Privacy Policy
Last reviewed: 24 September 2026
This policy separates browser-local files from technical website requests, voluntary contact data and advertising data that may exist only after a future activation.
Controller
Paul GardeaCluj, Romania
[email protected]
+40 750 435 191
Browser-local user files
For browser-local tools, selected images and PDFs are processed by application code in the browser. prvkit does not intentionally upload those file contents for processing. Generated results use local objects or Blobs. OCR text, GPS findings, supported metadata inspection and PDF rendering remain browser-local. Application models, WASM and PDF.js are downloaded assets, not upload APIs.
Technical network data
Normal delivery and security infrastructure may process IP address, request date and time, requested path, response status, browser or user-agent information and network-security signals. Purposes include delivery, security, abuse prevention, troubleshooting and reliability. Where applicable, the operator relies on legitimate interests under GDPR Article 6(1)(f) to operate the website, maintain security, prevent abuse, diagnose failures and maintain reliability, balanced against user rights.
The planned production retention target for origin logs is 14 days, with possible exceptions for a security incident, abuse investigation or legal obligation. This target is not represented as actively enforced: it must be configured and tested during deployment. Cloudflare controls its own retention practices. The origin infrastructure is planned to be hosted in the European Union; the exact location must be verified at deployment.
Contact information
Email or phone communications contain information a person chooses to provide. It is used to answer requests, provide support, address security or abuse matters and communicate about the service. The operator relies on legitimate interests in receiving and responding to support and general inquiries where applicable. Circumstances may require another lawful basis for a specific communication. Communications are retained only as long as reasonably necessary to handle the request and meet legitimate or legal requirements.
Providers and recipients
Relevant categories can include hosting infrastructure, Cloudflare DNS/CDN/security and the email provider. Advertising and CMP providers are not active in this release. If advertising is enabled, the active providers and consent controls will be disclosed before relevant processing begins.
International data transfers
Infrastructure, email, CMP or advertising providers may operate internationally. If personal data is transferred outside the European Economic Area, the applicable provider and legal arrangements must be reviewed. Safeguards may include an adequacy decision or appropriate contractual safeguards such as Standard Contractual Clauses where applicable. prvkit does not state that a particular safeguard is in place until it has been verified for the production provider and account relationship.
Future advertising and consent
If advertising is enabled on prvkit, enabled partners may use cookies, local storage, IP address, browser or device identifiers and ad-measurement data depending on provider, location, consent, applicable law and configuration. A suitable certified CMP will be used where required, and the consent interface will reflect the actual active vendor set.
Rights
Subject to applicable conditions, rights may include access, rectification, erasure, restriction, objection, portability where applicable, withdrawal of consent where consent is the basis, and a complaint to the Romanian supervisory authority, ANSPDCP.
Automated decisions
SafeShare OCR and pattern detection are local utilities. prvkit does not use them for legal or similarly significant automated decisions and does not perform identity profiling.