✦ Legal

GDPR

The General Data Protection Regulation gives people in the EU and EEA a set of rights over their personal data. We extend all of them to every PocketUtils user, wherever you are.

Updated July 21, 20267 sectionsAsk a question

At a glance

Extended to everyone

These rights apply to every user, not only to people inside the EU and EEA.

Export on request

Your account data, in a structured machine-readable format, whenever you ask.

Deletion means deletion

Close your account and the profile and keys go immediately, not eventually.

01

Who this covers

The GDPR has applied across the EU and EEA since May 2018. It governs how organisations collect, store, and use personal data, and gives individuals enforceable rights over it.

Our position

We do not check where you are before deciding which rights you get. Everything on this page is available to every user, in every country. Splitting users into privacy-haves and have-nots is not a product decision we are willing to make.

For processing carried out through PocketUtils, we are the data controller. Where you use the API to process personal data of your own users, you are the controller and we act as your processor.

02

Your rights

Six rights, each exercisable by email. None of them cost anything.

Access

Ask what personal data we hold about you, why we process it, how long we keep it, and who it goes to. We send a copy.

Rectification

Have inaccurate or incomplete data corrected. Most of it you can edit yourself in account settings.

Erasure

Have your data deleted when it is no longer needed, when you withdraw consent, or when it was processed unlawfully.

Portability

Receive your data in a structured, commonly used, machine-readable format and take it to another provider.

Restriction

Have processing paused while an accuracy dispute or an objection is being resolved.

Objection

Object to processing we base on legitimate interest. We stop unless we can show compelling grounds that override your rights.

03

Lawful basis

Every category of data we process has a basis under Article 6. We do not rely on consent for anything essential, which is why there is no banner to click.

DataLawful basisPurpose
Account detailsContractProviding the service you signed up for
Billing detailsContractTaking payment and issuing credits
Request metadataContractMetering credits and reporting your usage
IP addressLegitimate interestRate limiting and abuse prevention
Aggregate analyticsLegitimate interestUnderstanding load and improving the service

Retention periods for each of these are listed in the Privacy Policy.

04

Making a request

Do it yourself

  • View and edit your profile from account settings.
  • Export your account data and usage history from the dashboard.
  • Close your account, which deletes your profile and revokes every key.

Or ask us

Email support@pocketutils.com from the address on your account, or use the contact form. Tell us which right you are exercising. If we cannot identify you from the request we will ask for enough detail to be sure — we are not going to hand your data to someone who merely claims to be you.

Response time

We reply within 30 days, as the regulation requires, and usually far sooner. If a request is genuinely complex and needs an extension, we tell you inside the first 30 days rather than letting the deadline pass quietly.

05

How we comply

Data minimisation

  • Using a tool page requires no personal data at all.
  • An account requires a name and an email address. That is the whole list.
  • Files and rendered output are processed in memory and never written to storage.
  • We log that a call happened and what it cost — never what it contained.

Privacy by design

  • Defaults favour privacy; nothing extra is opted into on your behalf.
  • Only strictly necessary cookies are set.
  • No third-party advertising or tracking is embedded anywhere on the site.

Security

  • TLS in transit, encryption at rest.
  • API keys stored hashed, never in plain text.
  • Isolated, short-lived sandboxes for every processing job.
  • Restricted, audited production access, and a documented incident response.

We are not required to appoint a Data Protection Officer at our size and processing volume. Data protection matters are handled directly by the team at support@pocketutils.com.

06

International transfers

Our infrastructure runs in secure data centres, and some of our processors operate outside the EEA. Where personal data crosses a border, the transfer is covered by an appropriate safeguard — Standard Contractual Clauses, or an adequacy decision of the European Commission.

Enterprise customers who need region pinning or a signed Data Processing Agreement should talk to us.

07

Complaints

If you think we have handled your data badly, tell us first — most problems are a misunderstanding we can fix in a day.

You also have the right to complain to your national supervisory authority, and you do not have to come to us first. You can find yours through the European Data Protection Board.