Privacy Policy
The short version: we collect what an account and an API key need to work, and nothing else. This page is the long version.
At a glance
No cross-site tracking
No advertising pixels, no behavioural profiles, no data sold or traded to anyone.
Files are never stored
Uploads and rendered output live in memory for the length of the request, then go.
Encrypted end to end
Every request runs over TLS, and API keys are stored hashed — never in plain text.
What we collect
What we hold depends entirely on how you use PocketUtils. Testing an endpoint on a tool page requires no account, and creates no record tied to you.
Using the tool pages
- No account, no name, no email address.
- Your IP address, briefly, for rate limiting and abuse prevention. It is not linked to a profile.
- Aggregate analytics via SiteBehaviour — traffic volume, coarse region, and device type. Nothing that identifies you personally.
Holding an API key
- Your name and email address, so the account can be signed into and contacted.
- An optional avatar, if you set one.
- Billing details — handled and stored by our payment processor, never on our servers.
- Per-request metadata: which endpoint, when, how many credits, and whether it succeeded.
The contents of what you process. The URLs you screenshot, the files you convert, and the pages you scan are not logged, retained, or inspected — only the fact that a billable call happened.
How we use it
Four purposes, and we do not invent new ones without telling you first.
| Data | Purpose | Basis |
|---|---|---|
| Account details | Sign-in, support, service notices | Contract |
| Billing details | Taking payment and issuing credits | Contract |
| Request metadata | Metering credits and showing your usage | Contract |
| IP address & analytics | Rate limiting, abuse prevention, capacity planning | Legitimate interest |
We do not use your data to train models, and we do not send marketing email you did not ask for.
Retention
Everything has an expiry. Nothing is kept because it might be useful one day.
| What | Kept for |
|---|---|
| Uploaded files and rendered output | The request only |
| Rate-limit IP records | 24 hours |
| Request metadata (endpoint, credits, status) | 13 months |
| Account and billing records | Until you delete the account |
Deleting your account removes your profile and API keys immediately. Billing records are kept as long as tax and accounting law requires, then deleted.
Sharing & disclosure
We do not sell, rent, or trade personal data. It leaves our systems in exactly three situations:
- Processors. Payment and infrastructure providers who run part of the service on our behalf, under contract, and only for that purpose.
- Legal obligation. A valid court order or equivalent legal process. We tell you unless we are legally barred from doing so.
- Change of ownership. A merger or acquisition, with notice to you before anything transfers.
Security
- TLS on every connection, to the site and to the API.
- API keys stored as hashes — we cannot read yours back to you, only issue a new one.
- Processing runs in isolated, short-lived sandboxes that are destroyed after each job.
- Access to production is limited and audited.
No service can promise perfect security. If a breach ever affects your data, we will tell you what happened and what we did about it — without waiting for a deadline to force it.
Your rights
You can ask us to do any of the following, and we extend these rights to everyone, not only to people covered by the GDPR.
Get a copy of what we hold about you.
Correct anything inaccurate.
Have your data deleted.
Export it in a machine-readable format.
Pause processing while a dispute is open.
Object to processing based on legitimate interest.
Email support@pocketutils.com to exercise any of them. We respond within 30 days, usually much sooner.
Changes to this policy
When this policy changes we update the revision date at the top of the page. If a change materially affects how we handle your data, we email account holders before it takes effect — we do not rely on you noticing a silent edit.
Questions about any of it go to support@pocketutils.com or through the contact form.
Something here unclear?
Plain-English answers beat legal text. Write to us and a human replies.