PD EZ PDF Editor ← Back to the tools

Privacy Policy

Effective date: July 16, 2026

In short: the PDF and image tools run in your browser — for ordinary editing, filling, signing, converting and OCR, your files never reach our servers at all. Data only touches our server when you use a feature that needs it: creating an account, saving documents to the cloud, sending a signature request, the voice form-fill AI (the spoken text, never audio, goes to OpenAI), or the handful of conversions that require a server. This page spells out exactly which is which.

EZ PDF Editor (the “Service”) is operated by AICS Solutions (“we”, “us”), Ontario, Canada. This policy explains what we collect, why, who we share it with, how long we keep it, and your rights under Canada’s federal Personal Information Protection and Electronic Documents Act (PIPEDA) and, for Quebec residents, the Act respecting the protection of personal information in the private sector as amended by Law 25. Questions: ezpdfeditor@aicanadiansolutions.ca.

1. What runs in your browser (and never reaches us)

The core of EZ PDF Editor is deliberately client-side. When you use these tools, your file is opened and processed by JavaScript running on your device, and the result is saved straight back to your device:

Documents you work on are cached locally in your browser’s storage (IndexedDB / localStorage) so you can pick up where you left off. That local copy is on your device only; clear the site’s data in your browser to remove it.

2. What we collect, and when

Nothing in this section happens unless you use the feature that needs it.

a) Account (optional)

If you create an account we store your email address, a salted-and-hashed password (never the password itself), email-verification and password-reset tokens, and sign-in session tokens (valid 30 days). Verification and reset emails are sent through SendGrid.

b) Saved documents & autofill profile (signed-in, explicit save)

If you choose to save a document to your account, the document’s contents are stored on our server so you can reopen it from any device. If you save an autofill profile (e.g. your name, address and contact details for filling forms), that profile is stored against your account. Both exist only because you pressed save, and both are deleted with your account.

c) Usage history (signed-in)

For signed-in users we keep a history of tools you used (tool name, page count, file name and size) and, so you can re-download results later, a copy of the output file. You can delete any history entry — and its stored file — yourself from inside the app.

d) E-signature requests

When you send a document for signature we necessarily store: the PDF you uploaded, the recipient names and email addresses you entered, each signer’s signature image, signing tokens, the IP address from which each signature was submitted (fraud evidence), and the final signed PDF. Signers receive emails via SendGrid.

e) Voice form-fill (AI)

When you fill a form by talking:

f) Server-side conversions

g) Payments

Pro subscriptions are processed by Stripe. Your card number goes to Stripe, never to us; we store only your Stripe customer/subscription identifiers and payment totals for accounting.

h) Analytics & logs (all visitors)

We run our own first-party analytics — no advertising networks, no fingerprinting. Each page view or tool use records: timestamp, IP address, user agent (device type, OS, browser family), the page/tool, and the referring page. Standard web-server logs (IP, timestamp, URL) also exist for security and troubleshooting. We additionally keep per-IP daily counters for rate-limiting the AI and conversion endpoints. We also offer optional Google Analytics, which loads only if you accept the analytics consent banner (see Section 6).

i) Video Signing Room (live sessions & recordings)

When you host or join a live video signing session we process your video and audio stream (for the live call) and, if the host starts recording, store the recording. Recordings may capture participants’ faces, voices and anything shown on camera or screen. Only the host controls recording. Recordings are kept for the host’s professional records and deleted automatically 24 months after the session, or sooner if the host deletes them (see Retention). If you join as a guest you are asked for your explicit consent before joining; your consent is recorded in the session’s compliance audit trail.

j) Identity verification (ID photos & selfies)

For certain signings the host may ask guests to upload a photo of their government-issued ID and a selfie, which the host compares against the guest’s live video before accepting a signature. These images are stored with the session and destroyed automatically 30 days after they are submitted by a scheduled job — sooner if the host deletes the session. What remains afterwards is the result of the check in the audit trail, never the ID photo or the selfie. Identity verification is optional per session (the host may also confirm a guest personally), and your consent is recorded in the audit trail.

k) AI legal document drafting

Pro Signing subscribers can generate draft legal documents. The document type, profession, jurisdiction, party names/emails and other details you provide are sent to OpenAI (our AI provider) to produce the draft. We do not use your documents to train AI models. If an AI-generated document is later signed in a Video Signing Room, participants are informed (in the consent step) that an AI drafting provider processes personal information in the document.

l) Contacts & Signees

When you invite a signing guest, their name, email, occupation, phone, city and province are stored so they can be re-invited (your “Contacts & Signees” list) and so the compliance audit trail records who participated. You can edit or delete any contact, and contacts are deleted with your account.

3. What we do not collect

4. How we use information

We do not use your documents, transcripts or personal information to train AI models.

Signing evidence: tamper-seals, Audit Reports & audit

Completed signings are tamper-sealed: a Certificate of Signing & Seal page is appended to the PDF and a cryptographic fingerprint of the sealed file is stored with the session record and written to the audit trail. Anyone can verify that a copy is unaltered by uploading it to /seal — we compare its fingerprint to the stored seal and report whether it is the original. Hosts can also export a per-session Audit Report (PDF or CSV) from Session Audits, and can set signing order and per-signer page visibility for a session. These records exist to help you demonstrate consent, identity, intent and document integrity; you are responsible for keeping and retaining them as your profession or applicable law requires.

5. Sub-processors & third-party services

ProviderPurposeWhat they see
OpenAI, L.L.C. (US)Voice form-fill: mapping your spoken text to form fields The text transcript of what you said and the form’s field labels — transiently, per request. Not used for model training per OpenAI’s API terms.
ConvertAPI (EU/US)PDF → Word/Excel/PowerPoint conversion The PDF you submit for that conversion — transiently, with file storage disabled.
Twilio SendGrid (US)Transactional email (verification, resets, signature invitations, signed copies) Recipient email addresses and the message content, including a signed PDF when one is attached.
Stripe (US/Canada)Payment processing for Pro Your email and payment details. PCI DSS Level 1 certified.
RevenueCat (US)Mobile (Android) subscription entitlements Your user identifier and subscription status, so the app knows your plan.
OpenAI, L.L.C. (US)AI legal document drafting (in addition to voice form-fill) Document type, profession, jurisdiction, party names/emails and notes you provide — transiently, per request. Not used for training per OpenAI’s API terms.
DigitalOcean (Canada — Toronto region)Hosting of our server and database Everything stored server-side lives on infrastructure in Canada.
CDN & fonts (jsDelivr, Google Fonts)Delivering the in-browser OCR engine and web fonts A standard web request (your IP and user agent) when your browser fetches the script or font. Your files are never sent to them.
Browser speech service (e.g. Google, Apple)Speech-to-text for voice form-fill, performed by your own browser Your voice audio, under the browser vendor’s privacy policy — this happens on/through your device, not our servers.

Data residency: our server and database are hosted in Canada. The transient exceptions are the round-trips to OpenAI, ConvertAPI, SendGrid and Stripe described above, whose endpoints may be served from the United States or Europe. Under PIPEDA we remain accountable for personal information we transfer for processing.

6. Cookies & local storage

We do not use advertising cookies. We offer optional, consent-based analytics: if you click “Accept analytics” on the consent banner, Google Analytics is loaded to help us understand which tools are used. Your choice is stored on your device, and you can revoke it at any time by clearing the site’s data. No analytics load unless you accept. The Service keeps a small amount of data in your browser’s local storage: your sign-in token (if you have an account), your in-progress documents, and small preference flags (e.g. whether you dismissed the tour or a sign-up nudge). All of it stays on your device and is removed when you clear the site’s data.

7. Retention

DataKept
Client-side documentsOn your device only — until you clear your browser data.
Account, saved documents, autofill profile, usage history, signature requests While your account exists; erased within 30 days of a verified deletion request (usually within 7). You can delete usage-history files yourself anytime.
Server-conversion working filesDeleted immediately after the conversion completes.
Voice transcripts sent to the AINot stored — processed and discarded; only token-count metadata is kept.
Analytics & server logs (IP-level)Rotated out, typically within 90 days.
Video Signing Room recordings 24 months (730 days) from the recording, then deleted automatically by a scheduled daily job. The period covers the two-year basic limitation period during which a signing is most likely to be questioned. The host may delete a recording sooner at any time. Not used by us for any other purpose.
Identity-verification ID photos & selfies 30 days from submission, then destroyed automatically by a scheduled daily job. These are the most sensitive images we ever hold, so they are kept only long enough to complete the verification and cover an immediate dispute. The result of the check (who was verified, when, and by whom) stays in the session’s audit trail — the images themselves do not.
AI legal document inputs sent to OpenAINot stored by us — transmitted to the provider per request; we keep only token-count/usage metadata.
Encrypted backupsPurged on normal rotation within 30 days.
Tamper-seal records (sealed PDF fingerprints)Stored with the session/request records and in the audit trail; removed with the session or account per this table.
Audit Reports (PDF/CSV exports)Generated from the session record when you export them; the underlying session record is kept per the rows above.
Billing records (held by Stripe)As required by Canadian tax law — generally up to 7 years.

8. Your rights (PIPEDA & Quebec Law 25)

At no charge, you may:

Automated processing: the only automated step that touches your data is the AI’s suggestion of which value goes in which form field — every suggestion is shown to you as editable text before anything is final, and no consequential decision about you is ever made automatically. Quebec residents may ask us to explain any automated suggestion or to have a human review it.

Breach notification: if a breach of security safeguards creates a real risk of significant harm, we will notify affected users and the OPC (and, for Quebec residents, the CAI) as soon as feasible, as PIPEDA’s regulations and Law 25 require. We maintain a confidential register of confidentiality incidents as Law 25 requires.

Privacy by design: new features that process personal information (such as the Video Signing Room, identity verification and AI document drafting) are assessed before launch, including a privacy impact assessment where the law calls for one, so that privacy is built in rather than added later.

9. Deleting your account & data

Full instructions, what exactly gets erased, and the few records we must keep are on the dedicated Delete your account & data page. Summary: email ezpdfeditor@aicanadiansolutions.ca from your account address and we erase everything within 30 days (usually 7). This is also the deletion path for the Android app: the app is the same Service, and deleting your account removes the same data.

10. Google Play data-safety summary

For users of the Android app, in Play data-safety terms:

11. Children

The Service is not directed at children. Accounts require you to be at least 13 years old (16 in Quebec). If we learn we hold an account created by a child below that age without verified parental consent, we will delete it.

12. Changes to this policy

If we change this policy we will update the effective date above; for material changes affecting account holders we will also email you. The current version is always at ezpdfeditor.aicanadiansolutions.ca/privacy.

13. Contact

AICS Solutions — Ontario, Canada.
Privacy Officer: Marcin Migdal — the person responsible for the protection of personal information (the “responsable de la protection des renseignements personnels” under Quebec’s Law 25), reachable at ezpdfeditor@aicanadiansolutions.ca.
Privacy questions and requests: ezpdfeditor@aicanadiansolutions.ca (or ezpdfeditor@aicanadiansolutions.ca). We acknowledge privacy enquiries within 5 business days and resolve substantive requests within 30 days.