Privacy Policy - PDF NEST
1. Introduction
PDF NEST values your privacy and is committed to being transparent about how we collect, use, and protect your personal data. This Privacy Policy explains our data practices and your rights.
2. Core Principle: 100% Local Processing
The most important aspect of PDF NEST is that all screen capturing, image processing, and PDF generation occur exclusively in your browser, on your device.
We DO NOT upload, transfer, or store:
- Content of the browser tabs you capture
- Images of the captured screens
- Generated PDF files
- Any visual or processed content data
You retain full control over all your visual data. PDF NEST has no access to what you capture.
3. Data We Collect
3.1 Authentication Data
When you create an account, we collect:
- Email Address (via Google OAuth)
- Google Unique ID (unique identifier provided by Google)
Purpose: To create and manage your account, enable login, and password recovery.
3.2 Subscription and Usage Data
We store in our database:
- Free credits count available in your account
- Subscription status (Free or PRO user)
- Last activity date (for administrative purposes)
Purpose: To track your usage plan, limit PDF generation according to your plan, and manage your subscription.
3.3 Payment Data
We do not collect, view, process, or store:
- Credit card numbers
- Expired card data
- CVV/CVC codes
- Any other financial information
Purpose: Stripe processes all payments securely and in isolation. We only receive transaction confirmations (approval/rejection).
4. Infrastructure and Third Parties
We use the following infrastructure services only to make the platform work:
4.1 Firebase/Firestore
- Function: Database to store User ID, email, credits, and subscription status.
- Data NOT stored: No visual content, images, or PDFs.
- Compliance: Google service with GDPR/LGPD compliance.
4.2 Stripe
- Function: Payment processing for PRO subscriptions.
- Data Stripe processes: Card data (in an isolated and secure manner).
- Data we never see: Card numbers, CVV, expiration dates.
- Compliance: Stripe follows PCI-DSS 3.2.1 and GDPR.
4.3 Chrome Extension Permissions
- activeTab & scripting: Required solely to capture visible screen content and temporarily remove ad elements upon your explicit action.
- identity: Used to authenticate your account via Google OAuth without storing passwords.
- storage: Used to save user preferences (language) and local credit caches.
5. Data Sharing
We NEVER sell, rent, or share your personal data with:
- Advertising or marketing networks
- Data brokers
- Non-essential analytics companies
- Any third party for any commercial reason
Legitimate exceptions:
- Compliance with law or court order (if required by law)
- Protection of rights and security (fraud, abuse, terms violations)
- Firebase and Stripe (as described in Section 4)
6. Data Retention
- Account data (email, Google ID): Kept while your account is active. Can be deleted at any time upon request.
- Subscription history: Kept for 24 months for accounting and tax purposes (as required by law).
- Transaction logs (Stripe): Managed by Stripe according to their retention policy.
Upon request for deletion, your personal data will be removed within 30 days, except when the law requires retention (e.g., tax records).
7. Your Rights
Under GDPR (EU) and LGPD (Brazil), you have the right to:
- Access your personal data
- Correct inaccurate information
- Delete your data ("right to be forgotten")
- Export your data in a readable format
- Revoke consent for marketing
- Object to data processing
To exercise these rights, contact us through the support form in the extension. We will respond within 15 business days.
8. Security
- All data is transmitted via HTTPS/TLS (encryption in transit).
- Passwords are not stored in plain text (we use Google OAuth authentication).
- Database access is restricted and audited.
- In-browser processing is isolated and sandboxed.
However, no system is 100% secure. If we discover a data breach, we will notify you within 72 hours.
9. Changes to this Policy
We may update this Privacy Policy occasionally. Your continued use of PDF NEST after the changes means consent to the new policy.
10. Contact
For any questions or data requests, contact us at: dcsgustavo@gmail.com