UnoPDF.ai
UnoPDF Trust Center

Your document. Your control.

See exactly where each kind of data goes, what stays on this device, and what you can delete immediately.

No cloud PDF library Review before AI edits One-click local deletion
Current architectureLocal-first by design

Manual editing and batch file output run in your browser. AI is a separate, visible action.

Local PDFs now0Stored only in this browser
PDFs in UnoPDF cloud storage0No cloud document library exists
AI training defaultOffOpenAI API inputs are not used for training by default
AI response storagestore:falseConfigured on every Uno request
Transparent data map

What happens in every workflow.

No vague “secure by design” label. Here is the actual boundary.

This device

Manual editor

PDF bytes, annotations, and up to five recent files live in this browser’s IndexedDB workspace. Text edits, drawing and page rendering all happen here.

Nothing is sent while you annotate, draw or edit text.
Explicit consent

Structural edits

Moving an image, removing vectors or rewriting text at object level cannot be done in the browser. For those, the document is sent to UnoPDF’s own worker, processed, and returned — after you confirm the notice, once per document.

Declining keeps the document local; the editor continues with everything it can do on this device.
AI request

Uno AI commands

Only extracted text blocks and your instruction pass through Firebase Functions to OpenAI.

The original PDF bytes are not included in command requests.
Explicit consent

Uno Vision OCR

Prepared page images are sent through Firebase Functions to OpenAI only after you confirm the OCR notice.

OCR never starts silently and detected text is reviewed before it is applied.
Local output

Batch automation

Original PDF bytes and generated ZIP output remain in your browser. Extracted text is sent for each AI command.

New PDF copies are generated locally only after your approval.
Cloud metadata

Account workspace

Firebase stores identity, profile preferences, plan metadata, usage counters, saved command workflows, and last authenticated activity. The referring hostname and campaign parameters from your first visit may be recorded once, for owner-only attribution reporting.

PDF bytes, PDF text, full referrer URLs, raw IP addresses, and precise location are not stored in your account.
Self-hosted

Visitor statistics

Page views are counted by a Plausible instance we run on our own server. It sets no cookies, stores no IP address, and builds no cross-site profile, so there is nothing to consent to and nothing to opt out of.

No cookies, no device fingerprint, no raw IP address, and no data shared with an advertising network.
AI provider transparency

OpenAI API, with realistic retention language.

UnoPDF sends AI requests with response storage disabled. OpenAI states that API inputs and outputs are not used to train models by default. Standard abuse-monitoring logs may still retain customer content for up to 30 days unless the API organization is approved for stronger data-retention controls.

Provider policy
Your controls

Delete, export, or reset.

These controls act on the real data locations described above.

This browser

Delete local PDF history

Removes PDF bytes, annotations, and recent-file records from UnoPDF’s IndexedDB workspace on this device.

This browser

Reset local app data

Clears local preferences, usage counters, and privacy-safe analytics events. Firebase sign-in remains active.

Portable JSON

Download privacy snapshot

Exports identity/profile metadata and local usage information. PDF content is deliberately excluded.

Privacy is a product surface, not a footer promise.Return here whenever you want to inspect or remove your UnoPDF data.
Open the private editor