Security & Data Protection
We take security seriously. Here's a clear, plain-language summary of how aipdf.studio protects your data — no vague promises, no marketing language.
Last reviewed: April 2026
Our Security Principles
Your data is never used for AI training
The documents you create and the content you input are never used to train AI models — ours or any third party's. Your work is private.
Encryption in transit and at rest
All data transmitted to and from aipdf.studio is encrypted using TLS 1.3. Data stored on our servers is encrypted at rest.
Minimal data retention
We retain only what's necessary to provide the service. Document content is not stored longer than required for your session or account.
GDPR compliance
We comply with GDPR requirements for EU users. You can request deletion of your data at any time. See our GDPR page for full details.
Technical Specifics
Authentication
User authentication is handled via Google OAuth 2.0. We do not store passwords. Session tokens are short-lived and rotated regularly.
Payment Security
All payment processing is handled by Stripe, a PCI DSS Level 1 certified payment processor. We never store credit card numbers on our servers.
Infrastructure
aipdf.studio is hosted on Vercel's edge network with automatic DDoS protection and CDN caching. Database infrastructure uses encrypted PostgreSQL on managed cloud providers.
AI Processing
AI generation is powered by large language model APIs. Content you send to the AI is processed to generate your document and is not retained by our AI providers for training purposes.
Security Checklist
- TLS 1.3 encryption for all data in transit
- Encryption at rest for all stored data
- No storage of credit card details
- OAuth 2.0 authentication (no passwords stored)
- GDPR-compliant data handling for EU users
- Your content is never used to train AI models
- Data deletion available on request
Responsible Disclosure
If you discover a security vulnerability in aipdf.studio, please report it responsibly to hello@zeroshot.ventures. We take all reports seriously and will respond within 2 business days.