Polityka prywatności
Ostatnia aktualizacja: 22 September 2026
Ten dokument jest dostępny po angielsku i po węgiersku - poniżej widzisz wersję angielską.
This notice explains what personal data MammothPDF ("we", "us") processes when you use mammothpdf.com and its tools, why, for how long, and what your rights are. The short version: your files are processed in your browser and never reach us; what we do process is the little that running an account, a subscription and a fair-use limit needs.
1. Who is responsible
The data controller is Kocsis Roland András, sole proprietor (egyéni vállalkozó), 8000 Székesfehérvár, Horvát István lakótelep 10., 4th floor, door 4, Hungary; sole-proprietor registration number 60210951, tax number 90864041-1-27 ("we"). For anything about your data, write to info@mammothpdf.com. We have not appointed a data protection officer, as the law does not require one for a service of this size and nature.
2. Your files never leave your device
Every PDF tool on this site runs inside your browser, on your own device. The files you open, their contents, the pages, the text, the images, the passwords you type to unlock a file, the signatures you draw - none of it is uploaded to us or to anyone else, none of it is stored by us, and we cannot see it. Closing the tab discards it.
The only things fetched from the network while you work are the site's own code and assets - fonts, the OCR engine and its language files - and they come from our own domain, not from a third-party content network, so no outside party learns which tool or language you used. The result you save is written straight to your device by your browser.
Files you produce carry a standard "Producer: MammothPDF" entry in their document properties, the way every PDF names the program that wrote it. That is metadata in your file, not data we receive.
3. What we process, and why
3.1 Using the tools without an account. When you first run a tool, we create an anonymous session in our authentication service: a random identifier stored in a cookie, with no name or e-mail attached. Each run adds one to a per-day, per-tool counter under that identifier, which is how the daily limit of the free tier is applied. To keep that limit meaningful when a cookie is cleared, we also count runs per network address: the address is hashed with a secret before it is stored, so the stored value identifies nobody on its own, and it is deleted after two days. Legal basis: our legitimate interest in offering a free tier with a fair-use limit and in preventing abuse (GDPR Art. 6(1)(f)).
3.2 Your account. If you register, we process your e-mail address and a password (stored only as a hash by our authentication provider), or, if you sign in with Google, the e-mail address and account identifier Google provides. We keep an optional display name if you set one, your interface language, and whether your e-mail is confirmed. Legal basis: performance of the contract with you (Art. 6(1)(b)).
3.3 Subscriptions. Payments are handled by Paddle, which sells the subscription to you as the merchant of record: your name, billing address, tax details and payment card are collected and held by Paddle, and we never see the card. From Paddle we receive and store the identifiers needed to know what you bought: a customer id, a subscription id, its status, plan, seat count, billing interval, currency and renewal date. Legal basis: performance of the contract (Art. 6(1)(b)); Paddle keeps its own records under its own accounting obligations.
3.4 Teams. A Team subscription's owner can invite people by e-mail address. We store the invited address, an invitation token, the invitation's status, when it was accepted, and any label or group name the owner gives a member. If you are invited, we process your address on the owner's behalf until you accept or the invitation is withdrawn; once you join, your membership is part of your own account. Owners see the members' addresses and names; members see the owner's name and the team's renewal date, never its price. Legal basis: performance of the contract with the team's owner and, once you join, with you (Art. 6(1)(b)).
3.5 Devices with a Pro session. A Pro subscription may be active on a limited number of devices at once. To count them, the browser keeps a random device identifier in its local storage and we record, per account, which identifiers were last active and when. Clearing that storage simply makes the browser count as a new device. Legal basis: legitimate interest in enforcing the terms of the subscription (Art. 6(1)(f)).
3.6 Saved settings and signatures. Pro users can save named option presets per tool, and the Merge tool remembers its last-used settings. These are the settings themselves (page rules, sizes, colours, texts you typed into a template), stored under your account until you delete them. A Pro user can also save images they use repeatedly - a signature drawn, typed or uploaded in the Sign tool, a logo for the Watermark tool, an image (a logo, a stamp) for the Edit tool - each the image alone, as a small PNG or JPEG under a name of their choosing, at most five of each kind - so they are available on every device they sign in on; it is stored only when they press "Save to my account", is removed with one click and goes with the account. The document being signed is never stored. Legal basis: performance of the contract (Art. 6(1)(b)).
3.7 Notices inside the app. We keep short in-app notices for you - an invitation accepted, a member who left, a subscription that ended - with the date and, where relevant, the address involved. Legal basis: performance of the contract (Art. 6(1)(b)).
3.8 E-mails we send. We send only the e-mails an account needs: confirmation of your address, password reset, a team invitation, and notices about your subscription. We send no newsletters and no marketing. Legal basis: performance of the contract (Art. 6(1)(b)).
3.9 Security and technical logs. Our hosting provider records the requests your browser makes to our servers - the address, the page or endpoint, the browser type, the time - for a short period, to keep the service running and secure. Our sign-in and sign-up forms use a bot-protection check (Cloudflare Turnstile) that evaluates browser signals without a puzzle. Legal basis: legitimate interest in the security and operation of the service (Art. 6(1)(f)).
3.10 Feedback you send us. If you use the feedback form, we store what you wrote, the kind you chose (bug, suggestion, other), the page and tool you sent it from, your interface language, your plan, your browser type and - only if you give it - your e-mail address, so we can reply. Signed in, the message is linked to your account. To keep bots out we also store the hashed network address for a per-day cap, and the form uses the same Cloudflare Turnstile check as sign-in. Messages are kept for at most a year. Legal basis: our legitimate interest in improving the service (Art. 6(1)(f)); the address, your consent by giving it (Art. 6(1)(a)).
3.11 Aggregate statistics. We count how many times each tool is run per day, per tier, as plain totals with no user attached, to see which tools matter. That is not personal data.
3.12 Crash reports. When a tool fails in your browser, it sends us a short technical report: which tool, the error message and the code stack, your browser type, the interface language, the page address, how many files the run had and how large they were. No part of your document is included - not its contents, not its name: the message and the stack are rewritten before sending so that any file name or path they may contain is replaced. We keep these for 90 days to fix what breaks, and the page tells you when one is sent. Legal basis: our legitimate interest in a working service (Art. 6(1)(f)).
3.13 Visitor statistics. To see which pages people reach and which they leave, we count page views through Vercel Web Analytics. It sets no cookie and stores nothing on your device: for each view it receives the page address, the referring site, and your browser, operating system, device type and country, from which it derives a visitor count that cannot be traced back to you and does not survive the day. It never runs on the account, sign-in, checkout or admin pages, and the page address is sent without its query string, so nothing that could name you is included. Legal basis: our legitimate interest in knowing how the site is used (Art. 6(1)(f)).
Beyond that we do not use advertising trackers, we do not follow you across other sites, we do not profile you, we make no automated decisions with legal or similar effect about you, and we do not sell or rent personal data.
4. Who receives data (our processors)
We use a small number of service providers who process data on our instructions, under data-processing agreements:
| Provider | What for | Where |
|---|---|---|
| Supabase | Database and authentication (accounts, sessions, counters, teams, presets) | EU (Ireland) |
| Vercel | Hosting of the website and its server functions; request logs; the cookieless visitor statistics in 3.13 | USA (EU-US Data Privacy Framework) |
| Paddle | Payments, invoicing, subscription billing - as merchant of record, Paddle is an independent controller for the purchase itself | UK / USA |
| Resend | Sending the account e-mails listed in 3.8 and the notification of a feedback message to us | USA (EU-US Data Privacy Framework) |
| Cloudflare | Turnstile bot protection on the sign-in, sign-up and feedback forms | USA (EU-US Data Privacy Framework) |
| Only if you choose "Continue with Google": the sign-in itself | USA (EU-US Data Privacy Framework) |
Where a provider is outside the European Economic Area, the transfer rests on the European Commission's adequacy decision for the EU-US Data Privacy Framework or on the Commission's standard contractual clauses. We disclose data to authorities only where the law obliges us to.
5. Cookies and browser storage
We set only what the site needs to work; there are no advertising or tracking cookies, and the visitor statistics in 3.13 store nothing at all on your device - which is why we show no cookie banner.
| Name | Purpose | Kind | Lifetime |
|---|---|---|---|
| sb-…-auth-token | Your session (anonymous or signed in) | Cookie, essential | Session, renewed while you use the site |
| NEXT_LOCALE | The language you chose | Cookie, preference | 1 year |
| theme | Light or dark mode | Local storage | Until cleared |
| mammoth_device_id | Counts this browser as one device for the Pro device limit | Local storage | Until cleared |
| Page-strip and sign-in throttle state | Remembers whether the page strip is open; slows repeated wrong passwords | Local storage | Until cleared |
6. How long we keep data
- Anonymous session counters: per day; the hashed network address for two days.
- Anonymous sessions themselves: until the cookie expires or you clear it; an anonymous account with no run for 30 days is deleted automatically, with its counters.
- Your account and everything under it (profile, teams, presets, notices): until you delete the account - which you can do yourself from the account page - or ask us to.
- Subscription records: for the life of the subscription and afterwards as long as accounting and tax law require the underlying invoices to be kept (Paddle holds those; we keep the identifiers).
- Invitations not accepted: until withdrawn by the owner or the team is deleted.
- Feedback messages: at most one year; the hashed network address with them.
- Visitor statistics: kept by the provider as counts per page and per day, with no identifier attached and nothing that could be traced back to a visit.
- Hosting request logs: a short period set by the hosting provider, typically days to a few weeks.
7. Your rights
Under the GDPR you may ask us for access to the personal data we hold about you, for its correction or deletion, for a restriction of processing, for a copy in a portable format, and you may object to processing based on our legitimate interests. Where processing rests on consent, you may withdraw it at any time without affecting what was done before.
You can do the most common things yourself: change your e-mail or password and delete your account on the account page, leave a team, withdraw an invitation, delete a preset. For anything else, write to info@mammothpdf.com; we answer within one month.
You also have the right to lodge a complaint with a supervisory authority - in Hungary the Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH), 1055 Budapest, Falk Miksa utca 9-11., naih.hu - or with the authority of the EU country where you live or work.
8. Children
The service is not directed at children. You must be at least 16 to create an account. If you believe a child has given us personal data, write to us and we will delete it.
9. Changes to this notice
When we change what we process or whom we use, we update this page and its "Last updated" date. For a change that matters to you - a new purpose, a new kind of data - we tell registered users by e-mail or with a notice in the app before it takes effect.