successful draft keep stores the current valid draft. Invalid text or an unconfirmed keep may remain only in memory, with feedback in the app.

Choosing to keep a reply while closing retains its workspace, including the working PDF and history, for Recover. This also applies to otherwise unchanged PDFs. Uninstall preserves that recoverable work. Posting clears the matching draft in the same state commit that records its PDF snapshot and result. The PDF then contains the reply words, display name and dates as unverified metadata. Undoing a post does not restore its old draft; an existing separate draft stays kept. No reply content is uploaded or sent to another reviewer by Pagekind.

Review decisions: The reviewer label, choice and conversation context stay in memory while navigating an open document. Unrecorded choices are not retained for restart recovery. Record decision writes the exact label, standard decision, date and previous-record reference into the working PDF, which is retained with its local undo/recovery history. Save a copy writes those records to your chosen PDF file. Names and dates are unverified metadata, not authenticated identities. No decision content is uploaded or sent to another reviewer by Pagekind.

Posted-reply corrections: A kept correction stores its new words, original reply text, original author label and short parent context in the local workspace for recovery. It is separate from a new-reply draft. Apply reply correction changes the working PDF and consumes its matching draft; discarding removes the draft from the current workspace state. Save a copy writes applied changes to a PDF. Reply correction and leaf removal preserve earlier PDF bytes and Undo history; removal from the current comment list is not confidential-content erasure. No reply text is uploaded or sent to other reviewers by Pagekind.

XFDF comment exchange: Inspection reads a chosen local XFDF file as data and keeps its inspection in that document tab while it is open. It does not open referenced files or URLs, execute actions or import comments into the PDF. Export writes supported plain-text comments, author labels, dates, relationships and document filename/ID hints to a new local XFDF file. The PDF and its Undo history are unchanged. Pagekind does not upload or send the exported file; its comment text and metadata are included for the person you choose to share it with.

Deliberate XFDF import: Choosing Review an XFDF import keeps a local, unencrypted copy of the chosen packet and its analysis with the receiving document workspace. The stored records include comment words, author labels, dates, relationships and position metadata. Explicit receiving-page review is required before Apply. Kept reviews can survive closing the document and recovery; they are not applied on recovery. Discard removes the task-owned kept review, leaving the external XFDF and original PDF unchanged. Pagekind does not send any of this data elsewhere. Applied comments remain in working PDF revisions and Undo history; Discard is not a secure erasure operation. Referenced URLs and files are not opened.

Saved reading places: only explicitly kept references are written to LocalAppData/Pagekind/Preferences/places.json. These contain the document path, file hash and byte count, page, zoom, position, fit and continuous-view settings, and update time. They do not contain PDF text, thumbnails or passwords. Remove and Clear saved places remove references without deleting the PDF. These local preferences survive uninstall.

Saved PDF groups: only explicitly saved groups are written to LocalAppData/Pagekind/Preferences/groups.json. Each contains a chosen name, member order, local PDF paths, saved-file hashes and byte/page counts, with no PDF contents or passwords. Renaming, reordering or removing a group changes this list only. Checking a member reads its saved bytes without opening a PDF workspace. Opening selected files copies verified bytes into owned local workspaces. Per-window opening records under TEMP/Pagekind-Workspaces-v2/owners contain request and workspace identifiers, hashes, byte counts and completion states; they omit passwords and plaintext source paths. They help reconcile interrupted openings without duplication. Finished dead windows' records can be removed; uncertain records and workspace files are kept. Group lists are preserved on uninstall. Ordinary PDF opening and closing do not add members automatically.

0.50 and earlier OCR receipts: applying OCR can keep a recognized-text transcript in the local plaintext workspace receipt, even when the PDF remains password protected. Avoid OCR on sensitive password-protected documents in these previews. A later correction removes transcripts from new receipts; it does not erase older records.

OCR word review (0.54): TEMP/Pagekind-OCR-Reviews-v1 stores an independent copy of the scan with its original PDF encryption and a protected recognition/correction record for the current Windows account. It is separate from the ordinary document workspace and remains after closing a document so Keep for later can be recovered. PDF passwords remain transient and are required again after restarting. The recognition image and review preview are processed in memory without a temporary raster file. Protected word records are authenticated; unavailable protection does not fall back to plaintext. This does not promise secure memory erasure.

Opening the kept scan creates an ordinary owned PDF workspace. Its opening and application receipts contain local source metadata, hashes and counts, without the recognized transcript, corrections or password. Completed reviews remain available to manage or discard. Discard first records a protected terminal result, then removes only its own scan and protected temporary writes; a failed removal can be retried from Recover. It is normal file deletion, not secure erasure. Uninstall preserves these local reviews. Operating-system temporary-file cleanup can remove them; keep a saved PDF for a durable copy. A hard stop before review preparation finishes can leave an uncommitted local scan, and no automatic global storage eviction is performed. Earlier preview OCR records are not retroactively erased by this version.

PDF access and password settings (0.54): PDF reading and owner passwords remain in memory for the session. They are not written into workspace records. Supported edited copies retain the original PDF encryption credentials and permissions; saved settings are checked before output is published. Explicit replacement or removal requires owner access. PDF owner access is separate from Windows account access. Print and export restrictions are checked; low-resolution printing is limited to 150 DPI. Existing weak PDF encryption is retained unless the owner explicitly changes protection. Unusual security filters that cannot be safely retained are refused.

Password choices and access guidance (0.54) Reading and owner passwords for new protection remain in memory. Workspace records do not contain these passwords or the submitted password-setting options. Permission-only reading can use an empty reading password; reopening such a PDF does not recover owner access. Selected-text copying follows the PDF permissions. Opening settings and selecting protected text do not remove protection. Creating or changing form fields requires both content and comment permissions; filling existing fields is checked separately. Signed structures are not redesigned.

Download the original technical privacy note (TXT).