Legal
Privacy Policy
Last updated: June 18, 2026
This Privacy Policy describes how Erantra Private Limited (“Erantra”, “we”, “us”, “our”), the company that operates ImaginePDF (the “Service”), collects, uses, and protects information. Erantra is incorporated under the laws of India and registered in the State of Karnataka. By using ImaginePDF you agree to the practices described below.
1. Scope
This policy covers the ImaginePDF website, the web application and canvas editor, the REST API, the ImaginePDF plugin for Claude Code, our public document-creation pages (where anyone can generate a document without an account), customer support, billing, and analytics. It does not cover third-party sites or services except where we process data on your behalf.
2. Our roles: controller and processor
For account, billing, usage, and analytics data, Erantra acts as the controller — the “Data Fiduciary” under India’s Digital Personal Data Protection Act, 2023 (the “DPDP Act”). For the personal data you place into your designs and datasets so that we can generate documents for you (“Document Data”), Erantra acts only as a processor (“Data Processor”), handling that data on your instructions. In that case you are the controller and are responsible for the lawful basis to use it.
3. Information we collect
Account information
When you create an account we collect your email address, password (stored as a salted hash, never in plaintext), and optionally your full name. If you sign in with Google, we receive your basic profile information from Google’s OAuth response. We also store your workspace membership, roles, and settings.
Workspace and document content
We store the designs and templates you create, the assets you upload (images, fonts), the datasets and dynamic field values you submit for generation, and the generated PDF outputs. This content is private to your workspace and is never used to train AI models.
API keys
API keys are workspace-scoped and stored as SHA-256 hashes. Only the prefix and a one-time-display key are ever shown to you; we cannot recover a lost key.
Billing information
If you purchase a paid plan, we record your plan, payment status, credit usage, and invoice history. Payment card details are handled by our third-party payment processor — we do not receive or store full card numbers.
Usage and operational data
We collect technical logs needed to operate the Service: request timestamps, IP addresses, user agents, generation job status, and error traces. These are retained for up to 90 days for debugging, abuse prevention, and capacity planning.
Public (anonymous) generation data
When someone uses our public document-creation pages without an account, we process the values they enter into the form and any file they upload in order to produce the requested document. This data is kept separately from workspace data and is retained only briefly (see Data retention).
4. How we collect information
We collect information when you create an account, create or join a workspace, invite team members, build designs, upload assets, import a dataset, run a generation job, call the API or use the Claude plugin, contact support, generate a document on our public pages, or interact with our emails. We also use cookies and similar technologies (see Cookies and analytics).
5. Public (anonymous) document generation
Our public document-creation pages let anyone fill in a template and generate a document without signing up. The values and any uploads submitted through these pages are processed only to render that document and are stored in a separate collection from workspace data. You should not enter sensitive personal data into these public pages.
6. How we use your information
- To provide, maintain, and improve the Service
- To authenticate you and authorise access to your workspaces
- To generate the PDFs you request and deliver them to you
- To process payments and calculate plan usage and credits
- To detect, investigate, and prevent abuse or security incidents
- To communicate with you about service updates, security notices, and account matters
- To comply with legal obligations and enforce our Terms
7. Document Data and your responsibility
When your designs or datasets contain personal data about other people, you are the controller (Data Fiduciary) of that data and we process it only on your instructions, as your processor. You are responsible for having a lawful basis to collect and use it and for honouring the rights of the individuals concerned. See section 5 of our Terms of Service for the corresponding obligations.
8. AI and the Claude plugin
ImaginePDF does not send Your Content to AI providers for processing on our servers, and we never use Your Content to train AI models. AI assistance is available through the ImaginePDF plugin for Claude Code, which runs on your own machine; when you use it, your content passes through Claude under your own agreement with Anthropic and that processing is governed by Anthropic’s terms, not by us.
9. Cookies and analytics
We use essential cookies to keep you signed in and to operate the Service, and analytics tools (which may include Google Analytics) to understand traffic and feature usage. You can control cookies through your browser settings; some features may not work if cookies are disabled.
10. Payments
Payments are handled by a third-party payment processor that collects the card and billing details needed to complete a transaction. We receive only limited information — such as payment status, amount, and billing metadata — and never full card numbers. The processor’s own terms and privacy policy govern its handling of your payment data.
11. Sub-processors and service providers
We do not sell your data. We share information only with the categories of sub-processor required to operate the Service:
- Cloud infrastructure (including Google Cloud): for hosting our application servers
- Object storage: for storing your design files, uploaded assets, and generated PDFs
- Database hosting: for storing account, workspace, and generation records
- Email delivery: for transactional emails (account verification, password reset, notices)
- Analytics: for understanding usage and improving the Service
These providers process data only as needed to provide their services to us and under contractual confidentiality and security obligations.
12. International data transfers
We operate from India, but some of our infrastructure providers may store or process data in other countries. Where data is transferred outside India, we rely on appropriate safeguards as permitted under the DPDP Act and applicable law. Those countries may have different data protection rules than India.
13. Data retention
Active workspace content is retained for as long as your account is active. Generated PDFs are retained for 30 days by default unless stored as a saved design. Operational logs are kept for up to 90 days. Data from our public document-creation pages is retained only briefly and then deleted. When you delete your account, we permanently delete your workspaces, designs, assets, and generations within 30 days, except where retention is required by law, tax, or accounting rules, or kept in routine backups for a limited period.
14. Deletion and export
Most actions — editing your profile, exporting designs, deleting content, revoking API keys — are available directly in the dashboard. For anything you cannot self-serve, contact us at the address below and we will respond within 30 days. Where we process Document Data as your processor, we act on your instructions and may redirect a request back to you as the controller.
15. Security
We protect your data with encryption in transit (TLS), encryption at rest for object storage, hashed credentials, role-based access, and least-privilege access for our infrastructure. No system is perfectly secure — if you suspect your account has been compromised, contact us immediately and revoke any active API keys from the Settings tab.
16. Internal access
Our personnel do not browse your workspace content as a matter of course. Limited access may occur only where needed for support, troubleshooting, security investigation, legal compliance, or operating the Service.
17. Your rights under the DPDP Act
Subject to applicable law, you have the right to access a summary of the personal data we hold about you, to request its correction or erasure, to nominate another person to exercise your rights in the event of death or incapacity, and to a grievance redressal mechanism. Account users can exercise most of these rights from the dashboard or by contacting us; we will respond within 30 days. Where we act as a processor for Document Data, please direct requests to the relevant controller.
18. Grievance redressal
If you have a complaint about how we handle your personal data, you may contact our Grievance Officer at support@imaginepdf.com. We will acknowledge and respond to grievances within the timelines required by the DPDP Act.
19. Children
ImaginePDF is intended for business use and is not directed at children. Consistent with the DPDP Act, we treat anyone under 18 as a child and do not knowingly collect their personal data. If you believe a child has provided us personal data, contact us and we will delete it.
20. Legal compliance and protection
We may disclose information where necessary to comply with applicable law, respond to lawful requests or legal process, enforce our Terms, or protect the rights, property, or safety of Erantra, our users, or the public.
21. Business transfers
If Erantra is involved in a merger, acquisition, financing, reorganisation, or sale of assets, personal data may be transferred as part of that transaction. We will continue to handle it under this Privacy Policy unless and until it is replaced by an updated policy.
22. Changes to this policy
We may update this policy from time to time. Material changes will be notified by email or via a notice in the dashboard at least 7 days before they take effect.
23. Contact
Erantra Private Limited, Karnataka, India.
Questions about this policy or your data? Email us at support@imaginepdf.com.