Your privacy, by design

Privacy Policy

NamahaPDF processes your documents in your browser. Your files never leave your device, so the things we can't see, we can't lose.

Last updated: June 23, 2026

1. Introduction

This Privacy Policy explains how NamahaPDF (“NamahaPDF”, “we”, “us” or “our”) collects, uses, shares and protects your personal data when you use our website and PDF tools (the “Service”). It is written to be consistent with India's Digital Personal Data Protection Act, 2023 (DPDP Act) and, for users in the European Economic Area and the UK, the General Data Protection Regulation (GDPR).

For the purposes of the DPDP Act we act as the Data Fiduciary and you are the Data Principal. Under the GDPR we act as the data controller. By using the Service you acknowledge the practices described here.

2. Your documents stay on your device

Editing, conversion, compression, watermarking, redaction and OCR run client-side in your browser. We do not upload, view, store or transmit the contents of the files you open, and we never use your document content to train any AI model.

A small number of features may require a server (for example certain encryption operations or heavier machine-learning models). Where that happens, the file is processed only to perform the task you requested and is not retained afterwards. We will always make it clear when a feature needs a server.

3. Personal data we collect

We keep data collection to the minimum needed to run the Service:

  • Account data: if you create an account or sign in with Google, we store your name, email address and (for email/password sign-in) a securely hashed password.
  • Usage data: to operate the free tier and understand product usage we record lightweight events such as the action performed, the tool used, an approximate file size, and a timestamp. For guests this is tied to a device cookie or IP address rather than an identity.
  • Technical data: standard information your browser sends, such as IP address, browser type and device type, used for security and rate limiting.
  • Analytics data: aggregated, anonymised statistics about how pages are used.

We do not collect the contents of your documents, and we do not knowingly collect sensitive personal data.

4. How and why we use your data

We use personal data to:

  • provide, maintain and secure the Service and your account;
  • operate free-tier limits and prevent abuse, fraud and excessive use;
  • understand and improve how the Service is used;
  • respond to your support requests; and
  • comply with legal obligations.

Legal bases. Under the DPDP Act we rely on your consent and on certain “legitimate uses” permitted by the Act. Under the GDPR we rely on your consent (e.g. optional analytics), the performance of our contract with you (providing the Service), and our legitimate interests (security and product improvement). You can withdraw consent at any time.

5. Cookies and tracking

We use a small number of cookies and similar technologies: strictly necessary cookies for sign-in and security, a device cookie to apply free-tier limits, and analytics cookies to measure usage. You can control cookies through your browser settings; disabling some cookies may affect how the Service works.

6. Sharing and service providers

We do not sell your personal data. We share it only with trusted service providers (Data Processors) who process it on our behalf under appropriate safeguards:

  • Google: sign-in (OAuth) and website analytics;
  • Vercel: application hosting and privacy-friendly analytics;
  • Neon: managed database hosting for account and usage data.

We may also disclose data where required by law or to protect our rights, users or the public.

7. Data retention

We keep account data for as long as your account is active, and usage and technical data for only as long as needed for the purposes above. When data is no longer required, or when you ask us to delete your account, we delete or anonymise it within a reasonable period, except where we must keep it to meet legal obligations.

8. How we protect your data

We use technical and organisational measures appropriate to the risk, including encryption in transit (HTTPS), hashed passwords, access controls, rate limiting and security headers. No method of transmission or storage is completely secure, but processing documents on your own device removes the largest risk entirely.

9. Your rights

Subject to applicable law, you have the right to access your personal data, correct or update it, request its erasure, withdraw consent, and complain to the relevant authority. Under the GDPR you additionally have rights to data portability, to restrict or object to processing, and to lodge a complaint with your local supervisory authority. Under the DPDP Act you also have the right to nominate another individual to exercise your rights in the event of death or incapacity, and the right to a readily available grievance redressal mechanism (see section 12).

To exercise any of these rights, contact us at namaha.tech@gmail.com. We will respond within the timelines required by applicable law.

10. Children's data

The Service is not directed at children. In line with the DPDP Act, we do not knowingly process the personal data of a child (a person under 18 in India) without verifiable consent from a parent or lawful guardian, and we do not undertake tracking, behavioural monitoring or targeted advertising directed at children. If you believe a child has provided us personal data, please contact us and we will delete it.

11. International transfers

Our service providers may process data on servers located outside your country. Where data is transferred internationally, we rely on the safeguards offered by those providers and on the mechanisms permitted under applicable law (such as the GDPR's transfer mechanisms) to keep your data protected.

12. Grievance redressal / contact

If you have any questions, requests or complaints about this policy or your personal data, you can reach our grievance contact:

NamahaPDF Grievance Contact
namaha.tech@gmail.com

We aim to acknowledge grievances promptly and resolve them within the period required by law.

13. Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes we will update the “last updated” date above and, where appropriate, notify you. Your continued use of the Service after changes take effect means you accept the updated policy.