Back to Home

Privacy Policy

Last updated: September 12, 2026

The Client-Side Guarantee

Most operations on Modifyle happen entirely in your browser using WebAssembly and canvas APIs. When you merge PDFs, compress an image, or create a static QR code, those files never leave your device and never touch our servers.

1. The Short Version

Modifyle ("we," "us," "Modifyle") operates modifyle.com. This policy explains what data we collect, why, and how it is handled — written to reflect how the product actually operates, rather than generic boilerplate.

Most of what Modifyle does happens entirely on your machine. For the specific subset of features that do require a server (heavy server-side PDF processing, dynamic QR code redirects, and account subscriptions), this document details exactly what is collected and why.

2. Data We Collect

2.1 Client-Side Tools (Merge, Split, Image-to-PDF, Watermark, Lock/Unlock, Compress, Convert, Resize, Static QR)

We collect nothing about the files themselves. These tools run using WebAssembly and modern browser APIs directly on your device. Your files are never uploaded to Modifyle's servers, never stored, and never accessible to us.

2.2 Server-Side Heavy Processing (Ghostscript Compression, PDF-to-Word, Watermark Removal)

When you use credit-based heavy conversion features, your file is temporarily uploaded to our isolated processing service strictly to perform the requested operation:

  • Files are stored only for the duration of the processing cycle.
  • Processed files and original uploads are automatically wiped within 1 hour via an automated lifecycle bucket policy.
  • We never inspect, read, or retain file contents beyond the automated conversion operation.

2.3 Account Data

If you create an account (for dynamic QR codes, vanity short links, credits, and subscriptions), we collect your email address and basic profile attributes provided by Google OAuth or Apple Sign-In. We use Supabase as our secure authentication and database provider.

2.4 Dynamic QR Codes & Short Links

For each dynamic QR code or short link you create, we store: destination URL, styling preferences, and creation timestamp. When a visitor scans your QR code or clicks your link, our edge router logs:

  • Approximate country (derived via Cloudflare edge headers without recording raw IP addresses).
  • Device category (Mobile, Desktop, Tablet) parsed via User-Agent headers.
  • Referrer domain (where the click originated).

We never log or store individual visitors' IP addresses, names, or personally identifiable information.

2.5 Payment Data

Payments are processed by LemonSqueezy, our global merchant of record. We never receive or store complete credit card or debit card numbers. We only retain subscription status, credit balances, and transaction timestamps for your billing dashboard.

2.6 Transactional Emails

We use Resend to deliver necessary account notifications (welcome messages, receipt confirmations, and feature waitlist alerts). We do not send marketing spam without explicit opt-in.

2.7 Cookies & Session Management

We use strictly essential cookies to maintain secure authentication sessions via Supabase SSR. We do not place third-party cross-site advertising or tracking cookies on your device.

3. What We Never Collect

  • The content of any file processed client-side (impossible for us to see — it never leaves your machine).
  • Credit card numbers, bank routing numbers, or CVV security codes.
  • Government identification numbers, biometric markers, or location data beyond country level.

4. How We Use Your Data

  • To provide the core services requested (file conversion, link routing, analytics dashboard).
  • To authenticate your sessions and manage credit balances.
  • To prevent fraud, malicious link phishing, and platform abuse.
  • We never sell, rent, or monetize your personal data.

5. Third-Party Service Providers

Modifyle relies on industry-leading infrastructure partners to deliver high reliability and edge performance:

ProviderFunction
SupabaseAuthentication, PostgreSQL database, and Row Level Security
CloudflareEdge DNS, DDoS mitigation, and edge redirect infrastructure
LemonSqueezyMerchant of Record, payment processing, and billing management
ResendTransactional email delivery
Railway / Fly.ioIsolated container runtime for server-side Ghostscript operations

6. Your Rights & Data Deletion

Depending on your jurisdiction (such as GDPR in the EU/UK or CCPA/CPRA in California), you have rights regarding your personal data, including the right to inspect, export, or delete your account records.

You may request account deletion at any time by contacting privacy@modifyle.com. Deleting your account permanently wipes your profile, dynamic QR links, and scan records within 30 days.

7. Children's Privacy

Modifyle is intended for general audiences and professionals. We do not knowingly collect personal data from children under the age of 13. If you believe a minor has created an account, please contact us immediately for prompt deletion.

8. Contact Us

For any inquiries regarding this Privacy Policy or your personal information, please reach out to:

privacy@modifyle.com