šŸ”’LockedPDFs

Privacy Policy

Effective: 7 March 2026Last updated: 7 March 2026

LockedPDFs ("we", "our", "us") is operated by FinLens Advisory, registered in India. We are committed to protecting your personal data in accordance with the Digital Personal Data Protection Act, 2023 (DPDP Act).

1. The Core Promise

Your PDF files are never uploaded to our servers. All document processing happens entirely within your browser using client-side technology. We have no technical ability to access, read, or store your documents — because they never reach us.

2. What Personal Data We Collect

We collect only what is strictly necessary to provide our service: a) Account Data • Email address (required for account creation and login) • Password (stored as a bcrypt hash — we cannot read your password) • Account creation date b) License & Billing Data • Plan type (Free / Pro / Team) • Subscription start and end dates • Razorpay Payment ID (a reference number — we do not store card or UPI details; these are handled entirely by Razorpay) c) Usage Data (minimal) • Login timestamps • No document metadata, filenames, or content is ever logged We do NOT collect: • The contents of any PDF you process • Filenames of documents you process • Any biometric data • Any data about minors (our service is for professionals aged 18+)

3. Why We Collect This Data (Purpose)

We use your data solely for: • Authenticating your account (email + password) • Verifying your license to access Pro/Team features • Sending payment receipts and GST invoices (via Razorpay) • Responding to support requests you initiate We do not use your data for advertising, profiling, or any purpose beyond operating the service you signed up for.

4. Data Sharing — Who We Share With

We share your personal data with the following third parties only: a) Supabase (supabase.com) Role: Data Processor Purpose: Database hosting and authentication infrastructure Data shared: Email, hashed password, license data Location: Hosted on AWS (region: ap-south-1, Mumbai) b) Razorpay (razorpay.com) Role: Data Processor (Payment Gateway) Purpose: Processing payments, generating GST invoices Data shared: Email, name (if provided), payment amount Note: Card/UPI/banking details are collected and stored by Razorpay directly — we never see or store this information We do not sell your data. We do not share your data with advertisers. We do not share your data with any other third party.

5. How Long We Keep Your Data

• Account data: Until you delete your account • License/billing records: 7 years (required by Indian tax law / GST compliance) • Support communications: 1 year after resolution When you delete your account, we permanently delete your email and account data. Billing records are retained only as required by law.

6. Your Rights Under the DPDP Act 2023

As a Data Principal under the DPDP Act, you have the right to: a) Access — Know what personal data we hold about you b) Correction — Correct inaccurate or incomplete data c) Erasure — Request deletion of your personal data ("right to be forgotten") d) Grievance Redressal — Raise a complaint with our Grievance Officer e) Withdraw Consent — Withdraw consent at any time (this will require account deletion as consent is necessary to provide the service) f) Nominate — Nominate another individual to exercise rights on your behalf in the event of death or incapacity To exercise any of these rights, contact our Grievance Officer (see Section 9) or use the account management tools in your dashboard.

7. Data Security

We implement the following security measures: • All data transmitted over HTTPS/TLS encryption • Passwords stored using bcrypt hashing (never in plain text) • Database access restricted by Row Level Security (Supabase RLS) • Payment processing handled by PCI-DSS compliant Razorpay • No document content ever stored — eliminates the largest attack surface

8. Children's Data

LockedPDFs is a professional tool intended for users aged 18 and above. We do not knowingly collect data from minors. If you believe a minor has created an account, please contact us immediately for deletion.

9. Grievance Officer

In accordance with the DPDP Act 2023, we have appointed a Grievance Officer: Name: Rushabh Jamdade Email: privacy@lockedpdfs.com Response time: We will acknowledge your grievance within 48 hours and resolve it within 30 days.

10. Changes to This Policy

We will notify you of material changes to this policy via email at least 7 days before they take effect. Continued use of the service after that date constitutes acceptance of the updated policy.

11. Contact

For any privacy-related queries: Email: privacy@lockedpdfs.com