Privacy Policy
Last updated: 2026-08-16
1. Who we are
FRONTPLUG LLC, a limited liability company organized under the laws of the State of Delaware, United States of America, operates brewmypdf at brewmypdf.com. For questions about this policy or to exercise your rights, contact support@brewmypdf.com.
2. Our role ★
There are two different kinds of data here, and we have a different role for each.
| Data | Our role | Governed by |
|---|---|---|
| Your account data — your email, billing, usage | Controller | This policy |
| Data you send us to render — which may contain personal data of your own users | Processor, acting on your instructions | DPA |
3. What we collect and why
| Data | Purpose | Legal basis (EEA/UK) |
|---|---|---|
| Email address, password (hashed) | Create and secure your account | Performance of a contract |
| API keys (hashed) | Authenticate API requests | Performance of a contract |
| IP address, User-Agent | Security, abuse prevention, audit records | Legitimate interests |
| Usage records (counts, sizes, timestamps) | Enforce plan limits and bill correctly | Performance of a contract |
| Billing details | Take payment (held by Stripe, not by us) | Performance of a contract |
We never store passwords or API keys in plain text — only a hash. We do not store full payment card numbers; our payment provider does.
We do not sell or share personal information, and we do not use it for cross-context behavioural advertising.
4. Cookies
We use only strictly necessary cookies, so there is no consent banner. The full list is in the Cookie notice. We do not use advertising or third-party analytics cookies.
5. How long we keep data ★
| Data | Retention |
|---|---|
| Generated output (PDF, images) | 24 hours by default, 30 days maximum |
| Request payloads (the JSON you send) | Not stored — deleted as soon as rendering finishes |
| Templates and account data | For as long as your account exists |
| Audit logs | 2 years, kept in anonymized form after account deletion |
| Billing records | As required by tax and accounting law |
Expiry and deletion are irreversible. We keep no backups for your benefit and cannot restore expired or deleted data — see Terms §10.
6. Who we share data with
Only the service providers we need to run the Service. They are listed, with their role and what they process, on our Subprocessors page. We also disclose data where the law requires it.
7. Where data is processed
The Service runs on Cloudflare's global network, and we and our providers are located in the United States and elsewhere, so your data may be processed outside your country. For transfers of personal data out of the EEA, the UK, or Switzerland, we rely on the European Commission's Standard Contractual Clauses and, for the UK, the ICO Addendum, as set out in the DPA.
8. Your rights
Depending on where you live, you may have the right to access, correct, delete, restrict, or object to the processing of your personal data, and to receive it in a portable format.
- Access — view your data in the console
- Portability — export templates and settings as JSON from Settings
- Erasure — delete your account from Settings; this removes your data from our database and object storage, and we confirm when it is done. Audit logs are kept for the legally required period with identifiers removed
- Restriction or objection — write to us
Contact support@brewmypdf.com. We respond to legitimate requests within one month. We do not charge for this, and exercising your rights will not cause us to treat you differently. If you are in the EEA or the UK you may also complain to your local supervisory authority.
9. California residents
If you are a California resident, you have the rights to know, delete, and correct personal information, and to opt out of sale or sharing. We do not sell or share personal information, so there is nothing to opt out of. Use the same contact address above; you may use an authorized agent.
10. Children
The Service is not directed to children. We do not knowingly collect personal information from anyone under 13. If you believe a child has given us personal information, contact us and we will delete it.
11. Security
We use TLS in transit, hash passwords and API keys, isolate every account at the database query level, block network access inside the rendering environment, and keep access audit records. No system is perfectly secure; we describe our measures in the DPA.
12. AI features ★
We do not use customer data to train models. If you use an AI feature, the prompt is sent to our AI provider listed on the Subprocessors page solely to produce your result.
13. Changes
We will post any update here with a new "last updated" date, and give notice of material changes by email or in the console.
14. Language
This policy is published in English and Korean. The English version is the authoritative version; the Korean version is a convenience translation.