Privacy Policy
Last updated 28 August 2026 · PDFlare is a product of NextGenOmni
Privacy is the product's core design constraint, so this policy is short — there is very little to disclose.
- Your documents never leave your machine. All PDF processing runs locally. There is no upload code path, no cloud storage, no AI service.
- The app's only network traffic is (a) licence activation and a lightweight licence check-in, and (b) an update check. That is the complete list — verify it behind a firewall or packet sniffer.
- No analytics, no telemetry, no tracking, no ads, no data sales.
- No account is required — just a licence key.
What the app sends, exactly
1. Licence activation and check-in. When you activate your key, and during a periodic background check-in, the app sends: your licence key; salted SHA-256 hashes of up to three hardware identifiers — never the raw identifiers (hashing happens on your machine, we cannot reverse it, and the same hardware produces a different hash for any other product); operating system and OS version; the device name you chose; and the app version.
That is the full list. The check-in exists so licence upgrades reach you and so a refunded key can be revoked. Missing it — indefinitely — never disables the app.
2. Update check. The app asks our server whether a newer version exists, sending your operating system and update channel. No identifiers, no document data.
What is never sent: your documents, their contents, their filenames, raw hardware identifiers, usage data, or anything else not listed above.
What we store on our servers
- Licence record: your key, tier, device allowance, status, purchase source, and the email address from your purchase.
- Device records: per activated device, the hashed fingerprint components, your chosen device name, OS and OS version, app version, and activation / last-seen timestamps. These power the self-service device list in the app.
- Order record: purchase date, amount, currency, country, and email — what we need for accounting, tax, and honouring the 60-day refund.
Payments
Direct purchases are processed by Stripe; AppSumo purchases by AppSumo. Your card details go to the payment processor, not to us — we never receive or store card numbers. Stripe and AppSumo handle your payment data under their own privacy policies.
Server logs
Like any internet service, our licence server sees the IP address of requests and uses it for rate limiting and abuse prevention. Logs are rotated and deleted within 30 days. Licence keys are never placed in URLs, so they do not appear in access logs.
Your rights
- Erasure (GDPR Art. 17 and similar laws): email us and we erase your personal data — your email address is blanked from licence and order records. We retain the resulting pseudonymous licence record (key, tier, hashed fingerprints) so your purchase keeps working; it no longer identifies you.
- Access: ask and we will tell you what we hold about you (it is the short list above).
- Deactivation: you can remove any device from your licence yourself, in the app.
- If you believe we have mishandled your data you can complain to your local data protection authority; we would appreciate the chance to fix it first.
Retention
Licence records are kept for as long as the licence exists — it is perpetual, so honouring it requires keeping the (pseudonymised, on request) record. Order records are kept as long as tax and accounting law requires.
Changes and contact
If this policy changes, the new version is published here and with the app; we will not weaken the core promises above — the product exists because of them.
Questions or requests: pdflare-support@nextgenomni.com