Privacy Policy
Last updated: 2 August 2026.
This policy explains what personal data urltodoc collects, why, and what you can do about it. It covers this website and the rendering API.
1. Who is responsible
urltodoc is owned and operated by Kadiaak OÜ, Sepapaja tn 6, 15551 Tallinn, Harju Maakond, Estonia. VAT number: EE102437021. Company registration number: 16357744. Kadiaak OÜ is the data controller for the data described below.
For any question about this policy, or to exercise the rights in section 7, write to hello@urltodoc.com.
2. What we collect
a. Account data
When you create an account we store your name, your email address, a hashed version of your password, and the date your email was verified. We never store your password in a readable form.
b. Billing data
Payments are processed by Stripe. We store the identifiers Stripe gives us — your customer reference, your subscription and its status — so we can tell what you are entitled to. Card numbers never reach our servers; they go directly to Stripe.
c. Render records
Every render writes a row describing the job: the URL or a reference to the HTML you sent, the options you chose, when it ran and how long it took, the number of pages, the file size, a checksum, the outcome, any error, and the callback URL if you asked for a webhook. We use these records to bill credits, to show your history, and to debug failures.
d. The documents themselves
The files we produce are stored so you can download them, and deleted when their retention period expires (see section 5). If the page you asked us to render contains personal data, that data is inside the document we store for you.
e. Usage analytics
We use PostHog to understand how the product is used. PostHog is hosted in the European Union. When you are signed in, your analytics activity is linked to your email address and name. When you are signed out, no personal profile is created.
f. Server logs
Our servers keep technical logs — IP address, timestamp, requested path, error traces — which we use to keep the service running and secure.
3. What we deliberately do not keep
- Document passwords. If you ask us to encrypt a PDF, the password is used for that render and then discarded. It is not written to the database, not included in your render history, and not sent to any analytics tool. We only record that the document was protected.
- Card details. See section 2b.
4. Why we are allowed to process it
- To perform our contract with you — running your renders, storing your files, billing you, and supporting you.
- Our legitimate interest — keeping the service secure and reliable, preventing abuse, and understanding how the product is used.
- Legal obligation — keeping the accounting records tax law requires.
5. How long we keep it
Rendered documents are kept for the retention period set on the request. The default is 7 days. You may choose 1 hour, 24 hours, 7 days, 30 days, 1 year, 7 years, or to keep the file indefinitely. When the period expires the file is deleted.
Render records — the job metadata in section 2c — outlive the file, because they are what your invoice is built from.
Account data is kept while your account exists. Invoices and the records behind them are kept as long as accounting law requires.
6. Who else processes it
We use a small number of providers, each only for the purpose listed:
- Amazon Web Services — runs the browser that renders your documents, and stores the files. Rendering and storage currently take place in the United States.
- Stripe — payments and invoicing.
- PostHog — product analytics, hosted in the European Union.
- Resend — delivers account emails such as address verification and password resets. It receives your email address and the contents of those messages.
We do not sell personal data, and we do not share it with anyone for advertising.
Transfers outside the EU. Amazon Web Services and Resend are established in the United States, and our rendering and file storage run on AWS infrastructure there, so part of your data is processed outside the European Economic Area. These transfers rely on the European Commission's standard contractual clauses in our agreements with those providers.
7. Your rights
If you are in the European Economic Area you may ask us to give you a copy of your data, correct it, delete it, hand it over in a portable format, restrict what we do with it, or object to processing we base on legitimate interest. Write to hello@urltodoc.com and we will answer within one month.
You may also complain to the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), or to the supervisory authority where you live.
8. Security
Traffic to the API and this website is encrypted in transit. Passwords are hashed. API keys identify your account and should be treated as secrets — anyone holding one can spend your credits and read your renders. If you believe a key has leaked, rotate it from your dashboard and tell us.
9. Children
The service is for professional use and is not directed at children. We do not knowingly collect data from anyone under 16.
10. Changes
If we change this policy we will update the date at the top. If a change materially affects how we handle your data, we will tell account holders by email before it takes effect.