Privacy and cookie policy
We collect what we need to run the service and nothing else. No ads, no data sales, no tracking analytics. Documents you render are deleted automatically within 30 days.
Format is a platform for building and generating PDFs with web technology run by Format.dev Ltd, a company registered in England and Wales (registered office 111 Ryhall Road, Stamford PE9 1UJ). We are the data controller for the personal data described here.
This policy covers the Format website, documentation, dashboard, APIs, and developer tools. It also covers cookies, so there is no separate cookie notice.
What we collect
Account data
You sign in with GitHub. When you do, GitHub sends us your GitHub account ID, name, email address, and avatar. We use these to create and operate your account. We never see your GitHub password.
Documents you build and render
Any code you write in Studio or an SDK stay on your local computer while you build them. Studio contacts our servers to sign you in and to download the rendering engine. It does not report what you are building or send us any of your local code.
When you generate a PDF, the HTML, CSS and assets for that document will be sent to our servers.
We keep a record of each render, including the HTML, so you can review recent activity in your dashboard. These records expire automatically. Your organization controls the retention period, up to a maximum of 30 days. After that, they are deleted.
Treat this for what it is: your documents may contain personal data about your own users. For that data, you are the controller and we are your processor. We only process it to render and deliver your documents.
Logs and request data
Like every web service, we log requests. Logs include your IP address, user agent, and request metadata. We use them to keep the service running, debug problems, and prevent abuse.
Visits to our marketing site and docs pass through Cloudflare, which gives us edge data such as IP address, approximate location, and user agent.
Newsletter and feedback
If you join our mailing list, we store your email address to send you updates. Every email includes an unsubscribe link.
If you send feedback through the docs, we store your rating, your message, and your email address if you choose to give it.
What we don't collect
We currently run no analytics or tracking on any of our sites. If we add analytics later, we will use a privacy-focused tool that sets no cookies and does not track you across sites. We will name it here when we do.
We never sell personal data, and we never share it with advertisers.
How we use your data
We use your data to:
- Provide the service: sign you in to the developer tools, render documents, operate your account, and show your render history
- Communicate with you: transactional email such as sign-in verification and organization invitations, plus the newsletter if you opted in
- Keep the service safe: debug failures, enforce rate limits, and prevent abuse
- Meet legal obligations
Our legal bases under UK GDPR are performance of a contract, legitimate interests, consent, and legal obligation. The contract basis covers running the service you signed up for. Legitimate interests cover security, debugging, and service improvement. Consent covers the newsletter.
How long we keep it
| Data | Retention |
|---|---|
| Documents and render records | Your organization's setting, capped at 30 days, then deleted automatically |
| Account data | While your account exists, then deleted within 12 months |
| Server logs | Up to 90 days |
| Newsletter email | Until you unsubscribe |
| Feedback | Up to two years |
To delete your account and its data, email us at [email protected].
Who we share it with
We use a small number of service providers to run Format. Each one only receives the data it needs:
| Provider | Role | Data involved |
|---|---|---|
| Cloudflare | Hosts our website and docs | Visitor IPs, location, user agent |
| Unikraft Cloud | Runs our rendering infrastructure | Document content during rendering |
| Resend | Sends transactional email | Email addresses and message content |
| GitHub | Sign-in and infrastructure | GitHub account identity |
Newsletter signups and docs feedback are handled by our email and feedback tooling. Email [email protected] for the current list of providers.
Our own databases and file storage are self-hosted. We may also disclose data where the law requires it.
The Format CLI checks the npm registry for updates. That request comes from your machine, not ours, and sends npm your IP address like any package install does.
Where your data lives
Our servers are in the UK and EU. Some providers, such as GitHub and Resend, may process data in the US. Where data leaves the UK, we rely on adequacy decisions or standard contractual clauses.
Your rights
Under UK GDPR you can ask us to access, correct, delete, or export your personal data. You can also object to the processing we base on legitimate interests, which for us means security, debugging, and service improvement.
We handle these requests by hand rather than through a settings page. Some processing can't be separated from running the service, so if you object to that, the practical answer is closing your account. We'll tell you which applies to your request.
Email [email protected] and we will respond within one month.
You can also complain to the Information Commissioner's Office at ico.org.uk, though we'd appreciate the chance to sort it out first.
Cookies
We set cookies for one purpose: keeping you signed in to the dashboard. These are essential cookies, so there is no consent banner to click through.
| Cookie | Purpose | Lifetime |
|---|---|---|
| Session cookies | Keep you signed in | [SESSION LIFETIME] |
The marketing site and docs set no cookies at all. If we add privacy-focused analytics later, it will be a cookieless tool, and this section will say so.
Children
Format is a business tool. It is not for anyone under 18, and we do not knowingly collect data from children.
Changes
We update this policy when the service changes. For significant changes we will tell account holders by email. The date at the top always shows the latest version.
Contact
Questions about privacy: [email protected].