Privacy Policy
Last updated September 23, 2026
This policy explains, in plain language, what PDFlora does and does not do with your files and your personal data. The short version: most tools run entirely in your browser, and we do not ask you to create an account.
Who is responsible for your data
The website florapdf.com is operated by PDFlora (the 'operator', 'we' or 'us'). For the limited personal data described in this policy, PDFlora acts as the data controller. You can reach us at hello@capriapp.app for any question about privacy or to exercise your rights.
This policy applies to the website and to the PDF tools offered on it. It does not apply to other websites that you may reach through links, or to the services of the third parties named below, which have their own policies.
The short version
There are no user accounts, and we do not ask for your name, address or phone number to use a tool. No payment is needed to use any tool; an optional, voluntary tip is possible, as explained in the section on voluntary tips.
Here is what we do and what we do not do in practice:
- Browser tools: your files are read and processed on your own device. They are not uploaded to us and we do not store them.
- Server tools (Word, Excel, PowerPoint and HTML to PDF): the file is uploaded over HTTPS, converted, sent back to you and then deleted. Details are in the section on server processing.
- We do not use your files or their contents for training, analytics or advertising, and no human reviews them.
- Analytics and advertising are optional and only run if you consent. You can change your mind at any time.
Files processed in your browser
Most tools, including merge, split, compress, rotate, sign, redact, protect, convert to and from images, and OCR, work with JavaScript and WebAssembly running inside your browser. The file you select is read from your device into your browser's memory, processed there, and the result is created in memory and downloaded by you.
For these tools, your file is not sent to our servers and is not stored by us. When you close or reload the page, the working data in your browser's memory is released. Files you download are saved on your device, and from that moment they are under your control only.
The sign tool can, if you choose 'remember on this device', keep your signature in your browser's local storage. That data stays on your device and you can delete it by clearing your browser's site data.
Files processed on our server
Four tools convert office or web documents and need server software: Word to PDF, Excel to PDF, PowerPoint to PDF and HTML to PDF. For these tools only, the file you choose is uploaded to our server over an encrypted HTTPS connection.
The uploaded file is placed in a private temporary directory named with a random job identifier and is processed by LibreOffice or WeasyPrint with restricted resources, such as time and size limits. The result is streamed back to you. The whole job directory, including the input, the output and any intermediate files, is deleted immediately after delivery, and also if the job fails, times out or is cancelled. As a safety net, a background task removes anything older than 20 minutes (this value is configurable by the operator).
We do not keep documents in object storage or in a database, we do not review them, and we do not use them for training or analytics. Our technical logs for these jobs contain only a job identifier, the tool name, a size class, the duration and the outcome or error code. They never contain file names or file contents.
OCR and the public CDN
The OCR tool runs in your browser using Tesseract.js. The first time you use it, your browser downloads the OCR engine and the language files you selected from a public content delivery network (CDN), jsDelivr.
That request tells jsDelivr your IP address and the standard information every browser sends with a request, such as the browser type. jsDelivr does not receive your documents: they are never uploaded and stay in your browser. jsDelivr processes this technical data under its own privacy policy.
Cookies and local storage
We use a small number of essential or functional items: a cookie named NEXT_LOCALE that remembers your language for one year, a theme entry in your browser's local storage that remembers light or dark mode, and a consent-v1 entry in local storage that remembers your cookie choice. These are needed to provide the features you ask for and do not track you across sites.
Analytics and advertising cookies are only set after you consent. The full list and how to manage each item is in our Cookie Policy.
You can change or withdraw your consent at any time by using the 'Cookie settings' link in the footer of every page. You can also delete cookies and local storage in your browser settings; the site will then ask for your choice again.
Analytics
If the operator has enabled it, and only after you consent, we use Google Analytics 4 to understand which tools are used and to improve them. The events we record are anonymous and limited to things like the tool name, the interface language, the tool category and an event type such as file selected, processing completed or download clicked.
We never send file names, file contents or OCR text to analytics. IP anonymization is on by default in Google Analytics 4. If you do not consent, or if you later withdraw consent, no analytics events are collected.
Advertising
If the operator has enabled advertising, and only after you consent, the site shows ads served by Google AdSense. Google and its partners may use cookies or similar identifiers to serve and measure ads, and to limit how often you see them. The site tells Google about your choice through Google consent mode.
If you reject advertising or withdraw your consent, these cookies are not used for ads on this site. You can change your choice at any time with the 'Cookie settings' link in the footer. Google describes how it uses data in its own privacy policy and in its advertising controls.
Server logs and IP addresses
Like almost every website, the web server and the hosting provider keep standard access logs. These typically include your IP address, the date and time, the requested address, the response status and your browser's user agent.
We use these logs to keep the service secure, to detect abuse and to troubleshoot errors. They are kept for a limited period that is set by the hosting configuration; we do not promise a specific duration here. We do not use logs to identify you personally and we do not combine them with the content of your files.
Voluntary tips
The site has an optional page, /support, where you can leave a voluntary, one-time tip. A tip buys nothing: every tool stays available without paying, no account is needed and no feature is unlocked.
Payment is handled entirely by Stripe (Stripe Payments Europe or Stripe, Inc.) on Stripe's own hosted checkout page: you are redirected to stripe.com. We never see, receive or store your card number or wallet details, and we load no Stripe scripts on our own pages. Your tool files are never involved in a tip.
From Stripe we receive only limited information about the tip: the amount, the currency, the date, the payment status and, only if you enter them on Stripe's page, a name and/or email address. We use it to confirm the tip and thank you, to meet our accounting and tax obligations, and to prevent fraud and abuse. Stripe acts as an independent controller for its own processing of payment data, which is governed by Stripe's own privacy policy.
Legal bases: contract (processing the tip you chose to give), legal obligation (accounting and tax records) and legitimate interests (fraud prevention). We keep tip records for as long as accounting and tax law requires. We set no cookies of our own for tips; Stripe's own cookies apply only on Stripe's page. The rights described below also apply to these records, and questions about a tip can be sent to hello@capriapp.app.
Third parties and international transfers
Depending on how the operator has configured the site, the following third parties may be involved: the hosting provider that serves the website and keeps the server logs, jsDelivr (the CDN used by the OCR tool), Stripe (only if you choose to leave a voluntary tip), Google Analytics (only with your consent) and Google AdSense (only with your consent). We do not sell your files, and we do not share them with anyone.
Some of these providers may process data in countries other than your own, including countries that may not offer the same level of data protection. Where the law requires it, such transfers rely on appropriate safeguards, for example standard contractual clauses or the provider's certification under a recognised framework. The exact location depends on the hosting and on the providers the operator has enabled.
Legal bases and retention
Under the GDPR and similar laws, we rely on the following legal bases: our legitimate interests in operating and securing the service (server logs, essential cookies, technical processing, fraud prevention), your consent (analytics and advertising), the need to provide the tool you asked for (processing the file you submit) or to process a tip you chose to give (contract), and our legal obligations (accounting and tax records).
We keep data only as long as needed for these purposes. Files in browser tools are never stored by us. Files in server tools are deleted immediately after delivery and in any case within the automatic cleanup interval of 20 minutes by default. Server logs are kept for the period set by the hosting configuration. Your cookie choice stays in your browser until you change or clear it. Tip records are kept for as long as accounting and tax law requires. Data held by Google, jsDelivr or Stripe follows their own retention rules.
Security
Traffic between your browser and the site is protected by HTTPS. On the server, uploaded files are placed in a private temporary directory under a random job identifier, are processed with restricted resources, and are deleted right after delivery.
No system is perfectly secure, and we cannot guarantee absolute security. Please do not use the server tools for documents that you are not allowed to send to a third-party server, and prefer the browser tools when you handle highly sensitive files.
Your rights
Depending on where you live, and in particular under the GDPR, the UK GDPR, the Swiss Federal Act on Data Protection (FADP) and the California Consumer Privacy Act (CCPA), you may have the right to access your personal data, to have it corrected or erased, to restrict or object to its processing, to receive it in a portable format, and to withdraw consent at any time without affecting earlier processing.
California residents can also ask what personal information is collected and how it is used, ask for deletion, and opt out of the sale or sharing of personal information. We do not sell your files. Advertising cookies from Google may count as 'sharing' under some laws, and they only run if you consent, so rejecting them or using 'Cookie settings' is your opt-out. We do not discriminate against you for using these rights.
To exercise a right, write to hello@capriapp.app. We may need to confirm that a request comes from you. Because files in our tools are not stored, there is usually nothing to retrieve or erase, and we will tell you so. You also have the right to lodge a complaint with your local data protection or supervisory authority.
Children, payments, changes and contact
The service is not directed to children under 16 (or under 13 in the United States). We do not knowingly collect personal data from children. If you believe a child has provided personal data, contact us at hello@capriapp.app and we will act on it.
The only payment possible is the optional, voluntary tip described above, which Stripe handles on its own page. We never collect card or wallet details.
We may update this policy when the service or the law changes. The date of the latest update is shown on this page, and material changes will be visible here. For any question about this policy, write to hello@capriapp.app.