Privacy Policy

Last updated: 4 August 2026

The short version

Our free tools run entirely in your browser. Your files are never uploaded to our servers, never stored, and never seen by us. We set no advertising trackers and no cookies for anonymous visitors — the only cookie we use is a single essential sign-in cookie set when you log in to an account (see below). We use Cloudflare Web Analytics — a cookie-less, privacy-first service that counts page views without identifying or tracking you.

The one thing to know if you have an account: for the tools that change a document’s contents, we log that you opened the tool, with the date, your IP address and your browser. That is an accountability record about the account, not about the document — your file, its name and any password you type still never reach us.

Who we are

ThekkelSoft (“we”, “us”) operates thekkelsoft.in. We are an MSME registered in Kerala, India (UDYAM-KL-07-0057065).

Browser tools — your files stay on your device

Tools such as the PDF Compressor, PDF Editor, Merge PDF, Split PDF, Sign PDF, Fill PDF Form, Watermark PDF, Add Page Numbers, Password Protect PDF, Unlock PDF and the Anything to PDF converter, our image tools (Image Compressor, Image Converter and HEIC to JPG), and our developer tools (QR Code Generator, JWT Decoder, Base64 encoder/decoder, JSON Formatter, Hash Generator, UUID Generator and Unix Timestamp Converter) process your files and text locally on your device inside your browser (using WebAssembly and JavaScript). When you select a file or photo, or type or paste text — including any images you insert while editing a PDF, the answers you type into a PDF form, a token you decode, or text you hash or encode:

  • The file is read and processed in your browser’s memory only.
  • No part of the file’s content is transmitted to our servers or to any third party.
  • Nothing is retained after you close or reload the page — with one optional exception, described below.

Saved signatures. The Sign PDF tool lets you keep a signature you have drawn, typed or photographed so it is ready the next time you sign something. If you use that, the signature image is stored in your browser’s local storage on that device only. It is never uploaded to us or to anyone else, it is not linked to any account, and clearing your browser data removes it. The tool also has a “Forget saved” button that deletes every stored signature immediately — worth using on a shared or public computer. The document you sign is still processed only in memory and is never stored.

PDF passwords. The Password Protect PDF and Unlock PDF tools, and the PDF Editor when you open a protected file, ask you to type a password. That password is used only to drive the encryption engine running inside your own browser. It is never transmitted, never stored, and never written to a log — it exists in the memory of a background worker for the few seconds the job takes, and that worker is destroyed as soon as the job finishes. We cannot recover a password you forget, because we never had it.

This is enforced technically, not just promised: our pages ship a Content-Security-Policy that instructs your browser to block network requests to any origin other than our own — the only exception being Cloudflare’s analytics beacon, which receives page-view metrics and never file content. You can verify this in your browser’s developer tools.

What we collect on public pages

Very little, deliberately. Public pages set no cookies. We use Cloudflare Web Analytics to understand aggregate site usage: it records page views, referrer and browser type without cookies, without fingerprinting, and without tracking you across sites — we see only anonymous, aggregate counts. Like virtually every website, our hosting infrastructure and CDN (Cloudflare) also automatically record standard request logs — IP address, browser user-agent, and the page requested — which are used solely for security and abuse prevention and are retained only for a short period. These logs never contain the contents of files you process with our tools.

What we collect if you create an account

Signing in is optional and is never required to use the free tools. If you register, we collect your email address and (optionally) your name to operate your account.

Account sign-up and sign-in are handled by Firebase Authentication, a Google service — you can create an account with an email and password, or sign in with your Google account. Firebase sends its own account-related emails directly to you (a verification link when you register with a password, and a reset link if you forget it). When you sign in, your browser exchanges a short-lived Firebase credential with our server, which verifies it and issues your session cookie; unlike the browser tools, this necessarily communicates with our server and with Google. If you sign in with Google, Google shares your email address and, if available, your name with us as part of that exchange. We never receive or store your password — Firebase manages it directly. (Passwords created before this account system moved to Firebase were transferred as an already securely hashed value, so no reset was required; we have no access to that hash or to the plaintext password it represents.) We use this data only to provide and secure the service — we do not sell or share your personal data with third parties for marketing.

If you switch on two-step verification, we store the setup key your authenticator app uses, encrypted on our server, together with a one-way hash of each of your recovery codes — we cannot read the codes themselves, which is why we can only replace them, never show them to you again. To stop someone guessing your codes, we also record the number of incorrect attempts and, if there are too many, the time at which your account may next be tried. All of this is deleted the moment you turn two-step verification off.

To keep you signed in, we set a single essential cookie holding your session. It is strictly necessary for the account to function, is not used for advertising or tracking, and is cleared when you sign out. So that your favorites and recently used tools appear across visits, we also store, against your account, the names of the tools you star or open — only the tool identifiers and timestamps, never the contents of any file you process. You can remove this at any time by asking us to erase your account data.

To operate your account and understand overall usage, we also keep basic operational details: the date you last signed in or used your account, and your account status — whether it is active and whether it currently has paid access. These are used only to run and secure the service and to see aggregate active-member counts; they are never used for advertising or to track you across other sites.

Account activity log. Some tools change the contents of a document — Unlock PDF, the PDF Editor, Sign PDF, Watermark PDF, Add Page Numbers, Fill PDF Form and Password Protect PDF. Because those carry real potential for misuse, we keep an accountability record for them. When you open one of these tools we record four things against your account: which tool it was, the date and time, your IP address, and your browser’s user-agent string. We also record the moment you accepted our Terms of Use and Acceptable Use Policy, with the same details, as the record of that acceptance.

What this record deliberately does not contain: your file, any part of its contents, its file name, any fingerprint or hash of it, any password you typed, anything you typed into a form or an edit, and any signature you drew. There is no route by which those could reach us — the tools run in your browser, and the interface that writes this log is structurally incapable of accepting anything beyond the tool’s name. It records that you used a tool, never what you did with it.

We use this record only to handle abuse of the document tools, to answer a lawful request from a competent authority, and to demonstrate that you accepted the policies. It is kept for 24 months and then deleted automatically. It is personal data covered by your rights under the DPDP Act, described below.

If you use our Shared Expenses feature, the details you enter are saved on our servers so your groups sync across devices and with the people you share them with. This includes the group names, expense descriptions, amounts, categories and dates, the splits and payments you record, and — when you invite someone — the email address and optional name you provide for them. Unlike the browser tools, this feature necessarily stores your data on our server. We use it only to operate the feature for you and the members of your groups; we do not sell it or use it for advertising. When you invite someone by email, we send them a notification through our email provider (SMTP). You can also invite people with a shareable link, which does not require their email address; anyone who opens that link and signs in joins the group. When you create a group we read the two-letter country code Cloudflare derives from your IP address to pre-select a default currency for it. That country code is not stored against your account and not logged; the currency you go on to confirm is saved with the group.

If you have a Pro membership, you can attach receipt images or PDFs to an expense. Unlike the browser tools, these files are uploaded — your browser sends them directly to Cloudflare R2, our object-storage provider, and they are shown to you and your group members only through short-lived, private signed links. A receipt file is retained until you delete the receipt, delete the expense it belongs to, or delete your account, at which point it is removed from storage. We use these files only to operate the feature; we never sell them or use them for advertising.

You can delete an individual receipt, delete a group (once it is settled), or ask us to erase your account — which removes your expense data and any receipt files you stored — at any time.

Your rights (DPDP Act, 2023)

We aim to comply with India’s Digital Personal Data Protection Act, 2023. If you have an account, you may request access to, correction of, or erasure of your personal data, and you may raise a grievance about how it is handled, by contacting us at the address below. We will respond within a reasonable time as required by law.

Third-party services

Our site is served through Cloudflare, which acts as our CDN and security layer, and provides our web analytics (Cloudflare Web Analytics). Cloudflare sees page requests (as any network carrier does) but never the contents of files processed by the browser tools, because those files are never transmitted. If you attach receipts in the Shared Expenses feature (Pro), those files are stored on Cloudflare R2, Cloudflare’s object-storage service, which acts as our storage sub-processor for that data.

The site may also link to Razorpay for voluntary contributions and for paid membership (see below). These are plain outbound links or redirects — our pages load no scripts or content from Razorpay, and following such a link is the only interaction the site has with it.

Account sign-up and sign-in are provided by Firebase Authentication, a Google service. When you create an account, sign in, or use “Sign in with Google”, your browser communicates directly with Firebase/Google to verify your identity, governed by Google’s own privacy policy.

To stop automated abuse of the account system, we use Google reCAPTCHA (via Firebase App Check). reCAPTCHA loads a Google script and analyses browsing signals to tell humans from bots, governed by Google’s privacy policy. It never receives the contents of any file you process — the tool pages continue to work entirely in your browser, and no file content is ever transmitted to Google or to us.

Voluntary contributions

You may optionally support the developer through a contribution. Choosing to do so opens Razorpay in a new browser tab. The entire payment happens on Razorpay’s own site under its own privacy policy. No payment details — card numbers, UPI IDs, or amounts — ever reach or are stored by thekkelsoft.in, and our pages embed no payment scripts. If you dismiss the contribution prompt shown after using a tool, that preference is stored only in your browser’s local storage and is never transmitted to us.

Pro membership

If you choose to upgrade a member account to Pro, you are redirected to Razorpay to complete the payment on its own site under its own privacy policy. We never see or store your card or UPI details. To activate your membership and keep a record of the transaction, we do store a payment record: the Razorpay payment and order identifiers, the plan, the amount and currency, any discount or coupon code applied, a status, and the date, linked to your member account. We use this only to grant access, provide support, and meet accounting and legal obligations.

To show you the right price, we read the two-letter country code that Cloudflare derives from your IP address at the moment the page loads — rupees for India, US dollars elsewhere. That country code is used only to pick the currency for that one response. It is not stored against your account, not logged, and not used for any other purpose.

Membership generates two kinds of email to your account address: a receipt when a payment succeeds, and a reminder shortly before your access ends. Both are transactional messages about your own membership rather than marketing, and are sent through our email provider (SMTP).

Changes to this policy

If we change this policy — for example, if a future tool requires server-side processing — we will update this page and the “last updated” date above before the change takes effect.

Contact

For privacy questions or grievances: contact@thekkelsoft.in