Privacy
Last updated: April 8, 2026
1. Information We Collect
We collect the following information:
- Account information: name, email address (provided via Google sign-in or registration)
- Usage data: URLs archived, number of pages processed, formats used
- Payment information: processed securely by our payment provider (Paddle). We do not store credit card details.
- Technical data: IP address, browser type (for security and rate limiting)
- Product analytics: pages viewed, features used, the site or campaign that referred you, and a country-level location derived from your IP address. This may include a recording of how you moved through the page. Everything you type is masked before it leaves your browser — we can see that a field was filled, never what was put in it. Your email address is not shared with our analytics provider.
2. How We Use Your Information
- To provide and maintain the service
- To process payments and manage subscriptions
- To enforce usage limits per your plan
- To communicate important service updates
- To understand which parts of the service are used and where people get stuck, so we can fix them
3. Data Storage
Your account data is stored on our servers in the EU (Germany). Generated archive files are stored for a plan-dependent period (Free 14 days, Lite 30 days, Starter 90 days, Pro 12 months, Business 24 months) and then automatically deleted.
4. Third-Party Services
We use the following third-party services:
- Google OAuth: for sign-in, and — only if you connect it — for saving finished archives to your own Google Drive (Google Privacy Policy applies; see section 5)
- Paddle: for payment processing (Paddle Privacy Policy applies)
- Google Analytics: for aggregate traffic measurement (Google Privacy Policy applies)
- PostHog: for product analytics and session recording, with all typed input masked (PostHog Privacy Policy applies)
5. Google Drive Access
Saving an archive to Google Drive is optional. Nothing in this section applies unless you explicitly connect your Google account for it on your account page; signing in with Google does not on its own give Site2PDF any access to your Drive.
When you connect it, Site2PDF requests a single Drive permission, drive.file. This is Google's narrowest Drive scope: it grants access only to files this application itself creates. Site2PDF cannot read, list, modify or delete any other file in your Drive, and cannot see what your Drive contains. We also receive the email address of the connected Google account, so the account page can show you which Drive is connected.
What we do with it:
- Finished archives you choose to send are uploaded into a folder named Site2PDF in your Drive, created once on first use.
- If you set up scheduled captures with Drive delivery, each finished capture is uploaded to that same folder automatically.
- We do not read anything back out of your Drive, and we never upload anything you did not ask us to.
What we store, and how:
- A Google refresh token, so uploads can continue without asking you to sign in again. It is encrypted at rest with a key held in server configuration and never in our code repository, so a copy of the database alone does not yield a usable token.
- The email address of the connected Google account, and the ID of the Site2PDF folder.
You can disconnect at any time from your account page, which immediately deletes the stored token, the email address and the folder ID from our systems. You can also revoke access independently from your Google Account at myaccount.google.com/permissions. Disconnecting does not remove files already delivered — they are yours, in your Drive, and remain there until you delete them.
Google user data obtained through this connection is never sold, never used for advertising, never used to train any model, and never shared with third parties. It is used solely to deliver the archives you requested.
Site2PDF's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
6. Data Sharing
We do not sell, trade, or share your personal information with third parties, except as required by law or as necessary to provide the service (e.g., payment processing).
7. Cookies and Analytics
We use essential cookies for authentication and session management, and analytics cookies to measure how the service is used. We do not use advertising cookies, we do not run ad networks, and we do not sell or share your data with advertisers.
Analytics includes session recording: a reconstruction of how a page was used, such as where you clicked and where you scrolled. Text you type into any field is masked before it is sent, so the recording never contains a URL you entered, an email address or a password. You can block this like any other analytics script, with a browser extension or a content blocker, and the service will work exactly as before.
8. Your Rights
You have the right to:
- Access your personal data
- Request deletion of your account and data
- Export your data
- Opt out of non-essential communications
9. Data Retention
Account data is retained while your account is active. Archive files are deleted when their plan-dependent retention period ends (Free 14 days, Lite 30 days, Starter 90 days, Pro 12 months, Business 24 months). Upon account deletion, all personal data is removed within 30 days.
10. Contact
For privacy-related questions, contact us at petyasavenok@gmail.com.