Privacy Policy
Last updated: April 11, 2026 ยท Effective date: April 11, 2026
Konomic is built around a simple promise: your files and personal data are yours, not ours. This policy explains exactly what we collect, why, and how we protect it.
1. Who we are
Konomic is a privacy-focused online PDF toolkit operated from the European Union. The data controller for the purposes of GDPR is Konomic. For privacy questions, contact privacy@konomic.io.
2. Data we collect
Account data (only if you sign up)
- Email address โ required to create an account and for password resets
- Password โ stored as a bcrypt hash, never in plain text
- Display name โ optional
- Subscription status โ current plan and billing period
Usage data
- Operation counters โ daily counts per tool to enforce tier limits
- File metadata โ file size, format, and processing time (NOT file content)
- IP address โ for rate limiting and abuse prevention, deleted after 30 days
- Browser user agent โ to render the appropriate UI
File content (transient)
- The PDF or document you upload, processed and deleted within 1 hour
- The result file, available for download for 1 hour
Payment data
- Processed entirely by Stripe โ we never see or store credit card numbers
- Stripe customer ID stored to link your account to your subscription
- Invoice records (date, amount, currency) for tax compliance
3. What we DON'T collect
- โ Content of your files (we process and delete, not analyze)
- โ Files for AI model training (yours or anyone's)
- โ Browser history outside konomic.io
- โ Location data beyond rough country from IP for compliance
- โ Cookies from third-party trackers (no Google Analytics, no Facebook Pixel)
- โ Contacts, calendar, or other device data
4. Why we collect data
- To deliver the service โ process your files and return results
- Account management โ let you sign in, see history, manage subscription
- Billing โ process payments and prevent fraud (via Stripe)
- Abuse prevention โ rate limiting and security monitoring
- Service improvement โ aggregated, anonymized usage stats only
- Legal compliance โ tax records, court orders we're legally required to comply with
5. Legal basis (GDPR Article 6)
- Contract โ to deliver the service you signed up for
- Legitimate interest โ abuse prevention, security monitoring
- Legal obligation โ tax records, regulatory compliance
- Consent โ for optional features like email newsletters (revocable anytime)
6. How long we keep data
- File content โ 1 hour, then permanently deleted
- IP addresses โ 30 days, then deleted
- Account data โ until you delete your account
- Invoice records โ 7 years (legal requirement)
- Backups โ encrypted, retained 7 days, EU-stored
7. Who we share data with
We share data only with vetted processors required to deliver the service:
- Stripe (payments) โ credit card processing, located in EU and US
- Resend (transactional email) โ password resets, sign request emails
- Groq (AI inference) โ only when you explicitly use AI features; content discarded immediately
- Hosting provider โ German VPS provider for our infrastructure
We have Data Processing Agreements (DPAs) with all processors. We never sell or share data with advertisers, data brokers, or marketing companies.
8. International transfers
Our servers are in the EU. Stripe processes payments in EU and US under Standard Contractual Clauses (SCCs). We are not subject to the US CLOUD Act because Konomic is a European company without US infrastructure.
9. Your rights (GDPR)
You have the right to:
- Access โ request a copy of your personal data
- Rectification โ correct inaccurate data
- Erasure โ delete your account and data (the "right to be forgotten")
- Restriction โ limit how we process your data
- Portability โ export your data in a machine-readable format
- Objection โ object to processing based on legitimate interest
- Withdraw consent โ for any consent-based processing
- Lodge a complaint โ with your local data protection authority
To exercise any right, email privacy@konomic.io. We respond within 30 days.
10. Cookies
We use only essential cookies (authentication session, language preference). We do NOT use tracking cookies, advertising cookies, or third-party analytics. See our Cookie Policy for details.
11. Security
Files are encrypted in transit (TLS 1.3) and at rest (LUKS2 with AES-256). Account passwords are bcrypt-hashed. We follow industry best practices for infrastructure security. See our Security page for details.
12. Children's privacy
Konomic is not directed at children under 13 (or 16 in some EU jurisdictions). We don't knowingly collect personal data from children under these ages. If you believe we have, contact us and we'll delete it.
13. Changes to this policy
We may update this policy occasionally. Material changes will be announced via email and on the website at least 30 days before taking effect.
14. Contact
For privacy questions, requests, or complaints, email privacy@konomic.io. You can also lodge a complaint with your local data protection authority at any time.