Scope: This document applies to the Edith PDF Chrome extension for Google Chrome. It does not govern the Edith website or free browser-based PDF tools at https://edith.quinsy.app/tools — those are covered by separate website policies at https://edith.quinsy.app/privacy.
Privacy Policy — Edith PDF Chrome Extension
Effective date: 20 July 2026
Quinsy UG (haftungsbeschränkt)
Schönhausenstraße 41 28355 Bremen Germany
Commercial register: HRB 42890
Managing director: Helmut Albers
Privacy: privacy@quinsy.app Support: support@quinsy.app Contact: contact@quinsy.app
Corporate website: https://quinsy.app
Contact for privacy questions: privacy@quinsy.app
This Privacy Policy explains what data the Edith PDF Chrome extension processes, why we process it, and what choices you have.
1. What the extension does
Edith PDF is a Chrome extension that lets you open, view, create, annotate, sign, and manage PDF documents inside your browser. Working document data is stored locally on your device wherever possible.
The extension may:
- open PDFs from your computer, recent files, or linked web URLs
- store annotations, signatures, vault data, and preferences in your browser profile
- call Edith backend APIs for licensing, legal consent, telemetry, and template catalog delivery
2. Data we process on our servers
We process limited server-side data for licensing, fraud prevention, product telemetry, and legal-compliance records. We do not upload your PDF document content to Edith servers.
2.1 Licensing and customer records
When a license is purchased or activated, we may process and store:
- email address
- normalized email address for deduplication
- Lemon Squeezy customer and order identifiers
- order ID and payment metadata (we do not store full card numbers)
- license key, product ID, and variant ID
- activation count and activation timestamps
- internal customer identifier
We use this data to issue licenses, validate paid access, enforce activation limits, support customer portal access, and provide account-related support.
2.2 Device and installation records
When the extension is installed, started, or activated, we may process:
- device fingerprint generated by the extension
- user agent, browser, operating system, and device type
- locale and coarse country code
- install and last-seen timestamps
- linked license key when activated
We use this data to recover valid activations on the same browser profile, support fraud and abuse prevention, and understand product distribution at a coarse level.
2.3 Product telemetry
Edith PDF records limited, privacy-minimized telemetry events. Telemetry is stored without email addresses, document content, or raw document names.
Telemetry currently includes these event names:
- `install_created`
- `install_seen`
- `license_activated`
- `license_deactivated`
- `pdf_opened`
- `pdf_create_started`
- `pdf_created`
- `pdf_compressed`
- `signature_used`
- `pages_managed`
- `annotation_used`
Telemetry may include only structured context from an allowlisted set of fields, such as:
- feature or UI surface used
- annotation type
- file origin category (`local`, `web`, or `generated`) — not the file path or URL
- launch source
- page count (numeric)
- plan tier (free or paid)
- locale and coarse country code
- event timestamp
We do not collect filenames, document text, PDF binary content, or full document URLs in telemetry. We use telemetry to understand feature usage, improve reliability, and prioritize product decisions — not to inspect document content. Telemetry events are deleted automatically after 90 days.
2.4 Policy acceptance records
When you accept legal documents in the extension, we store the accepted policy versions, timestamp, device fingerprint, and related license or customer identifiers where available.
3. Data stored locally in your browser
This extension does not use tracking or advertising cookies.
For core PDF functionality, the extension stores working data locally in your Chrome profile using IndexedDB, Chrome extension storage (`chrome.storage`), and limited LocalStorage (for example UI layout preferences). This storage is technically necessary to operate the extension — to remember your documents, annotations, vault, license state, and settings. Under applicable EU law (including Germany's TDDDG), this strictly necessary device storage does not require a separate cookie consent banner.
Locally stored data includes:
- recent files metadata and file handles you grant
- annotations, thumbnails, and vault data
- saved signatures and autofill profiles
- language, accessibility, and license preferences
- legal-consent cache for offline-safe gating
Vault encryption
If you enable the encrypted vault for autofill profiles, vault data is encrypted locally in your browser before storage:
- AES-GCM (256-bit) for encrypting vault payload data
- PBKDF2 with SHA-256 (310,000 iterations) for deriving encryption keys from your vault passphrase
- a per-vault random salt and initialization vector (IV)
Your vault passphrase and derived keys are not sent to Edith servers. If you lose your passphrase and recovery answer, encrypted vault data cannot be recovered by us.
This data stays in your Chrome profile unless you delete it, uninstall the extension, or clear browser storage. Your PDF document content is not uploaded to Edith servers for normal viewing and editing.
4. Letter templates and fonts
When you use Create PDF with styled letter layouts, the extension may download HTML layout definitions and self-hosted fonts from https://edith.quinsy.app. These resources are served from our own domain — not from Google Fonts or similar third-party font CDNs.
5. Content script behavior
To detect PDF links and offer Open in Edith, the extension runs a minimal content script on pages you visit. It looks for PDF URLs and shows a small action control. It does not send page content to our servers.
6. Payments
License checkout is handled by Lemon Squeezy (merchant of record). We receive only the information required to provision and manage your license.
Subprocessors and service providers
For the Edith PDF Chrome extension and its backend APIs, we use:
| Provider | Purpose | Data processed |
|---|---|---|
| Vercel | Hosts API routes and serves template assets | IP address, user agent, request metadata, timestamps |
| Neon | Managed PostgreSQL database for extension licensing, telemetry, and legal-consent records | Customer email, license keys, device fingerprints, telemetry events, consent records |
| Lemon Squeezy | Payment processing, checkout, customer portal | Email, billing details, order ID, payment metadata, license provisioning data |
Each subprocessor processes data only as needed to provide its service. Their own privacy policies govern payment processing in particular.
Legal bases for processing (GDPR)
Where the GDPR or similar laws apply, we rely on one or more of the following legal bases:
- Performance of a contract — supplying licensed software, validating access, and fulfilling purchases
- Compliance with legal obligations — tax, accounting, and regulatory requirements where applicable
- Legitimate interests — securing the product, preventing abuse, understanding aggregated feature usage, improving reliability, and operating the service
- Consent — where required for policy acceptance records or jurisdiction-specific implementations
Data retention
We apply the following retention windows:
- Telemetry events (feature-usage events stored in our database): retained for 90 days, then deleted automatically by a scheduled job.
- Licenses, customer records, install/activation metadata, and policy-acceptance (consent) records: retained for contract performance and legal obligations (including commercial and tax retention), and to prevent abuse. These records are not subject to the 90-day telemetry purge.
- Locally stored browser data (IndexedDB, `chrome.storage`, and similar): remains under your control and may persist until you delete it, uninstall the extension, revoke permissions, or clear browser storage.
When data is no longer needed for the purposes above, we delete or anonymize it where feasible.
International transfers
Depending on where our service providers operate, personal data may be processed outside your country, including in the United States. Where required, we rely on appropriate safeguards for cross-border transfers, such as the EU Standard Contractual Clauses (SCCs) offered by our providers.
Your rights
Depending on your location, you may have the right to:
- access your personal data
- request correction of inaccurate data
- request deletion of personal data
- object to certain processing
- request restriction of processing
- request portability of certain data
- lodge a complaint with a supervisory authority
To exercise privacy-related rights, contact privacy@quinsy.app.
Supervisory authority
If you are in the EU, you have the right to lodge a complaint with your local data protection authority. Our lead supervisory authority in Germany is:
Die Landesbeauftragte für den Datenschutz und die Informationsfreiheit Bremen (LfDI Bremen) Arndtstraße 1 28195 Bremen Germany https://www.datenschutz.bremen.de
7. Data we do not collect in telemetry
We do not intentionally collect document content, document text, raw PDF filenames, exact location data, or long-term raw IP storage in telemetry payloads.
8. Children
Edith PDF is not directed to children, and we do not knowingly collect personal data from children.
9. Changes
We may update this extension Privacy Policy from time to time. Updated versions are delivered through the extension and our API. Material changes may require renewed acceptance in the extension.
For the Edith website and free web tools, see https://edith.quinsy.app/privacy, https://edith.quinsy.app/security, https://edith.quinsy.app/terms, and https://edith.quinsy.app/imprint.