Security and data protection
How we protect your account, your files and your personal information — in plain language.
Data privacy and security
Keeping your files and data private is the core of Potato PDF. We collect only what we need to run the tools and your account, we’re open about what we do with it, and we never sell it. Details are in our Privacy Policy.
Your files
- Browser tools: many tools run entirely on your device — the file never leaves it.
- Server tools: files are used only for the operation you request.
- Automatic deletion: a job runs every hour and removes processed files within 24 hours at the latest.
- Private storage: files are kept in a private folder that isn’t reachable from the web.
- No AI training: your files are never used to train AI.
Compliance and your rights
We follow data-protection principles such as those in the GDPR: data minimisation, purpose limitation and your right to see, correct and delete your data. You can delete your account and its data at any time from your account’s Security settings.
Product security
- Encryption in transit: the site is served over HTTPS, so data between your browser and our servers is encrypted.
- Passwords: stored as one-way hashes — nobody, including our team, can read them.
- Two-factor authentication: add an authenticator app to your account for extra protection.
- Secrets: API keys and similar secrets are stored encrypted.
- Forms and requests: protected against cross-site request forgery, validated on the server and rate-limited.
- Uploads: checked against each tool’s accepted types and size limits; web-page tools block private network addresses.
Internal security
- Only named administrators can reach the admin area, and every admin page checks their role.
- Administrators can’t see users’ passwords; they can only set a new one when a user asks.
- Access is kept to the minimum each person needs (least privilege).
Information security policy
We aim to keep your information confidential, intact and available. We keep improving our security as the service grows, fix reported issues quickly and review our practices when we add new tools.
Reporting a vulnerability
Found a security issue? Please tell us through our contact page. Don’t access or change other people’s data while testing. These are our practices, not a claim of third-party certification.