Legal
Privacy Policy
Effective 8 July 2026DRYPDF ("we", "us") is operated by Max Network. This policy explains what we collect, how we use it, and the choices you have. Questions: hello@drypdf.com.
What we collect
- Account. When you sign in with Google or Microsoft we receive your email address, a stable account identifier, and basic profile info.
- Your documents. The PDFs you upload, the text we extract from them, and light metadata (file name, size, page count, timestamps).
- Connected mailbox (optional). If you connect Gmail or Outlook, we access your mail on a read-only basis to find and import PDF attachments. We do not read, store, or process message bodies beyond locating PDF attachments.
- Usage. Request counts for metering and abuse prevention, and error logs for reliability.
- Payments. If you subscribe, payment is handled by Stripe. We do not receive or store your card details.
How we use it
- To provide the service: store your PDFs, convert them to readable text, index them, and let you (and, over MCP, your own AI agents) search them.
- To auto-index PDF attachments from a mailbox you explicitly connect.
- To operate billing, prevent abuse, and keep the service reliable and secure.
Google and Microsoft mail access, and Limited Use
DRYPDF's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, data obtained via the Gmail read-only scope (and the equivalent Microsoft Graph Mail.Read permission) is used solely to locate and import PDF attachments into your account. We do not use it for advertising, we do not sell it, we do not allow humans to read it except with your consent, for security, or where required by law, and we do not transfer it except as needed to provide or improve this feature, to comply with law, or with your consent. You can disconnect a mailbox at any time from your dashboard.
Browser extension
The optional DRYPDF browser extension brings save and search into your browser. It handles only what those two features need, and communicates solely with drypdf.com:
- Authentication. Connecting signs you in with your existing DRYPDF account via the standard OAuth flow. The resulting access token is stored locally on your device (in extension storage); the extension never sees your password.
- Saving a document. When you explicitly choose to save a PDF, the extension reads that file's bytes from the tab you acted on and sends them to your DRYPDF account to be stored and indexed, exactly like uploading it on the website. It reads a page only on your action, and has no standing access to your browsing.
- Searching. The search terms you type in the extension are sent to your DRYPDF account to return matching documents.
The extension collects no analytics, contains no third-party or remote code, and transfers no data to anyone other than your own DRYPDF account. You can disconnect it at any time from the extension, which removes the stored token.
Where your data is stored and processed
DRYPDF runs on Cloudflare. Your PDFs and extracted text are stored in Cloudflare R2 and D1; the search index is stored in Cloudflare KV; text extraction uses Cloudflare Workers AI. Data is transmitted over HTTPS and account credentials and secrets are encrypted at rest.
Sharing
We do not sell your data. We share it only with the processors that run the service: Cloudflare (hosting, storage, AI text extraction), Google and Microsoft (sign-in and, if connected, mailbox access), and Stripe (payments). Each processes data only to provide their part of the service.
Retention and deletion
We keep your documents until you delete them or close your account. Disconnecting a mailbox stops all further access to it. To delete your account and associated data, contact hello@drypdf.com and we will remove it.
Security and isolation
Each account's documents and index are isolated to that account. We use encryption in transit, encrypt sensitive settings at rest, and follow least-privilege access.
Your rights
Depending on where you live, you may have rights to access, correct, export, or delete your personal data, and to object to or restrict certain processing. To exercise them, contact hello@drypdf.com.
Children
DRYPDF is not intended for children under 16, and we do not knowingly collect their data.
Changes
We may update this policy; we will change the effective date above and, for material changes, notify you in the app.