KoruPDF Privacy Policy
Last updated: August 26, 2026
Our Core Promise
Your PDFs never leave your browser. All PDF rendering, word detection, and vocabulary management happen locally on your device. We never upload, transmit, or store your PDF files.
Data We Collect
Anonymous Usage Statistics
We collect anonymous, aggregated usage statistics to improve the product. This includes event counts only — no personal data is collected. Examples of tracked events:
- Onboarding completion
- AI quota exhaustion
- AI analysis usage
- Invite link generation
- Challenge completion
- Word saves
- Feedback submissions
- Annotation toggle events
- License activation
- Checkout initiation
- Sync completion
We do not collect:
- Personal identifiers (name, email, IP address)
- PDF file contents or file names
- Individual word lookups or vocabulary lists
- Browsing history
- Device fingerprints
Feedback Submissions
When you choose to send feedback, you may optionally provide:
- Feedback type (Bug / Feature request / Other)
- Message text
- Email address (optional)
This data is stored on our server (Cloudflare D1) to review and improve the product. We may follow up if you provide an email, but email replies are not guaranteed. Feedback data is retained on our server; to request deletion, email hello@byzanx.com with the email address you used (if any).
Uninstall Feedback
When you uninstall KoruPDF, a feedback page may open in your browser. You can optionally:
- Select one or more reasons for uninstalling
- Leave a comment (optional)
Additionally, anonymous metadata is passed via URL parameters to help us understand usage context:
- Extension version
- Days since install
- Vocabulary count (number of saved words)
- Anonymous device ID (the same identifier used by the invite system — not linked to personal data)
This data is stored on our server (Cloudflare D1) to review and improve the product. No personal data is collected through the uninstall feedback.
Data We Don’t Collect
- PDF files: Never uploaded, never transmitted. All processing is local.
- Vocabulary data (free users): Stored only in your browser’s local storage (IndexedDB + Chrome Storage). Never leaves your device unless you are a Pro subscriber who has enabled multi-device sync.
- Reading history: Stored only in your browser’s local storage.
- Payment card information: Never collected by KoruPDF — processed exclusively by Waffo Pancake.
Third-Party Services
Cloudflare Workers (AI Context Analysis)
When you use the “Why this word here?” AI feature, the selected word and up to three sentences of context (the containing sentence plus the immediately adjacent sentences) are sent to our Cloudflare Workers backend, which forwards the request to an LLM API. The full PDF is never sent.
- AI analysis is limited to 5 requests per day for free users; Pro subscribers have unlimited access
- Each AI request includes an anonymous device identifier so our backend can enforce the daily free-tier limit server-side; we store only a per-day usage count (device identifier + date + count) in Cloudflare D1 — never the word, sentence, or AI response
- Request contents are not stored or logged beyond transient processing
- API keys are never exposed to the client
Cloudflare Workers (Invite System)
Invite tokens are anonymous, device-level identifiers. No personal data is associated with tokens.
Waffo Pancake (Payment & Subscription Processing)
KoruPDF offers an optional Pro subscription (billed monthly or yearly). Payments are processed by Waffo Pancake, our Merchant of Record. Waffo is the legal seller of record and handles global tax compliance (VAT/GST/sales tax).
When you purchase a Pro subscription:
- Your email address and payment details are collected and processed by Waffo directly on Waffo’s checkout page — KoruPDF never sees or stores your payment card information
- Our backend issues a license key automatically when your subscription activates — in most cases Pro turns on automatically on the purchasing device right after checkout; pasting the key in Settings is only a fallback
- Waffo sends subscription lifecycle events (activated/renewed/canceled/expired/refunded) to our backend via signed webhooks so we can grant or revoke Pro access
What Waffo stores (managed by Waffo, not KoruPDF): your email, payment method, billing address, subscription status, and invoice history. You can manage these in Waffo’s customer portal (Magic-Link login with your purchase email; link available in Settings). See Waffo’s privacy policy for details.
What KoruPDF stores: the license key, its status (active/canceled/expired) and expiration date, the email address you used at checkout (delivered with Waffo’s order events, used for subscription support and refunds), and anonymous device identifiers (to enforce the 3-device limit per license). This is stored on Cloudflare D1.
License Verification
When the extension starts or periodically (every 24 hours), it sends your license key and an anonymous device ID to our backend (korupdf-api.byzanx.com/api/license/verify) to confirm your Pro status. Right after a checkout, the extension also briefly polls the same backend with the anonymous device ID only to activate Pro automatically on the purchasing device. This verification is required for Pro features to work. The license key is handled only inside the extension’s Service Worker and is never exposed to web pages or the PDF content you read.
If the extension cannot reach the verification server, it uses a locally cached status for a grace period so Pro features keep working offline. If the cache expires and no connection is available, the extension reverts to Free mode (core reading features remain fully available — they are permanently free).
Multi-Device Vocabulary Sync (Pro only)
Pro subscribers can sync their saved vocabulary across devices. If you enable this, your vocabulary data (saved words, mastery levels, example sentences from PDFs you’ve read) is uploaded to our backend (Cloudflare D1) and downloaded on your other devices.
- Sync is opt-in and Pro-only — free users’ vocabulary never leaves the browser
- Only vocabulary data is synced, never PDF files
- Synced data is keyed to your license key and not linked to other personal data
- You can disable sync in Settings; synced data can be deleted by requesting deletion at hello@byzanx.com
CDN Dictionary
Uncommon words (beyond the built-in 11,903 high-frequency words) are fetched from our CDN on demand and cached locally. Dictionary lookups do not include any user-identifying information.
Dictionary Data Source
Dictionary data is derived from Kaikki/Wiktextract (licensed under CC BY-SA). Word frequency data from Hermit Dave FrequencyWords (public domain).
Data Storage
All user data is stored locally in your browser:
| Storage | Data | Purpose |
|---|---|---|
| IndexedDB (Dexie.js) | Vocabulary, reading history, word encounters, TTS cache, dictionary cache | Core functionality |
| Chrome Storage | Preferences, reading progress, AI quota counts, onboarding state, streak data, license cache | Settings & limits |
Server-side storage (Cloudflare D1) is limited to:
- Anonymous event counts (analytics)
- Optional feedback submissions
- License keys + status + device IDs + checkout email (for Pro subscription verification, see Waffo Pancake section)
- Synced vocabulary (only for Pro subscribers who enable multi-device sync)
Your Rights
Export Your Data
You can export your vocabulary at any time in CSV or Anki format from the Vocabulary page.
Delete Your Data
You can delete all your local data at any time:
- Click the ⚙️ Settings menu in the popup
- Click “Delete all my data”
- Confirm the deletion
This permanently removes all vocabulary, reading history, preferences, and cached data from your browser. This action cannot be undone.
Note: This removes local data only. Server-side data (feedback submissions, license records, synced vocabulary if you are a Pro subscriber) is retained separately. To request deletion of your server-side data, email hello@byzanx.com with the email address or license key you used. To cancel a Pro subscription, use the Waffo customer portal (link available in Settings).
Children’s Privacy
KoruPDF is not directed at children under 13. We do not knowingly collect personal information from children.
Changes to This Policy
We may update this privacy policy from time to time. Changes will be reflected in the “Last updated” date above. Continued use of KoruPDF after changes constitutes acceptance of the updated policy.
Contact
If you have questions about this privacy policy, please:
- Send feedback through the KoruPDF popup settings menu (⚙️ → Send Feedback)
- Email hello@byzanx.com
For users in the EU: under GDPR Article 27, our representative for matters relating to GDPR can be reached at the same address.
Chrome Web Store Privacy Practices
- We do not collect personal data except: optional email in feedback, and email + payment details processed by Waffo Pancake when you purchase a Pro subscription (Waffo Pancake is the Merchant of Record; KoruPDF never sees payment card data)
- We do not sell user data
- We do not use data for purposes unrelated to the item’s core functionality
- Data transferred to third parties: (1) anonymous LLM API calls for the AI analysis feature; (2) license key + device ID to our backend for Pro verification; (3) vocabulary data to our backend only for Pro subscribers who enable multi-device sync; (4) payment data to Waffo Pancake for Pro subscription processing
- We do not determine creditworthiness or lend
Summary
| Question | Answer |
|---|---|
| Are my PDFs uploaded? | No — never |
| Is my vocabulary sent to servers? | Free users: No — stored locally only. Pro subscribers: only if they enable multi-device sync |
| Is any personal data collected? | Only optional email in feedback; email + payment details via Waffo Pancake for Pro subscriptions |
| Is my payment card data collected? | No — Waffo Pancake processes payments directly, KoruPDF never sees it |
| Can I delete my data? | Yes — local data via Settings; server-side data (license, synced vocab, feedback) via hello@byzanx.com |
| Can I export my data? | Yes — vocabulary in CSV and Anki formats |
| Can I cancel my Pro subscription? | Yes — via Waffo customer portal (link in Settings) |