Privacy Policy
What we collect, why, and the choices you have.
Last updated: October 2026
01 Who is responsible
The data controller is Byte Size Curiosity LLC, a New York limited liability company, mailing address 41 State Street, Suite 112, Albany, NY 12207, operating mergepdfs.dev and YouTubeTranscript.dev. Contact: support@youtubetranscript.dev.
02 Browser merges never upload your files
When you merge PDFs on the website's main page, everything happens inside your browser: reading the files, drawing previews, unlocking a password-protected file you give the password for, and building the merged PDF. Your files and passwords stay on your device. They aren't uploaded to us or anyone else, we can't see them, and we don't keep any record of browser merges. The page makes no network requests while it merges.
03 API merges are processed on our servers
- Files you send to the API (
POST /v1/merge), including through "Try the API" on your account page, are processed on our servers. If you give us file URLs, our server downloads them. - Files you upload through the API are stored privately so our processing queue can work on them.
- Merged results are stored privately so you can download them again from your account. They are only reachable through short-lived signed links (valid for one hour).
- We keep a record of each server merge (time, file names, page counts, sizes, credits used) as part of your usage history.
04 What else we collect
- Account details: email address and sign-in method (Google, email code or password; passwords are stored hashed by our auth provider).
- API keys: we store only a hash and the first characters of each key, plus when it was created and last used.
- Credits and billing: your credit balance, usage history and purchases. Card details are handled by Stripe; we never see them.
- Technical data: IP address, browser type, server logs and essential cookies that keep you signed in.
05 How we use it
- To provide the service: merge your files and deliver the results.
- To run your account, credits and payments, and to send service emails (sign-in links, receipts, password resets).
- To prevent fraud and abuse, and to keep the service secure and working.
We don't sell your personal data, we don't read your documents, and we don't use them to train any model.
06 Who we share it with
Only the providers we need to run the service, under their own privacy terms:
- Supabase: accounts, database and private file storage.
- Render: hosting and server-side processing.
- Stripe: payments.
We may also disclose data when required by law.
07 Shared account with YouTubeTranscript.dev
Your login works on mergepdfs.dev and YouTubeTranscript.dev. Each product keeps its own credits and data; your mergepdfs.dev files and usage aren't shown in the other product.
08 Retention
Files uploaded through the API and merged results are kept privately until you ask us to delete them or we remove them under our retention schedule. Account, usage and purchase records are kept while your account is open and as required for tax and accounting. You can ask us to delete your account and all associated data at any time.
09 Your rights
You can access, correct, export or delete your data, and object to or restrict certain processing. Email support@youtubetranscript.dev and we'll respond within 30 days.
10 Cookies
We only use cookies needed to keep you signed in and to secure checkout. No advertising cookies.
11 Children
mergepdfs.dev isn't for children under 13, and we don't knowingly collect their data.
12 Changes
We'll post any changes here and email you about significant ones.