Leafwork

Legal

Privacy Policy

Last updated: June 10, 2026

This notice is written for India-first compliance and is guided by the Digital Personal Data Protection Act, 2023. In that law, you are the Data Principal for your personal data and Leafwork acts as a Data Fiduciary for the limited personal data we decide how to process.

Short version

  • Core PDF tools process file bytes in your browser. We do not upload or store those PDF files.
  • The sandbox is session-only. Files stay in browser memory until the workspace is cleared or the tab session ends.
  • Feedback, authentication, analytics, and future AI features may process limited non-file personal data for specific purposes.
  • We do not sell personal data, serve ads, or use your uploaded PDFs to train models.

Scope under Indian privacy law

India's DPDP Act applies to digital personal data processed in India and can also apply outside India when processing relates to offering goods or services to people in India. Most PDF content handled by Leafwork's core tools is not collected by Leafwork at all because it remains in your browser.

Information we process

AreaPersonal data or file dataSpecified purposeWhere it goes
Core PDF toolsPDFs, images, signatures, redaction boxes, page selections, and export settings.Generate the output you request.Processed locally in your browser. File bytes are not uploaded to Leafwork.
SandboxWorkspace files, marked pages, generated previews, and temporary operations.Let you inspect and combine document actions before final export.Kept in the current browser session.
FeedbackMessage, category, optional email, rating, page path, user agent, and signed-in user id when available.Read, triage, respond to, and improve the product from feedback.Stored in Supabase.
AuthenticationAccount identifiers, session data, and login provider details.Create and secure your account session for account-gated workflows.Handled by Supabase Auth.
Analytics and performancePage usage and performance signals from Vercel Analytics and Speed Insights, only after you allow analytics.Understand reliability, traffic, and product performance.Handled by Vercel when enabled. PDF content is not collected through analytics.
AI toolsAI features are currently marked coming soon. When enabled, they may send extracted text to an AI provider.Generate the AI output you explicitly request.PDF file bytes are not sent for AI flows unless a future feature says so clearly before use.

Lawful basis and consent

We process personal data only for a lawful purpose. Where consent is the basis, it should be specific, informed, unambiguous, and limited to the data needed for the stated purpose. You can withdraw consent for optional processing by stopping that workflow, signing out, or contacting us for account or feedback data requests.

Your rights as a Data Principal

  • Request information about personal data processed by Leafwork.
  • Request correction, completion, updating, or erasure of account or feedback data.
  • Withdraw consent for optional processing where consent is the basis.
  • Use grievance redressal by contacting us through the feedback widget or GitHub until a dedicated grievance contact is published.
  • Escalate unresolved privacy complaints to the Data Protection Board of India when the applicable provisions and process are available.

Submit a privacy or grievance request

Use the feedback form for privacy requests and grievance redressal. Choose the matching request type and include enough detail to identify the account or feedback record. Do not paste private PDF contents.

Children

Leafwork is not directed at children. Under the DPDP Act, a child means an individual under 18 years of age. Do not create an account or submit feedback on behalf of a child unless you are a parent or lawful guardian and the processing is appropriate for the document workflow.

Retention

Local PDF files are not retained by Leafwork because they are not uploaded for core workflows. Feedback and account records are retained only as long as needed to operate the service, respond to requests, prevent abuse, secure the product, or meet legal obligations.

Security and processors

We use service providers such as Supabase and Vercel as processors for specific hosting, authentication, database, analytics, and performance functions. Analytics and Speed Insights stay off unless you allow them from Privacy Choices. We design Leafwork around data minimisation: core document file bytes stay local, server secrets stay server-side, and support data is limited to what is needed for the stated purpose.

Contact and grievance requests

Use the feedback widget for privacy and grievance requests, open an issue on GitHub for public product issues, or visit the Security page for vulnerability reporting. Please do not send private PDFs through feedback.