Privacy Policy
Last updated: 5 September 2026
This policy describes what GrimoirePrint actually does with your data. It was written by reading the running service rather than by describing an intention, and it is meant to be checked against it. If anything here does not match what you observe, tell us and we will correct it.
This policy is under review by our solicitors and the page changes as anything is settled. The date at the top moves whenever it does.
In short. We do not persistently store your document text or PDFs. Your document is converted on our servers; the finished PDF is held briefly — about five minutes — so you can download it, and is then deleted (a server restart within that window can leave a copy on disk until the container is replaced). Nothing is written to our database. We keep an email address and a credit balance if you buy credits. We never see your card details. We do not sell your data, and we do not use your documents to train machine-learning models.
1. Who we are
GrimoirePrint (grimoireprint.com) is operated by Commercial Maths Consulting Ltd (trading as GrimoirePrint), a company registered in England and Wales, company number 13451910, registered office Threeways, Sleepers Hill, Winchester SO22 4ND. We are the data controller for the personal data described below.
Reach us at [email protected], or through the contact form. Either is a valid route for every request in this policy.
2. Your documents
When you convert a document, its text and images are sent to our server, written to a temporary file so the renderer can read them, and deleted as soon as the conversion finishes. The PDF is held for five minutes so that you can download it, and is then deleted too.
Your documents are never written to our database, never included in our logs, and never sent to any third party. We do not read them, and we do not use them to train machine-learning models.
Two honest caveats. If your document links to an image on another website, our renderer fetches that image, and that website will see a request from our server. And the temporary PDF is deleted on a timer — if the server restarts inside that five-minute window, the file can survive on the container's disk until that container is replaced.
The editor on the website also keeps your draft in your own browser's storage so you do not lose it on refresh. That copy stays on your device; clearing your browser storage removes it.
3. What we collect, why, and our lawful basis
| What | Why | Lawful basis |
|---|---|---|
| Document text and images you submit | To produce your PDF | Contract |
| Your email address | It is your account. It is how credits reach you, how you sign back in, and how we answer a billing question | Contract |
| Credit balance and the record of every credit bought and spent | To run the service, and to answer "where did my credits go" | Contract; legal obligation for the accounting record |
| Your Lemon Squeezy customer and order references | To match a payment to your account and to process a refund | Contract |
| Google or GitHub sign-in: your verified email address and that provider's account identifier | So the same person reaches the same account from any device | Contract |
| An opaque identifier stored in your browser | To count the free monthly conversions without asking you to sign up | Contract (it is what delivers the free tier you asked for) |
| Your IP address | Rate limiting, abuse prevention, and stopping the free allowance being farmed | Legitimate interests — keeping a small service usable and affordable |
| API keys (stored only as a hash) and their usage | To authenticate API calls against your balance | Contract |
| What you send us through the contact form | To answer you and fix the problem | Legitimate interests — responding to the person who contacted us |
| Website analytics | To see which pages and features are used | Consent — analytics do not load until you accept. See section 5 |
| What our analytics provider is told about a purchase: the pack, its price, the order and variant references, and a pseudonymous account id. This is a copy for measurement — it is not the purchase record itself, which is the three rows above | To measure sales. Sent from our server when your credits land — see section 5 | Consent for the identifying copy. If you did not consent, none of it is sent to the analytics provider; all it receives is a count of purchases by pack and price in a shared anonymous total, which identifies nobody and which we keep on the basis of legitimate interests — knowing how much we sell. Your own purchase record is unaffected either way |
Buying is never anonymous — measuring it can be. These are two different things and it is worth being exact about which is which:
- The purchase itself — your email address, your account, your credit balance and ledger, and the Lemon Squeezy order and customer references — is how we deliver what you bought. We keep it because we have to: it is what puts credits on your account, what lets you sign in and spend them, what answers "where did my credits go", and what a refund is worked out from. Lemon Squeezy holds its own record of the sale as the merchant of record, and issues your receipt. The lawful basis is performance of our contract with you — with the accounting entries kept for six years because tax law requires it. None of this is optional, and none of it is anonymous. Declining analytics does not make a purchase anonymous, and there is no way to buy credits from us anonymously.
- Measuring purchases — telling our analytics provider that a sale happened — is a separate copy made for our own product statistics, and that is the only part your consent governs. Decline, and the analytics provider is told only that a pack sold at a price, with nothing tying it to you. Your account and your credits are untouched by that choice.
We do not use any of this for advertising, we do not sell it, and we do not build profiles for anyone else.
4. Cookies and browser storage
| Name | What it does | Lifetime |
|---|---|---|
mdp_id |
An opaque token identifying your browser, so free conversions can be counted | 400 days |
mdp_sess |
Your signed-in session | 90 days, extended each visit |
mdp_oauth |
Holds the sign-in request while you are at Google or GitHub | 10 minutes |
| Editor storage | Your draft and your theme settings, kept on your device | Until you clear it |
| Analytics storage | A random identifier used to count returning visitors. Written only after you accept analytics — see section 5 | Until you clear it |
All three cookies are HttpOnly, Secure and
SameSite=Lax. None of them carries your balance: that is read from the database
on every request, so a stale cookie can never spend anything.
5. Analytics, and the choice you are given
We use Mixpanel, ingested in the EU, to count page views and to see which themes, backgrounds and options people actually use. It receives a random identifier, the page you are on, where you came from, and the name of the feature you used. It never receives your document.
Nothing analytics-related runs until you accept it. On your first visit a banner asks. Until you choose, and for as long as you decline, no analytics script loads and no analytics identifier is written to your browser — the site runs on its essential cookies alone, and everything except the counting still works. If the consent gate itself fails to load, analytics stays off. If your browser sends "Do Not Track", analytics do not run even after you accept.
Changing your mind is harder than it should be, and we would rather say so.
Your choice is remembered in your browser, and there is not yet a button on the site to
reverse it. To withdraw consent today, clear this site's storage in your browser — the
banner will ask again on your next visit — or block cdn.mxpnl.com in your
browser or an extension; nothing else on the site depends on it. A proper "cookie
settings" control is coming, and until it exists this is the honest position rather
than a claim that withdrawal is one click.
What this does not cover. Everything in this section is about measurement. It is not about the purchase itself: your account, your email, your credit balance and the order references are kept regardless of your analytics choice, because they are how we deliver the credits you paid for and issue your receipt — see the note under the table in section 3. A purchase is never anonymous to us. What follows is only about what our analytics provider is told.
Your choice follows you through the checkout. Nothing that identifies you is measured without your consent — not in your browser, and not on our server. When you buy credits, our server records the purchase after the payment lands, rather than relying on your browser coming back, and your analytics choice travels with the checkout and governs what that record contains.
If you accepted analytics, the record carries the pack, its price, the order and variant references and a pseudonymous account identifier — never your email — and the amount is added to that account's revenue total.
If you declined, never chose, or bought through an older checkout link that predates this, none of that is sent: no account identifier, no email, no order or variant reference, and nothing attached to a profile. The only thing recorded is a single anonymous entry saying that a purchase of that pack happened at that price, filed under a shared "anonymous" label that is not a person and cannot be traced back to one. It tells us how much we are selling and nothing else, and we keep it on the basis of legitimate interests. The same split applies to refunds, and nothing from your document is ever included either way.
The mdp_id identifier is different: without it we cannot count your free
conversions, so it is part of delivering the service rather than something you can turn off
and still use the free tier.
6. Who else sees your data
| Who | What they get | Their role |
|---|---|---|
| Lemon Squeezy | Your name, email, card details and billing address at checkout | Merchant of record — the seller of your credit pack, and an independent controller of what it collects, under its own privacy policy. Your card details never reach us. We receive back only the email you paid with and the order and customer references |
| Railway | Hosts the service, its database and its logs | Our processor |
| Resend | Your email address, to deliver a sign-in link or a purchase confirmation | Our processor. Transactional email only — there is no mailing list |
| GitHub | What you send through the contact form, filed in our private issue tracker | Our processor |
| Google or GitHub, if you sign in with them | The sign-in request. We ask only for your verified email address; we do not receive your name, avatar, contacts or repositories | Independent controllers for your account with them |
| Mixpanel | The analytics described in section 5: page views, which features and options you used, whether a conversion succeeded or failed and why, and — if you consented — the server-side purchase and refund records and, when you are signed in, a pseudonymous account identifier with your credit balance and which sign-in provider you used. Never your documents, and never the name of a file you upload | Our processor |
We will also disclose data where the law requires it, or to establish or defend a legal claim. Nobody else gets it.
The same list, with each provider's role, location and what it is used for, is kept as a sub-processor list alongside our Data Processing Addendum — which is what a business customer sending us personal data in their documents will want.
What the contact form sends. Your message, the subject you chose, and — only if you fill them in — your name and email, together with your browser's user-agent string and the time you sent it. If you tick "include my markdown & settings", your draft goes with it; if you do not tick it, it does not.
7. Where your data goes
Some of the providers above are outside the UK, principally in the United States. Where that happens we rely on a transfer mechanism recognised by UK law. We have now checked this provider by provider rather than giving you a blanket reassurance, and this is what each one is:
| Provider | What we rely on for transfers out of the UK |
|---|---|
| Railway (hosting) | UK standard contractual clauses with the UK International Data Transfer Addendum. We have signed Railway's data processing addendum |
| Cloudflare | EU standard contractual clauses (Module Two), amended by the UK Addendum for UK data, and the Data Privacy Framework |
| Resend (email) | EU and UK standard contractual clauses, and the EU–US Data Privacy Framework with its UK Extension |
| Mixpanel (analytics) | The EU–US Data Privacy Framework with its UK Extension, and standard
contractual clauses Modules Two and Three. Analytics are ingested in the EU
(api-eu.mixpanel.com) rather than the United States |
| GitHub (contact-form reports) | EU standard contractual clauses with the Information Commissioner's International Data Transfer Addendum, and the EU–US Data Privacy Framework |
| Lemon Squeezy (payments) | EU standard contractual clauses. Their terms do not name the UK Addendum, and we have raised it with them — see the note below |
Lemon Squeezy's own data processing terms name the EU standard contractual clauses and do not mention the UK Addendum, and they are governed by the law of Utah. We have flagged that with them and with our solicitors. We would rather tell you about a gap in someone else's paperwork than let you assume there is not one.
8. How long we keep it
| Data | Kept for |
|---|---|
| Your documents | The duration of the conversion |
| The generated PDF | Five minutes |
| Sign-in links | They expire shortly after being sent, and are single use |
| Account, balance and credit history | While your account is open. Purchase records are then kept for six years, which UK tax law requires of us |
| IP addresses used for rate limiting | In memory only, for the length of the limit window |
| The IP a browser or API key was first and last seen from | 30 days after the browser or key was last seen. A sweep then erases the address; the account or key it belonged to is not deleted, only the IP |
| Contact-form messages | 24 months from when you send it, and sooner on request |
| Analytics | 18 months |
9. Your rights
Under UK GDPR you can ask us for a copy of your personal data, to correct it, to delete it, to restrict or object to how we use it, and to have it sent to you in a portable form. Where we rely on your consent you can withdraw it at any time. It costs nothing, and we will answer within one month.
How to make a request. Email [email protected], or use the contact form, with "Privacy request" in the subject. Tell us which right you want to exercise, and give us the email address your account uses — that address is the account, so it is what lets us find your data. We may need to check the request really comes from you; normally that means replying from that address, and we will not ask you for anything more than we need. It costs nothing, and we will answer within one month. If a request is unusually complex we may extend that by up to two further months, and we will tell you within the first month if that happens. If we decline a request we will tell you why and how to complain.
Two things you should know before you ask:
- There is no self-service delete button yet. Erasure is done by hand, by us, on request. We would rather say so than imply a feature that does not exist.
- Erasing an account cannot erase the purchase record. We are required to keep the accounting entries for six years. What we can do is remove your address and sign-in details and leave the transaction as an unattributed record. If you have unused credits when you ask, tell us — see the Refunds & Cancellation Policy.
If you think we have got something wrong, please tell us first — but you can complain to the Information Commissioner's Office (ico.org.uk, 0303 123 1113) at any time, or to your own supervisory authority if you are in the EU.
10. Security
Everything travels over TLS. Sessions are signed and cannot be forged into a balance. API keys are stored only as a SHA-256 hash, so a copy of our database does not yield a working key — which is also why we cannot show you a key again after it is created. Passwords are not stored because there are none: you sign in with a one-time emailed link, or with Google or GitHub.
No service is perfectly secure, and we will not pretend otherwise. If a breach affects your rights we will tell the ICO within 72 hours and tell you where the law requires it.
11. Children
GrimoirePrint is not aimed at children. You must be at least 13 to use it — the age at which UK law lets someone consent to an online service on their own account — and 18 or over to buy credits, or have a parent or guardian's consent, as the Terms of Service explain. We do not knowingly collect the personal data of anyone under 13; if you believe we have, tell us and we will delete it.
12. Changes to this policy
When what we do changes, this page changes with it and the date at the top moves. If a change materially affects account holders we will email them.