privacy
How to read a privacy policy on a free tool
A privacy policy looks long on purpose, and most people close it. You do not have to read all of it. For a free tool that handles your files, four questions cover almost everything that matters, and you can find each one by skimming.
How long do they keep the file
Look for a deletion window. The better services give a clear number: an hour, two hours, a set number of days. A short window is a good sign, because it shows the company has thought about it. A long window is not really the problem; the thing to watch for is a policy that never gives a deletion time at all, because if it does not say when your file is removed, you have no reason to think it ever is.
Do they train AI on it
This one has become important. The larger services now state plainly that they do not use your files to train AI models, and that is worth counting in their favour. What you are checking for is silence. A newer or smaller tool that says nothing about training has made you no promise, and silence is not the same as no.
Who else can reach it
Files often pass through other companies: hosting providers, payment processors, analytics services. A policy usually lists these somewhere, sometimes under a heading like third parties or subprocessors. You are not trying to judge each one. You are just seeing how long the chain is, because every extra company is one more place your file rests.
What they collect about you
The file is one thing; you are another. A site can delete your document in an hour and still run trackers that follow you around afterwards. These sit in a different part of the policy, often a friendlier sounding one. Read both, because they are frequently written in very different tones.
When you would rather not check
Reading the policy is the honest way to judge a tool that uploads your file. The other way is to remove the need. A tool that keeps the file on your own device has no retention window, no subprocessors, and no policy to trust, because the file never leaves. We made that case in full in are online PDF tools safe, and the ten second way to check a tool is in how to tell if a website uploads your file.
Frequently asked questions
What should I look for in a privacy policy?
Four things: how long your files are kept, whether they are used to train AI, which other companies can access them, and what is tracked about you beyond the file. Those cover most of what matters.
Is a short retention time a good sign?
Usually yes. A clear, short deletion window shows a service that has thought about it. A policy that says nothing about how long files are kept is the one to be wary of.
What does it mean if the policy says nothing about AI training?
Silence is not a promise. The larger services state plainly that they do not train on your files. When a policy is quiet on the point, you cannot assume the same.