Privacy Policy
Last updated 4 August 2026
The short version
- • Free tools need no account. Your file is processed and deleted — we don't keep a copy.
- • We never use your files to train any AI model, ours or anyone else's.
- • We don't sell or rent your data to anyone, for any reason.
- • Pro features need an account (email, via Clerk) so we can manage access over time.
- • You can ask us to export or delete your account data any time — see §10.
1. Who operates this service
iGuardPDF is an independent product — not a division of a larger platform, and not affiliated with any other document-tools company. For the purposes of data protection law, iGuardPDF is the data controller for the personal data described in this policy. You can reach us at iguardpdf@hotmail.com for anything covered here.
2. Files you upload
When you use a free tool (merge, split, compress, convert, sign, watermark, password protect, unlock), your file is transmitted over an encrypted connection (TLS), processed in memory or briefly on disk to perform the requested operation, and then deleted. We don't archive uploads, back them up, or use them for any purpose beyond completing the action you requested — including not using them to train any AI model, ours or anyone else's.
What we don't do
We don't scan file contents for advertising purposes, build a profile from what you upload, or retain a copy "just in case." Once the tool has produced your output and it's been downloaded (or the request times out), the input and output are gone.
3. Account data (Pro features)
Free tools require no account. If you sign up for a Pro feature, our authentication provider (Clerk) collects the account details needed to sign you in — typically your email address and authentication tokens — and issues a session cookie so you stay signed in. We don't store passwords ourselves; Clerk handles that under its own security practices.
For Guarded (fingerprinted) documents, we also store: which tool produced the document, whether it was Guarded, a document identifier, and the embedded fingerprint value used for leak tracing — never the document content itself alongside that record.
4. Photo verification (Pro feature)
A document owner can turn on photo verification for a Guarded share link — whoever opens it is asked to take a live photo before the document unlocks. That photo is encrypted at rest, viewable only by the document owner inside their own dashboard (never emailed, never pushed anywhere else), and reviewed under a hard 60-second decision window once opened. The photo is permanently deleted the moment a decision is made — approved or denied — and automatically deleted within 24 hours regardless, if it's never reviewed at all. There's no facial recognition and no automated identity matching: a real person (the document owner) makes the call, the same way they'd recognize someone in person.
5. Why we're allowed to process this data
Under UK/EU GDPR, our legal basis for each category of processing is:
- Files you upload to free tools — contract/legitimate interest: processing is the entire point of the request you made, and we minimize it to exactly that.
- Account data for Pro features — contract: we need it to provide the service you signed up for.
- Photo verification (once live) — explicit consent, separately from any other consent, revocable at any time. See §4.
8. International data transfers
Our infrastructure providers operate global networks, which can mean data is processed outside your home country. Where that crosses into the EU/UK from elsewhere (or vice versa), our providers rely on their own appropriate safeguards (such as Standard Contractual Clauses) — we don't independently transfer your data anywhere beyond what those providers do to deliver the service.
9. How long we keep data
- Free-tool file uploads/outputs — deleted immediately after the request completes, typically within seconds.
- Account data (Pro) — retained while your account is active, deleted within 30 days of account deletion.
- Document fingerprint records — retained while the associated account is active, so leak-tracing keeps working; deleted with the account.
- Photo verification captures (once live) — hard 24-hour maximum retention regardless of outcome; see §4.
- Contact form submissions — retained until resolved plus a reasonable period for follow-up, then deleted.
10. Your rights
Depending on where you live, you may have the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Request deletion ("right to be forgotten")
- Request a portable export of your data
- Object to or restrict certain processing
- Withdraw consent at any time, where processing is based on consent
Exercise any of these by emailing iguardpdf@hotmail.com. We'll respond within 30 days. If you're in the EU/UK and unsatisfied with our response, you can also complain to your local data protection authority (the ICO, if you're in the UK).
11. California residents (CCPA/CPRA)
We don't sell or share personal information as those terms are defined under the CCPA/CPRA. California residents have the same practical rights described in §10 — access, deletion, correction, and opt-out of sale (which doesn't apply here, since we don't sell data). Contact us at the email above to exercise them.
12. Children
iGuardPDF isn't directed at children under 16, and we don't knowingly collect their data. If you believe a child has provided us personal data, contact us and we'll delete it.
13. How we secure your data
TLS encryption in transit on every request, AES-256 encryption on Password Protect output, and envelope encryption (a unique key per item, wrapped by a master key) for anything stored for Pro features. Full detail on our Security page.
14. Changes to this policy
If this policy changes materially, we'll update the date at the top of this page and, for significant changes affecting Pro users, notify you directly. Continued use of the service after a change means you accept the update.
15. Contact
Questions about this policy, or want to exercise any right described above? Email iguardpdf@hotmail.com or use the form on our Contact page.
This page describes our actual data practices in plain language. It isn't a substitute for independent legal advice if you need specific compliance guidance for your own use of the service.