Privacy Policy
Last Updated: January 24, 2026
At GrzenPilot ("we", "us", or "our"), we take your privacy seriously. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our PDF2JSON API Service.
1. Information We Collect
1.1 Account Information
When you register for our Service, we collect:
- Email address: Used for authentication and communication
- Authentication tokens: Provided by Google OAuth or our email verification system
- Account creation date and last login information
1.2 Document Data
When you use our Service, we process:
- PDF files: Temporarily stored during processing, deleted after extraction
- Extracted text: May be sent to Google Gemini API for template generation
- Templates: JSON extraction templates you create and store
- Extraction results: JSON output from your conversions
- Sample documents: PDFs used for template creation (stored for template reference)
1.3 Usage Data
We automatically collect:
- API request logs (timestamps, endpoints, response codes)
- Template usage statistics
- Error logs and diagnostic information
- IP addresses (for security and abuse prevention)
- Browser type and operating system (from web interface access)
1.4 Cookies and Tracking
We use:
- Session cookies: To maintain your authenticated session
- JWT tokens: For API authentication (stored client-side)
- We do not use third-party tracking or advertising cookies
2. How We Use Your Information
We use collected information for the following purposes:
2.1 Service Provision
- Process your PDF documents and generate JSON output
- Create and store extraction templates
- Authenticate and authorize access to your account
- Provide customer support and respond to inquiries
2.2 Service Improvement
- Analyze usage patterns to improve performance and features
- Monitor and diagnose technical issues
- Develop new features and capabilities
- Create anonymized, aggregated statistics
2.3 Business Operations
- Calculate usage for future billing purposes
- Detect and prevent fraud and abuse
- Comply with legal obligations
- Send service announcements and updates
3. Data Sharing and Disclosure
3.1 Third-Party Services
We share data with the following third-party services:
Google Gemini API:
- Extracted text from your PDFs is sent to Google for AI-powered template generation
- Subject to Google's privacy policy and terms of service
- Used only during template creation, not during template-based extraction
Auth0:
- Handles OAuth authentication and user identity verification
- Subject to Auth0's privacy policy
- We receive only your verified email address
3.2 Legal Requirements
We may disclose your information if required to:
- Comply with legal obligations, court orders, or government requests
- Enforce our Terms and Conditions
- Protect our rights, property, or safety, or that of others
- Investigate fraud, security issues, or technical problems
3.3 Business Transfers
If we are involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you via email and prominent notice on our Service.
3.4 What We Don't Do
We do NOT:
- Sell your personal information to third parties
- Share your documents or templates with other users
- Use your content for advertising or marketing to third parties
- Train AI models on your private documents
4. Data Storage and Security
4.1 Storage Location
Your data is stored:
- In SQLite databases on our servers
- In file system storage for templates and logs
- Temporarily in memory during processing
4.2 Security Measures
We implement security measures including:
- Encrypted HTTPS connections for all data transmission
- Secure authentication via OAuth 2.0 and JWT tokens
- Token expiration (24 hours for API tokens)
- Server-side validation and input sanitization
- Regular security updates and patches
- Access logging and monitoring
4.3 Data Retention
We retain data for the following periods:
- Account data: Until account deletion or 2 years of inactivity
- Templates: Indefinitely or until you delete them
- API logs: 90 days
- Uploaded PDFs: Deleted immediately after processing
- Sample documents for templates: Retained with template unless deleted
- Extraction results: 30 days or configurable per user
5. Your Rights and Choices
5.1 Access and Portability
You have the right to:
- Access your personal information and account data
- Export your templates and extraction results
- Request a copy of your data in a portable format
5.2 Correction and Deletion
You can:
- Update your account information through the web interface
- Delete individual templates at any time
- Request deletion of your account and all associated data
5.3 Data Deletion Requests
To delete your account and data, contact us via the information provided below. We will:
- Confirm your identity
- Delete your account within 30 days
- Provide confirmation of deletion
- Retain only data required for legal or business obligations
5.4 Opt-Out Rights
You can:
- Opt out of service announcement emails (critical security notices may still be sent)
- Disable cookies through your browser settings (may affect functionality)
- Stop using the Service at any time
6. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence. These countries may have different data protection laws. By using our Service, you consent to such transfers.
7. Children's Privacy
Our Service is not intended for users under 18 years of age. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately.
8. Third-Party Links
Our Service may contain links to third-party websites. We are not responsible for the privacy practices of these external sites. We encourage you to review their privacy policies.
9. Data Processing for AI
Important: When you create templates, extracted text from your PDFs is sent to Google Gemini API for AI processing.
This data is:
- Processed by Google's servers
- Subject to Google's privacy policy and data handling practices
- Used to generate extraction templates based on your document structure
- Not stored by us beyond what's necessary for template creation
Best Practice: Do not upload documents containing sensitive personal information, trade secrets, or confidential data during template creation if you are concerned about third-party processing.
10. Your California Privacy Rights (CCPA)
If you are a California resident, you have additional rights:
- Right to Know: Request details about personal information we collect
- Right to Delete: Request deletion of your personal information
- Right to Opt-Out: Opt out of sale of personal information (we don't sell data)
- Right to Non-Discrimination: Equal service regardless of privacy rights exercise
11. GDPR Compliance (EU Users)
If you are in the European Economic Area (EEA), you have rights under GDPR:
- Legal Basis: We process data based on consent, contract performance, and legitimate interests
- Right to Access: Obtain confirmation and access to your data
- Right to Rectification: Correct inaccurate data
- Right to Erasure: Request deletion ("right to be forgotten")
- Right to Data Portability: Receive data in structured format
- Right to Object: Object to certain processing activities
- Right to Lodge Complaint: File complaint with supervisory authority
12. Changes to This Privacy Policy
We may update this Privacy Policy periodically. Changes will be posted on this page with an updated "Last Updated" date. Material changes will be communicated via:
- Email notification to registered users
- Prominent notice in the web interface
- Notice period before changes take effect (for material changes)
13. Contact Us
For privacy-related questions, concerns, or requests, please contact us:
- Website: grzenpilot.com
- Service: convertpdf2json.com
- Company: GrzenPilot
We will respond to your request within 30 days.