Privacy Policy
Effective date: July 16, 2026
EZ PDF Editor (the “Service”) is operated by AICS Solutions (“we”, “us”), Ontario, Canada. This policy explains what we collect, why, who we share it with, how long we keep it, and your rights under Canada’s federal Personal Information Protection and Electronic Documents Act (PIPEDA) and, for Quebec residents, the Act respecting the protection of personal information in the private sector as amended by Law 25. Questions: ezpdfeditor@aicanadiansolutions.ca.
1. What runs in your browser (and never reaches us)
The core of EZ PDF Editor is deliberately client-side. When you use these tools, your file is opened and processed by JavaScript running on your device, and the result is saved straight back to your device:
- Opening, filling, editing, annotating and drawing a signature on a PDF.
- Merging, splitting, compressing and rearranging PDFs.
- Image conversions (HEIC/JPG/PNG/WebP), image-to-PDF and PDF-to-image.
- OCR (making a scan searchable) — performed entirely in your browser by the open-source Tesseract engine. Your scanned pages are not uploaded anywhere for OCR.
Documents you work on are cached locally in your browser’s storage (IndexedDB / localStorage) so you can pick up where you left off. That local copy is on your device only; clear the site’s data in your browser to remove it.
2. What we collect, and when
Nothing in this section happens unless you use the feature that needs it.
a) Account (optional)
If you create an account we store your email address, a salted-and-hashed password (never the password itself), email-verification and password-reset tokens, and sign-in session tokens (valid 30 days). Verification and reset emails are sent through SendGrid.
b) Saved documents & autofill profile (signed-in, explicit save)
If you choose to save a document to your account, the document’s contents are stored on our server so you can reopen it from any device. If you save an autofill profile (e.g. your name, address and contact details for filling forms), that profile is stored against your account. Both exist only because you pressed save, and both are deleted with your account.
c) Usage history (signed-in)
For signed-in users we keep a history of tools you used (tool name, page count, file name and size) and, so you can re-download results later, a copy of the output file. You can delete any history entry — and its stored file — yourself from inside the app.
d) E-signature requests
When you send a document for signature we necessarily store: the PDF you uploaded, the recipient names and email addresses you entered, each signer’s signature image, signing tokens, the IP address from which each signature was submitted (fraud evidence), and the final signed PDF. Signers receive emails via SendGrid.
e) Voice form-fill (AI)
When you fill a form by talking:
- Your speech is converted to text by your browser’s built-in speech recognition (the Web Speech API). Depending on your browser this may involve the browser vendor’s speech service (for example Google on Chrome or Apple on Safari) processing the audio under that vendor’s own privacy policy. We never receive or store your audio.
- The resulting text transcript, together with the form’s field labels, is sent to our server and forwarded to OpenAI (our AI sub-processor) to work out which value goes in which field. Per OpenAI’s API terms, API data is not used to train OpenAI’s models.
- We do not store the transcript or the AI’s answer. We log only bookkeeping metadata about the call: token counts, the model used, computed cost, your IP address and (if signed in) your account — used for abuse prevention and a per-IP daily limit.
f) Server-side conversions
- Word/Excel/PowerPoint → PDF runs on our own server (LibreOffice). Your file is processed in a temporary directory that is deleted immediately after the conversion — typically within seconds — and is never added to any database.
- PDF → Word/Excel/PowerPoint is performed by ConvertAPI, a third-party conversion service. The file is sent for synchronous conversion with storage disabled, and the result streams straight back to you.
g) Payments
Pro subscriptions are processed by Stripe. Your card number goes to Stripe, never to us; we store only your Stripe customer/subscription identifiers and payment totals for accounting.
h) Analytics & logs (all visitors)
We run our own first-party analytics — no advertising networks, no fingerprinting. Each page view or tool use records: timestamp, IP address, user agent (device type, OS, browser family), the page/tool, and the referring page. Standard web-server logs (IP, timestamp, URL) also exist for security and troubleshooting. We additionally keep per-IP daily counters for rate-limiting the AI and conversion endpoints. We also offer optional Google Analytics, which loads only if you accept the analytics consent banner (see Section 6).
i) Video Signing Room (live sessions & recordings)
When you host or join a live video signing session we process your video and audio stream (for the live call) and, if the host starts recording, store the recording. Recordings may capture participants’ faces, voices and anything shown on camera or screen. Only the host controls recording. Recordings are kept for the host’s professional records and deleted automatically 24 months after the session, or sooner if the host deletes them (see Retention). If you join as a guest you are asked for your explicit consent before joining; your consent is recorded in the session’s compliance audit trail.
j) Identity verification (ID photos & selfies)
For certain signings the host may ask guests to upload a photo of their government-issued ID and a selfie, which the host compares against the guest’s live video before accepting a signature. These images are stored with the session and destroyed automatically 30 days after they are submitted by a scheduled job — sooner if the host deletes the session. What remains afterwards is the result of the check in the audit trail, never the ID photo or the selfie. Identity verification is optional per session (the host may also confirm a guest personally), and your consent is recorded in the audit trail.
k) AI legal document drafting
Pro Signing subscribers can generate draft legal documents. The document type, profession, jurisdiction, party names/emails and other details you provide are sent to OpenAI (our AI provider) to produce the draft. We do not use your documents to train AI models. If an AI-generated document is later signed in a Video Signing Room, participants are informed (in the consent step) that an AI drafting provider processes personal information in the document.
l) Contacts & Signees
When you invite a signing guest, their name, email, occupation, phone, city and province are stored so they can be re-invited (your “Contacts & Signees” list) and so the compliance audit trail records who participated. You can edit or delete any contact, and contacts are deleted with your account.
3. What we do not collect
- The contents of files you edit with the client-side tools (they never leave your browser).
- Your voice audio from the client-side voice form-fill tool (speech-to-text runs in your own browser and is never sent to us).
- Payment card numbers (Stripe holds those).
- Your location, contacts, or anything outside the Service.
- We do not sell personal information, and we show no third-party ads.
4. How we use information
- To provide the features you invoke (accounts, saved documents, signature requests, AI form-fill, conversions).
- To authenticate you and secure your account.
- To bill Pro subscriptions and keep the accounting records Canadian law requires.
- To rate-limit, detect abuse and keep the Service running.
- To understand, in aggregate, which tools are used so we can improve them.
We do not use your documents, transcripts or personal information to train AI models.
Signing evidence: tamper-seals, Audit Reports & audit
Completed signings are tamper-sealed: a Certificate of Signing & Seal page is appended to the PDF and a cryptographic fingerprint of the sealed file is stored with the session record and written to the audit trail. Anyone can verify that a copy is unaltered by uploading it to /seal — we compare its fingerprint to the stored seal and report whether it is the original. Hosts can also export a per-session Audit Report (PDF or CSV) from Session Audits, and can set signing order and per-signer page visibility for a session. These records exist to help you demonstrate consent, identity, intent and document integrity; you are responsible for keeping and retaining them as your profession or applicable law requires.
5. Sub-processors & third-party services
| Provider | Purpose | What they see |
|---|---|---|
| OpenAI, L.L.C. (US) | Voice form-fill: mapping your spoken text to form fields | The text transcript of what you said and the form’s field labels — transiently, per request. Not used for model training per OpenAI’s API terms. |
| ConvertAPI (EU/US) | PDF → Word/Excel/PowerPoint conversion | The PDF you submit for that conversion — transiently, with file storage disabled. |
| Twilio SendGrid (US) | Transactional email (verification, resets, signature invitations, signed copies) | Recipient email addresses and the message content, including a signed PDF when one is attached. |
| Stripe (US/Canada) | Payment processing for Pro | Your email and payment details. PCI DSS Level 1 certified. |
| RevenueCat (US) | Mobile (Android) subscription entitlements | Your user identifier and subscription status, so the app knows your plan. |
| OpenAI, L.L.C. (US) | AI legal document drafting (in addition to voice form-fill) | Document type, profession, jurisdiction, party names/emails and notes you provide — transiently, per request. Not used for training per OpenAI’s API terms. |
| DigitalOcean (Canada — Toronto region) | Hosting of our server and database | Everything stored server-side lives on infrastructure in Canada. |
| CDN & fonts (jsDelivr, Google Fonts) | Delivering the in-browser OCR engine and web fonts | A standard web request (your IP and user agent) when your browser fetches the script or font. Your files are never sent to them. |
| Browser speech service (e.g. Google, Apple) | Speech-to-text for voice form-fill, performed by your own browser | Your voice audio, under the browser vendor’s privacy policy — this happens on/through your device, not our servers. |
Data residency: our server and database are hosted in Canada. The transient exceptions are the round-trips to OpenAI, ConvertAPI, SendGrid and Stripe described above, whose endpoints may be served from the United States or Europe. Under PIPEDA we remain accountable for personal information we transfer for processing.
6. Cookies & local storage
We do not use advertising cookies. We offer optional, consent-based analytics: if you click “Accept analytics” on the consent banner, Google Analytics is loaded to help us understand which tools are used. Your choice is stored on your device, and you can revoke it at any time by clearing the site’s data. No analytics load unless you accept. The Service keeps a small amount of data in your browser’s local storage: your sign-in token (if you have an account), your in-progress documents, and small preference flags (e.g. whether you dismissed the tour or a sign-up nudge). All of it stays on your device and is removed when you clear the site’s data.
7. Retention
| Data | Kept |
|---|---|
| Client-side documents | On your device only — until you clear your browser data. |
| Account, saved documents, autofill profile, usage history, signature requests | While your account exists; erased within 30 days of a verified deletion request (usually within 7). You can delete usage-history files yourself anytime. |
| Server-conversion working files | Deleted immediately after the conversion completes. |
| Voice transcripts sent to the AI | Not stored — processed and discarded; only token-count metadata is kept. |
| Analytics & server logs (IP-level) | Rotated out, typically within 90 days. |
| Video Signing Room recordings | 24 months (730 days) from the recording, then deleted automatically by a scheduled daily job. The period covers the two-year basic limitation period during which a signing is most likely to be questioned. The host may delete a recording sooner at any time. Not used by us for any other purpose. |
| Identity-verification ID photos & selfies | 30 days from submission, then destroyed automatically by a scheduled daily job. These are the most sensitive images we ever hold, so they are kept only long enough to complete the verification and cover an immediate dispute. The result of the check (who was verified, when, and by whom) stays in the session’s audit trail — the images themselves do not. |
| AI legal document inputs sent to OpenAI | Not stored by us — transmitted to the provider per request; we keep only token-count/usage metadata. |
| Encrypted backups | Purged on normal rotation within 30 days. |
| Tamper-seal records (sealed PDF fingerprints) | Stored with the session/request records and in the audit trail; removed with the session or account per this table. |
| Audit Reports (PDF/CSV exports) | Generated from the session record when you export them; the underlying session record is kept per the rows above. |
| Billing records (held by Stripe) | As required by Canadian tax law — generally up to 7 years. |
8. Your rights (PIPEDA & Quebec Law 25)
At no charge, you may:
- Access — ask what personal information we hold about you; we answer within 30 days.
- Correction — have inaccurate information fixed.
- Withdrawal of consent — stop using any optional feature at any time; the client-side tools require no data at all.
- Deletion — have your account and data erased (see Delete your account & data).
- Portability — request a machine-readable export of the data we hold about you (a formal right in Quebec under Law 25; we extend it to everyone).
- Complaint — contact the Office of the Privacy Commissioner of Canada (priv.gc.ca) or, in Quebec, the Commission d’accès à l’information (cai.gouv.qc.ca).
Automated processing: the only automated step that touches your data is the AI’s suggestion of which value goes in which form field — every suggestion is shown to you as editable text before anything is final, and no consequential decision about you is ever made automatically. Quebec residents may ask us to explain any automated suggestion or to have a human review it.
Breach notification: if a breach of security safeguards creates a real risk of significant harm, we will notify affected users and the OPC (and, for Quebec residents, the CAI) as soon as feasible, as PIPEDA’s regulations and Law 25 require. We maintain a confidential register of confidentiality incidents as Law 25 requires.
Privacy by design: new features that process personal information (such as the Video Signing Room, identity verification and AI document drafting) are assessed before launch, including a privacy impact assessment where the law calls for one, so that privacy is built in rather than added later.
9. Deleting your account & data
Full instructions, what exactly gets erased, and the few records we must keep are on the dedicated Delete your account & data page. Summary: email ezpdfeditor@aicanadiansolutions.ca from your account address and we erase everything within 30 days (usually 7). This is also the deletion path for the Android app: the app is the same Service, and deleting your account removes the same data.
10. Google Play data-safety summary
For users of the Android app, in Play data-safety terms:
- Collected: email address (account, optional); user-generated content (documents and autofill profiles you explicitly save, signature-request files); app interactions (first-party analytics with IP address and device info); purchase history (Pro, via Stripe).
- Shared: voice-transcript text with OpenAI (transient, AI form-fill); conversion files with ConvertAPI (transient); email addresses with SendGrid (message delivery); billing details with Stripe.
- Not collected: location, contacts, audio recordings, files processed by the client-side tools.
- Deletion: ezpdfeditor.aicanadiansolutions.ca/account-deletion.
- Data in transit is encrypted (TLS); passwords are stored hashed.
11. Children
The Service is not directed at children. Accounts require you to be at least 13 years old (16 in Quebec). If we learn we hold an account created by a child below that age without verified parental consent, we will delete it.
12. Changes to this policy
If we change this policy we will update the effective date above; for material changes affecting account holders we will also email you. The current version is always at ezpdfeditor.aicanadiansolutions.ca/privacy.
13. Contact
AICS Solutions — Ontario, Canada.
Privacy Officer: Marcin Migdal — the person responsible for the protection of personal
information (the “responsable de la protection des renseignements personnels” under Quebec’s Law 25),
reachable at ezpdfeditor@aicanadiansolutions.ca.
Privacy questions and requests: ezpdfeditor@aicanadiansolutions.ca
(or ezpdfeditor@aicanadiansolutions.ca).
We acknowledge privacy enquiries within 5 business days and resolve substantive requests within 30 days.