Legal
Privacy Policy
Last updated: 23 September 2026
Scope. This notice describes PDFWhirl's currently documented application and data-handling behavior. It is updated when material implementation or provider changes are verified.
Operator
PDFWhirl is operated by Kotipalli Srikesh in India. Privacy enquiries can be sent to support@pdfwhirl.com.
Information handled
If you create an account, PDFWhirl handles the email address and account identifiers needed to register, authenticate, and display account information. The browser stores the access token and basic user record in local storage after sign-in.
Uploaded files and processing
Files you select are uploaded so the requested tool can process them. File metadata is recorded by the file service, objects are stored in the configured Cloudflare R2-compatible storage, and supported workers temporarily download inputs while performing a job. Workers attempt to remove per-job temporary directories after processing. This does not delete stored input or output objects.
Uploads, downloads, and access
The browser sends selected inputs to the file service. The file service issues time-limited signed download URLs, and workers use signed upload URLs when registering generated outputs. Production frontend and gateway configuration uses HTTPS, and the gateway attaches security headers. These controls do not amount to a guarantee that every transmission or system is risk-free.
Authentication
Signed-in requests can include a bearer token. Passwords are hashed by the authentication service. Some current public tool requests can also run as an anonymous guest; users should not treat an anonymous browser session as a private account workspace.
Logs and diagnostics
Backend services produce operational logs and job status records for processing and diagnosis. PDFWhirl does not publish a fixed log-retention period because retention may vary by service, operational need, and infrastructure configuration.
Cookies, local storage, analytics, and advertising
The audited frontend stores sign-in information and a recent list of document job identifiers, tool names, statuses, timestamps, and output identifiers in browser local storage. A temporary session-storage flag prevents repeated reloads while obsolete service-worker data is removed. No Google Analytics or Google AdSense script was found in the frontend during this review. Hosting providers may apply essential network or security mechanisms outside the Angular code. If analytics or advertising is enabled later, this policy and any required consent controls will be updated before use.
Retention and deletion
Stored input and output objects are deleted automatically: files uploaded without an account are removed about 24 hours after upload, and files belonging to a signed-in account are removed after 7 days. A scheduled sweep enforces this hourly against the object store itself. Workers attempt to remove per-job temporary directories after processing. This does not delete stored input or output objects.
The file API can request deletion of a stored object and then soft-delete its metadata, but the current public interface does not consistently expose that API control. A deletion API request makes a best-effort attempt to remove the object and then marks its database metadata as deleted. Account-information or file-deletion requests can also be sent through the privacy request channel below.
Service providers and international processing
PDFWhirl uses Railway for application-service hosting and Cloudflare services for site delivery, including Cloudflare R2 for object storage. It also relies on database and queue services. Data may be processed in locations used by those providers. PDFWhirl does not publish a fixed provider-region or subprocessor list beyond the services named here because provider infrastructure and locations can change.
Your choices and rights
You can clear browser storage, avoid creating an account, and use the published privacy request channel for file or account deletion questions. Applicable privacy law may provide additional rights. Email support@pdfwhirl.com for a private privacy enquiry.
Privacy requests and account deletion
To request access to, correction of, or deletion of account information, or to withdraw a previous consent, email support@pdfwhirl.com from the address associated with the account. State the type of request and the account email. Do not attach identity documents, passwords, or uploaded PDFs unless support first explains a necessary and secure verification method.
Support may request proportionate information to verify account ownership before acting. The published email process is available even when an in-account control does not cover the requested action. A request does not override records that must be retained under applicable law or information that cannot be reliably linked to the requester.
India and regional privacy requirements
PDFWhirl is operated from India. India’s Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 have phased commencement dates. This notice and the request channel above are operational transparency measures; they are not a claim that every provision applies or is already in force. Users in other regions may have additional rights under applicable law, and the site’s advertising consent configuration is reviewed before ads are enabled in those regions.
The phased commencement is documented in the Government of India commencement notification and the Digital Personal Data Protection Rules, 2025.
Children
PDFWhirl is not presented as a service directed to children. Users should only use the service when they are permitted to do so under the laws that apply to them, with parent or guardian involvement where required.
Changes and contact
This notice may change as the product and its data practices change. Material implementation changes will be reflected here. See the Contact page for currently published channels.