Privacy Policy
1. Who we are
This Privacy Policy applies to ApexDoc (“ApexDoc”, “we”, “us”, or “our”), including the marketing and account website, authentication flows, Stripe checkout, and the gated PDF workspace. It should be read together with our Terms of Service.
Depending on how you use ApexDoc, we may act as a controller for account and billing-related personal data, and as a processor for document content that you choose to upload and process in the workspace.
2. Scope of this Policy
This Policy covers personal information processed when you:
- visit ApexDoc web pages;
- create or sign into an account (email/password or Google Sign-In);
- purchase a monthly or lifetime plan through Stripe;
- open and use the ApexDoc PDF workspace;
- contact support about billing, access, or security.
It does not cover third-party websites linked from ApexDoc, except for our described use of processors such as Firebase Authentication and Stripe. Those providers have their own privacy notices.
3. Privacy principles we follow
We designed ApexDoc around these commitments:
- Data minimization. We collect the least personal data needed to run accounts, payments, and access control.
- Purpose limitation. Account and document data are used to provide and secure the Service, not for unrelated advertising.
- No sale of document contents. Your PDFs are not sold, rented, or licensed to data brokers.
- Security by default. Access to the workspace requires authentication and a valid paid plan.
- Transparency. This Policy aims to explain our practices in plain professional language.
- User control. You can request account-related deletion and access information through verified support channels.
4. Personal data we collect
4.1 Account data
When you register or sign in, we may process:
- full name or display name;
- email address;
- authentication identifiers (such as a Firebase user ID);
- sign-in method (email/password or Google);
- password credentials handled by Firebase Authentication (we do not store plaintext passwords);
- basic account timestamps such as creation or last sign-in metadata provided by our auth provider.
4.2 Billing and license data
When you purchase a plan, Stripe processes payment details. ApexDoc may receive and store related business records such as:
- customer email used at checkout;
- Stripe customer ID and subscription/session identifiers;
- plan type (monthly or lifetime);
- payment status and limited invoice/receipt metadata;
- license validity signals needed to unlock or revoke workspace access.
ApexDoc does not store full payment card numbers, CVV codes, or complete card magnetic/track data on its application servers. Card entry occurs in Stripe-hosted checkout.
4.3 Document and workspace data
When you use the PDF workspace, the files you upload and the outputs you generate are processed to fulfill your request. Depending on configuration and tool behavior, files may exist temporarily in memory, temporary storage, logs associated with processing errors, or local browser/session artifacts on your device.
Document contents may include personal data of third parties (employees, customers, counterparties). You control what you upload. We process those files to provide the feature you invoke, not to build marketing dossiers.
4.4 Technical and security data
To operate and protect the Service, we may process:
- IP address and approximate network metadata;
- browser/user-agent information;
- cookie or local session identifiers required for authentication;
- request timestamps, diagnostics, and security logs;
- error reports needed to investigate outages or abuse.
4.5 Communications
If you contact us, we process the content of your message and any account details needed to verify your identity and respond.
4.6 Data we do not intentionally collect
We do not intentionally collect special-category data as a product requirement. If such data appears inside a PDF you upload, it is incidental to your document processing request and remains your responsibility to handle lawfully.
5. How we use personal data
We use personal data to:
- create and authenticate accounts;
- maintain signed-in sessions and prevent unauthorized workspace access;
- process purchases, renewals, cancellations, and receipts through Stripe;
- attach paid licenses to the correct account;
- provide PDF processing features you request;
- detect fraud, chargeback abuse, credential stuffing, and security incidents;
- comply with legal obligations and enforce our Terms;
- improve reliability, usability, and security of the Service;
- respond to support requests.
We do not use the contents of your PDFs to target third-party advertisements. We do not sell personal information.
6. Legal bases (where applicable)
If you are in a region that requires a legal basis for processing (such as the EEA/UK), we typically rely on:
- Contract — to provide the account, paid access, and features you request;
- Legitimate interests — to secure the Service, prevent abuse, and maintain reliable operations, balanced against your rights;
- Legal obligation — where tax, accounting, or lawful requests require retention or disclosure;
- Consent — where required for optional cookies or specific processing that is not necessary for the core Service.
7. When we share information
We share personal data only when needed for the Service or required by law. Categories of recipients include:
- Infrastructure and auth providers (for example, Firebase Authentication) to create and verify accounts;
- Payment processors (Stripe) to complete checkout and manage subscriptions;
- Hosting and function providers (for example, Netlify for the storefront and APIs) to serve the website and account endpoints;
- Professional advisors under confidentiality obligations when needed;
- Authorities when legally required or to protect rights, safety, and security.
We do not sell personal information and do not share personal information for cross-context behavioral advertising as that term is commonly defined under US state privacy laws.
8. Key processors and subprocessors
Depending on configuration, ApexDoc relies on reputable processors such as:
- Firebase Authentication / Google — account authentication (email/password and Google Sign-In);
- Stripe — payment checkout, invoices, subscription state, and payment security;
- Netlify — hosting for the public storefront and serverless account APIs;
- Application hosting for the PDF workspace — processing environment for document tools behind access controls.
These providers process data according to their terms and security controls. We select processors with the expectation that they maintain industry-standard safeguards appropriate to authentication and payments.
9. How we treat your documents
Your documents are yours. ApexDoc processes them to complete the action you initiate (for example, merge or compress). We do not review document contents for advertising research, and we do not claim ownership of your files.
Because PDF tools often require temporary processing storage, residual technical copies may exist briefly in system memory, temporary directories, or operational logs after a job completes. We design the product to avoid turning casual document work into permanent content surveillance. You should still avoid uploading files you are not authorized to process, and you should retain your own authoritative backups.
If you use ApexDoc on a shared office computer, sign out when finished and clear local browser data according to your internal IT policy.
10. Security measures
Protecting account access and reducing unauthorized exposure of customer data is a primary product goal. Our safeguards include a combination of technical and organizational measures, such as:
- authentication required before paid workspace access;
- HttpOnly session cookies for account sessions where used;
- separation of payment card entry into Stripe Checkout;
- license checks that revoke access after failed or canceled subscriptions where webhooks/events are configured;
- least-privilege approach to profile fields;
- monitoring and investigation of suspected abuse;
- transport encryption (HTTPS) for the public storefront and API calls.
No method of transmission or storage is perfectly secure. We continuously improve controls, and we ask customers to protect endpoints, passwords, and shared devices. If you believe your account has been compromised, contact us immediately.
11. Data retention
We retain personal data only as long as needed for the purposes described in this Policy, including:
- Account data — while your account remains active and for a reasonable period afterward to handle disputes, security reviews, or legal requirements;
- Billing records — as required for accounting, tax, chargeback defense, and financial compliance (often for multiple years depending on jurisdiction);
- Security logs — for a limited period useful for incident detection and investigation;
- Document processing artifacts — generally transient, unless a durable storage feature is explicitly enabled for your workflow.
When retention is no longer necessary, we delete or de-identify data where feasible, subject to backup cycles and legal holds.
12. Your privacy rights
Depending on your location, you may have rights to access, correct, delete, restrict, or export certain personal data, or to object to certain processing. You may also have the right to lodge a complaint with a supervisory authority.
To exercise rights related to your ApexDoc account:
- Contact us using the email on your Stripe receipt or the published ApexDoc support channel.
- Provide enough information for us to verify that you own the account (we will not disclose account data to unverified requesters).
- Specify whether you need access, correction, deletion, or another supported action.
Some requests may be limited where we must retain records for legal, security, or billing reasons (for example, invoice history needed for tax compliance or fraud prevention).
If you signed in with Google, you may also manage certain Google account permissions through your Google account settings.
13. Cookies and similar technologies
We use cookies and similar technologies that are necessary to operate authentication and account sessions, including:
- secure account session cookies after sign-in;
- technical cookies required by hosting or security tooling;
- local browser storage used by the PDF workspace for operational state on your device.
These technologies are used to keep you signed in, protect routes, and make the product work. Where optional analytics cookies are introduced in the future, we will update this Policy and obtain consent where required.
14. Children’s privacy
ApexDoc is intended for business and adult professional use. It is not directed to children under 16 (or the higher age required in your jurisdiction). We do not knowingly create accounts for children. If you believe a child provided personal data, contact us and we will take appropriate steps to delete it.
15. International data transfers
ApexDoc and its processors may process data in countries other than your own, including regions where Firebase, Stripe, Netlify, or workspace hosting infrastructure operates. Where required, we rely on appropriate transfer mechanisms and contractual protections offered by those providers.
By using ApexDoc, you understand that your account and billing metadata may be processed internationally as needed to authenticate you, take payment, and deliver the Service.
16. Changes to this Privacy Policy
We may update this Privacy Policy to reflect product improvements, legal requirements, or stronger security practices. We will revise the “Last updated” date when changes are published. If changes are material, we will provide additional notice where practicable (for example, a website notice or account message). Continued use after an update means you acknowledge the revised Policy, except where additional consent is legally required.
17. Contact and privacy requests
For privacy questions, security concerns, or data-subject requests related to ApexDoc accounts, contact us through the support email on your Stripe receipt or the contact method published on the ApexDoc website. Include your account email and a clear description of your request.
If you are reporting a suspected security vulnerability or unauthorized access, please mark the message as urgent and avoid sending unnecessary copies of sensitive documents in the initial report.