Privacy Policy
Last updated: August 22, 2026
This policy explains how personal information is handled when you visit pdfs.build, use our hosted application, APIs, embedded editor, or public links, or contact us.
Who we are and our role
The service is operated by Brilliminds FZC (License No.4306832), Business Centre, Sharjah Publishing City Free Zone, Sharjah, United Arab Emirates, postal code 519285. Contact us at[email protected]. More company information is in our Legal Notice.
We are a controller for account, website, security, product-usage, and commercial data we determine how to use. When a business customer places personal data in templates, datasets, prompts, documents, forms, or API requests and determines the purpose of that processing, the customer is normally the controller and we act as its processor under our Data Processing Addendum.
Information we process
- Account and identity data: name, email, password hash, organization and membership details, invitations, authentication provider identifiers, sessions, IP address, user agent, and the time and version of your Terms and Privacy acknowledgement.
- Customer Content: templates, source code, schemas, sample or form data, prompts and chat history, uploaded and generated images, fonts, imports, and rendered documents.
- Product and technical data: features used, render and AI usage, API-key identifiers, request and error logs, device/browser details, diagnostic context, and security events.
- Billing data: customer and subscription identifiers, plan, status, country, invoices, transactions, and metered usage. Our Merchant of Record collects payment-card details; we do not receive full card numbers.
- Communications: support, privacy, security, and other messages you send us.
- Website data: pages and referrers measured through cookieless Cloudflare Web Analytics when enabled.
We receive this information from you, your organization or an application integrating our Service, identity and billing providers you choose, and automatically from your device and use of the Service.
Purposes and legal bases
Where the GDPR or UK GDPR applies, we use personal data as follows:
- Contract: create and secure accounts; provide editing, rendering, AI, sharing, billing, support, and requested integrations.
- Legitimate interests: operate, troubleshoot, and improve the Service; understand aggregate usage; prevent fraud and abuse; and protect users and our systems. We balance these interests against individual rights.
- Legal obligations: maintain tax and transaction records and comply with valid legal requests.
- Consent: where law requires it for a particular optional feature or communication. Consent can be withdrawn at any time.
Account and request data marked as required must be provided for us to supply the relevant Service. We do not use personal data to make decisions that produce legal or similarly significant effects solely by automated means.
AI and web-search features
When you use an AI feature, the information needed to answer the request may be sent to an AI gateway and the selected model provider. This can include prompts, relevant chat history, template source, schemas, sample data, images, and generated output. Suggestion features may also send template metadata or source. When web search is used, the query and requested domain filters are sent to the search provider. Do not submit sensitive or regulated personal data unless your organization has confirmed the feature and contract are appropriate for it.
Who receives information
We disclose information only as needed:
- to infrastructure, storage, email, monitoring, AI, search, identity, and billing providers described in our Subprocessor List;
- to other members and administrators of your organization according to workspace permissions;
- to people you choose through published templates, forms, embeds, or public links;
- to advisers, authorities, or other parties when reasonably necessary to comply with law, protect rights and safety, or complete a corporate transaction.
Polar acts as Merchant of Record and independently controls payment and buyer data under its own privacy policy. Google and GitHub independently process optional OAuth sign-in under their own terms. We do not sell personal information or share it for cross-context behavioural advertising.
International transfers
Brilliminds FZC is established in the United Arab Emirates, and our providers operate in the locations listed on the Subprocessor List. Information may therefore be processed outside your country, including outside the EEA, United Kingdom, or Switzerland. Where required, we use an adequacy decision or contractual safeguards such as the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, together with supplementary measures where appropriate. Contact us to request information about the safeguard relevant to a transfer.
Retention
We keep account and Customer Content while the account or workspace is active and until it is deleted by an authorized user or the account is closed. We keep operational and security logs only for the period needed to troubleshoot, secure, and operate the Service. Billing, tax, dispute, and legal records are retained for the period required by applicable law. Residual copies may remain temporarily in backups until they rotate out and may be isolated where law requires preservation. Provider retention can vary by feature and configuration.
Retention decisions consider the amount and sensitivity of data, the purpose, security risk, customer instructions, contractual commitments, and legal requirements. You can request more detail for a specific category at the contact address below.
Cookies and device storage
We use necessary authentication and security cookies, including a session cookie that normally lasts up to seven days. The application also uses browser storage for theme, layout, onboarding, and similar preferences until you clear it; short-lived workflow values are kept in session storage until the browser tab is closed. A sidebar preference cookie normally lasts seven days.
We do not currently use advertising or cross-site tracking cookies. Cloudflare Web Analytics, where enabled, is configured as cookieless analytics. If we introduce non-essential cookies or similar tracking that requires consent, we will ask before using it.
Security
We use technical and organizational measures designed to protect personal data, described on our Security page. No service can guarantee absolute security. You are responsible for protecting credentials, restricting workspace and public-link access, and avoiding unnecessary personal data in templates and prompts.
Your rights and choices
Depending on your location and our role, you may have rights to access, correct, delete, restrict or object to processing, receive a portable copy, and withdraw consent. You may also complain to the data-protection authority where you live or work. UAE law may provide rights concerning access, correction, deletion, restriction, objection, portability, and automated processing, subject to its conditions and exceptions.
Email [email protected] to make a request. We may verify your identity and authority. We respond within the period required by applicable law. If we process data for your organization, please contact that organization first; we will assist it as required. You may appeal a denied request by replying to our decision.
Children
The Service is for business users aged 18 or older. We do not knowingly collect personal information from children. Contact us if you believe a child provided information to us.
Changes
We may update this policy as the Service or law changes. We will post the new version and date here and provide additional notice when required. Material changes apply prospectively.
Contact
Privacy requests and questions: [email protected].
Brilliminds FZC, Business Centre, Sharjah Publishing City Free Zone, Sharjah, United Arab Emirates, postal code 519285.