✦ Legal

Privacy Policy

The short version: we collect what an account and an API key need to work, and nothing else. This page is the long version.

Updated July 21, 20267 sectionsAsk a question

At a glance

No cross-site tracking

No advertising pixels, no behavioural profiles, no data sold or traded to anyone.

Files are never stored

Uploads and rendered output live in memory for the length of the request, then go.

Encrypted end to end

Every request runs over TLS, and API keys are stored hashed — never in plain text.

01

What we collect

What we hold depends entirely on how you use PocketUtils. Testing an endpoint on a tool page requires no account, and creates no record tied to you.

Using the tool pages

  • No account, no name, no email address.
  • Your IP address, briefly, for rate limiting and abuse prevention. It is not linked to a profile.
  • Aggregate analytics via SiteBehaviour — traffic volume, coarse region, and device type. Nothing that identifies you personally.

Holding an API key

  • Your name and email address, so the account can be signed into and contacted.
  • An optional avatar, if you set one.
  • Billing details — handled and stored by our payment processor, never on our servers.
  • Per-request metadata: which endpoint, when, how many credits, and whether it succeeded.
Never collected

The contents of what you process. The URLs you screenshot, the files you convert, and the pages you scan are not logged, retained, or inspected — only the fact that a billable call happened.

02

How we use it

Four purposes, and we do not invent new ones without telling you first.

DataPurposeBasis
Account detailsSign-in, support, service noticesContract
Billing detailsTaking payment and issuing creditsContract
Request metadataMetering credits and showing your usageContract
IP address & analyticsRate limiting, abuse prevention, capacity planningLegitimate interest

We do not use your data to train models, and we do not send marketing email you did not ask for.

03

Retention

Everything has an expiry. Nothing is kept because it might be useful one day.

WhatKept for
Uploaded files and rendered outputThe request only
Rate-limit IP records24 hours
Request metadata (endpoint, credits, status)13 months
Account and billing recordsUntil you delete the account

Deleting your account removes your profile and API keys immediately. Billing records are kept as long as tax and accounting law requires, then deleted.

04

Sharing & disclosure

We do not sell, rent, or trade personal data. It leaves our systems in exactly three situations:

  • Processors. Payment and infrastructure providers who run part of the service on our behalf, under contract, and only for that purpose.
  • Legal obligation. A valid court order or equivalent legal process. We tell you unless we are legally barred from doing so.
  • Change of ownership. A merger or acquisition, with notice to you before anything transfers.
05

Security

  • TLS on every connection, to the site and to the API.
  • API keys stored as hashes — we cannot read yours back to you, only issue a new one.
  • Processing runs in isolated, short-lived sandboxes that are destroyed after each job.
  • Access to production is limited and audited.
Honest caveat

No service can promise perfect security. If a breach ever affects your data, we will tell you what happened and what we did about it — without waiting for a deadline to force it.

06

Your rights

You can ask us to do any of the following, and we extend these rights to everyone, not only to people covered by the GDPR.

Access

Get a copy of what we hold about you.

Rectification

Correct anything inaccurate.

Erasure

Have your data deleted.

Portability

Export it in a machine-readable format.

Restriction

Pause processing while a dispute is open.

Objection

Object to processing based on legitimate interest.

Email support@pocketutils.com to exercise any of them. We respond within 30 days, usually much sooner.

07

Changes to this policy

When this policy changes we update the revision date at the top of the page. If a change materially affects how we handle your data, we email account holders before it takes effect — we do not rely on you noticing a silent edit.

Questions about any of it go to support@pocketutils.com or through the contact form.