Privacy Policy
Last updated: July 2026
1. Controller
Yunus Ak, Kreuzfeldstraße 34, 45473 Mülheim an der Ruhr, Germany
Email: easyconvertsupport@gmail.com
2. Overview of processing
PixelPDF is a PDF-to-PNG conversion API with a user account. To operate it, I process personal data during registration, when the API is used, and when payments are made for the Pro plan. External service providers are involved as processors or as independent controllers (see section 6).
3. Registration and user account
During registration I collect your email address and password (passwords are stored encrypted). In addition, an automatically generated API key, your plan (Free/Pro), remaining credits, and your monthly usage are stored. Authentication is handled by Supabase (Supabase, Inc.).
Legal basis: Art. 6(1)(b) GDPR (performance of the usage contract).
4. Use of the conversion API
Each API call checks the submitted API key against the database and updates your remaining credits or monthly usage. Uploaded PDF files are processed only temporarily for the conversion and are deleted immediately afterwards — they are not stored permanently.
Legal basis: Art. 6(1)(b) GDPR.
5. Payment processing (Pro plan)
Payments for the Pro plan are handled through the payment provider Stripe. Payment data (e.g. card details) is collected and processed exclusively by Stripe — I never receive or store full payment details myself. I only receive a customer and subscription identifier from Stripe in order to update your account status (Free/Pro).
Legal basis: Art. 6(1)(b) GDPR.
6. Service providers used
- Supabase, Inc. — user accounts, login, and database
- Stripe Payments Europe, Ltd. / Stripe, Inc. — payment processing for the Pro plan
- Render Services, Inc. — hosting of the conversion API
- Cloudflare, Inc. — hosting/delivery of this website
These providers may process data outside the EU/EEA (in particular the United States). Where this is the case, the respective providers apply appropriate safeguards (e.g. EU Standard Contractual Clauses) to ensure an adequate level of data protection.
7. Cookies and local storage
After logging in, your browser stores a session token via Supabase in local storage (localStorage) to keep you logged in. This is technically necessary for the account functionality and is not used for tracking. I do not use analytics or marketing cookies.
8. Retention period
Account and usage data is stored for as long as your account exists. After account deletion, the data is deleted within a reasonable period, unless legal retention obligations apply (e.g. commercial and tax law retention periods for invoice data).
9. Your rights
You have the right to access, rectify, erase, and restrict the processing of your data, as well as the right to data portability and the right to object to processing. To exercise these rights, simply contact the email address above. You also have the right to lodge a complaint with a data protection supervisory authority, e.g. the North Rhine-Westphalia State Commissioner for Data Protection and Freedom of Information.
10. Automated decision-making
No automated decision-making within the meaning of Art. 22 GDPR takes place. The automatic checking of credits/usage limits is a purely technical quota check without any legal or similarly significant effect within the meaning of this provision.