Privacy policy
The short version: your documents never leave your device. Every Plume PDF tool does its work inside your browser. We never receive, store or see the files you process. Our one server-powered tool, the barcode generator, is covered in its own section below.
Last updated July 2026
Your files
We never upload your PDF to any server. That is the whole point of Plume. When you use a tool such as Merge PDF, your file is opened and processed right here in your browser. We have no access to its contents at any point, and nothing is kept once you close the tab.
The barcode generator, the one exception
Every PDF tool on this site runs entirely in your browser. That has not changed and never will. The barcode & QR generator is different, and we say so plainly: it renders on our servers. When you generate a code, the content you type is sent to our server, used in memory to draw the image, and returned to you. We do not store the content you encode. What we keep is a technical event record: the barcode type (e.g. QR, Code 128), the output format, the general category and length of the content (e.g. “a URL, 42 characters”), how long the render took, whether it was a preview or a download and whether it succeeded or hit the daily limit, and a timestamp. The content of sensitive codes (Wi-Fi details, contact cards, phone numbers, payment strings) is never stored in any form. To meter the free daily limit we set one functional cookie holding a random identifier, kept for up to a year; it is used only for counting and abuse prevention, never for advertising, and is not joined to any analytics or ad pixel. One practical note: a barcode is designed to be read by anyone who scans it, so never encode secrets, in any generator, ours included. That event record is kept as a rolling log of the 50,000 most recent entries, so older ones are dropped automatically, and the daily counters expire at the next UTC midnight.
Saved signatures (Sign PDF)
One thing does persist, by design: signatures and initials you save in the Sign PDF tool are kept in your browser’s local storage (on your device only, never on a server) so they’re ready the next time you sign something. They stay until you delete them from the tool’s signature list or untick “Remember my signatures on this device”, which clears them immediately. On a shared or public computer, we recommend turning that option off or deleting your saved signatures when you’re done.
What we collect
To understand which tools people use and how the site performs, Plume uses Google Analytics. It records pseudonymous usage (the pages you open, your rough region, and your device and browser type) and sets a small analytics cookie (named “_ga”) to recognize a returning visit. It never sees your documents: your files are opened and processed entirely in your browser, so their names and contents are never sent to Google or to us. In the EU and UK we ask before it loads, so you can decline and no analytics cookie is set. We don’t sell data.
If you agree, Plume also uses the Meta pixel and Conversions API to measure our Facebook and Instagram ads, so we can tell which ads bring people who genuinely find the tools useful. It records the same kind of pseudonymous activity (viewing a page, opening a tool, or finishing a job) together with technical details your browser sends anyway (such as your IP address and browser type), and sets Meta cookies (“_fbp”, plus “_fbc” if you arrived from an ad). Because Plume has no accounts, we never send Meta your name, email, or phone, and, exactly as with everything else, never your file names or their contents. In the EU and UK we ask before it loads; elsewhere you can block it through your browser.
On the same consent basis, Plume also runs Google Ads conversion measurement, so we can tell which ads bring people who actually complete a tool (say, download a merged PDF) rather than just click. It rides the same Google tag as Analytics and records only that a conversion happened; it never sees your file names or their contents. It sets one first-party advertising cookie (“_gcl_au”) so a finished job can be linked back to the ad you arrived from. In the EU and UK we ask before it loads; elsewhere you can block it through your browser.
The one number we do count: when a tool finishes a job, your browser tells our server how many files were processed so we can show a global “files processed” total. The request carries that number and nothing else: no file names, no file contents, no cookies, no account. Like any request to any website it does carry your IP address, which we hold for 60 seconds purely so the counter cannot be flooded, and then it expires.
These analytics and advertising tools are loaded through Google Tag Manager, a container that helps us manage them, and we only ever load the specific trackers named on this page through it. Nothing loads until consent applies, and you can change your mind at any time: use the “Your privacy choices” link in the site footer to turn analytics and advertising off (or back on). We also honor your browser’s Global Privacy Control signal. If it’s enabled we treat it as an opt-out and load none of these trackers.
Cookies
Plume’s tools work without requiring you to sign in. Google Analytics sets one analytics cookie (“_ga”) to count returning visits, and, only where you’ve agreed, the Meta pixel and Google Ads set advertising cookies to measure our ads (“_fbp”, plus “_fbc” if you arrived from a Meta ad, for the pixel; “_gcl_au” for Google Ads conversion linking). None of these hold personal details, and none ever see your files. In the EU and UK we ask before loading any of them; elsewhere you can block them through your browser’s cookie controls. Everything else we store is functional and either stays on your device (such as the saved-signature library described above) or, for the barcode generator alone, is the metering cookie and server-side counters described in its section, and you can clear the on-device data at any time from the tool or through your browser’s site-data settings. How long each one lasts: “_ga” for two years, “_fbp” and “_fbc” for 90 days, “_gcl_au” for 90 days, and the barcode metering cookie for twelve months.
Third parties
Google Analytics, provided by Google, receives the pseudonymous usage described above; it never receives your documents. Where you’ve agreed, Google also receives a signal through its Ads conversion tag that an ad led to a completed tool, never your documents or personal details. Where you’ve agreed, Meta (Facebook) receives the ad-measurement activity and technical data described above through its pixel and Conversions API, never your documents, and never your name, email, or phone. Fonts are self-hosted with the site, so no font requests go to third-party servers while you browse. Our hosting provider processes standard server logs (such as IP addresses) to deliver and secure the site, as is normal for any website. The barcode generator’s metadata-only event records and daily counters are stored with our database provider (Upstash), which never receives the content you encode.
International transfers. Where you’ve agreed to analytics or ad measurement, Google and Meta process that data in the United States. Both self-certify under the EU-US Data Privacy Framework (and its UK extension) and rely on the European Commission’s Standard Contractual Clauses as safeguards for these transfers. This only happens after consent applies; if you decline, no such transfer takes place.
Your rights, legal basis & how long we keep data
Legal basis. Analytics and advertising run only on your consent, which you can withdraw at any time. The anonymous files-processed counter and standard server security logs rely on our legitimate interest in running and protecting the site. The barcode generator processes the content you type in order to render your code (to provide the service you requested) and keeps only the metadata event record described above, on a legitimate-interest basis, for abuse prevention and product analytics.
How long we keep it. Google Analytics and Google Ads data follow Google’s standard retention (up to 14 months for event data); Meta event data follows Meta’s standard windows. The barcode metering cookie lasts up to a year; the barcode event records are aggregate/metadata only and are never tied to you. The global “files processed” figure is a single running count with no personal data. Anything stored on your own device (saved signatures, tool preferences) stays until you clear it.
Your rights. Where the GDPR or UK GDPR applies, you have the right to access, correct, erase, restrict or object to processing of your personal data, and to data portability. Because Plume has no accounts and never receives your files, the only personal data involved is the analytics/advertising identifiers described above. You can withdraw consent at any time (footer → “Your privacy choices”) or block the cookies in your browser. You also have the right to lodge a complaint with your local data protection authority (in the EU, your national DPA; in the UK, the ICO).
Who is responsible. Plume is the data controller for this site. For any privacy request or question, contact us at the address below and we’ll respond.
Changes & contact
If this policy changes, we’ll update the date above. Questions about privacy, or want to exercise a data right? Email hello@plumedocs.com.