PDF Parcel · Privacy Policy
No cookies, no analytics, no account. What is left is written here.
This policy is short because the product does little that concerns your data. Every sentence in it is meant to be one you could check. It covers this website and the PDF Parcel app for macOS, and describes them separately, because what is true of one is not automatically true of the other.
1 · Who is responsible
Controller for the processing described on this page, within the meaning of Art. 4(7) GDPR:
Questions about this policy, and any request under the rights in section 6, go to that address. No data protection officer has been appointed.
2 · This website
These pages are static files. They are the same for every visitor and they run nothing that reports back. That is not a promise about intent; it is a description of what the files contain, and you can read them in your browser's view-source.
-
No cookies, and no browser storage
This site sets no cookies. It writes nothing into your browser — no localStorage, no sessionStorage, no IndexedDB. There is no cookie banner because there is nothing to ask you to consent to.
-
No analytics
No analytics service, no tag manager, no tracking pixel, no session recording and no A/B testing tool runs on these pages. What the server that delivers them records is section 3, and that is the whole of it.
-
No forms
Nothing on this site accepts input. There is no contact form, no newsletter box, no search field and no comment thread — so there is nothing here that could submit anything about you.
-
No third-party requests
Everything a page needs — the typefaces, the icons, the screenshots, the stylesheet — is served from the same address as the page itself. No font service, no social embed, no video player, no map. Opening a page contacts nobody but the server you asked.
A few links on these pages point outside the site: to Apple, and to the Hamburg supervisory authority. A link is not a request. Nothing is contacted until you follow one, and from that moment the other site's own policy applies rather than this one.
Because none of this happens, there is no purpose, no legal basis, no recipient and no retention period to state for it. A policy that listed them anyway would be describing a different website.
3 · The server that delivers this site
A policy that stopped at section 2 would be incomplete. These files are served by ALL-INKL.COM, and every web server writes a line in a log for each request it answers. That happens before anything on this page can have an opinion about it, and it is the only place on the website where personal data is processed at all.
-
Who does it
ALL-INKL.COM – Neue Medien Münnich, owner René Münnich, Hauptstraße 68, 02742 Friedersdorf, Germany. It processes these log data on the controller's behalf, as a processor within the meaning of Art. 28 GDPR, and that processing rests on an agreement under that Article. The identity is taken from that company's own imprint rather than from memory — it is a sole proprietorship, so there is no legal form to add to the name.
-
What a log line holds
The IP address the request came from, the date and time, the address requested, the status the server returned, the number of bytes it sent, and the user-agent string your browser supplies. Where your browser sends a referrer, that is logged too.
-
Why
To deliver the site, and to be able to investigate a fault or an attack on it. Nothing in a log is combined with any other source, used to build a profile of a visitor, or passed to anyone else.
-
On what legal basis
Art. 6(1)(f) GDPR. The legitimate interest is operating a website that works and can be defended. You may object to this processing under Art. 21 GDPR; see section 6.
-
For how long
Ninety days. The access log for this account is kept for 90 days and then deleted. That is the retention set for this site; what ALL-INKL.COM does by default on other accounts is its own to describe, and is not described here.
-
Where
In Germany. ALL-INKL.COM serves these files from German data centres, so delivering this site involves no transfer to a country outside the EU or the EEA — and section 2 leaves no other recipient for a transfer to reach.
4 · The app on your Mac
PDF Parcel runs on your Mac. It has no server of mine to talk to, no account, and no component that reports what you do with it. So nothing in this section is processing by the controller named above: your documents do not reach me, and there is nothing about them for me to keep, disclose or erase.
It is written down anyway, because a product whose argument is your files stay here owes you a precise account of what here means — including the two places where the app keeps something on your own Mac after you quit.
-
What it reads
The files you choose, through macOS's own security scope: the app can reach the documents you hand it and nothing else. A PDF is read where it lies and is never copied. A source file is never modified.
-
What it writes
The merged PDF, into the folder you pick. Outside its own folder it writes nothing else.
-
A converted copy, for a file that was not already a PDF
An image, a plain-text file, an RTF file or an HTML file is turned into a PDF first, and that converted PDF is kept in the app's own folder on this Mac after you quit — until a later launch finds your workspace no longer using it and deletes it. It is a full rendering of the file it came from. It stays on your Mac, and its name is a fingerprint of the original's contents, so a listing of that folder shows that a file was opened, though not where it came from.
-
An HTML file is laid out with its network access blocked
A web page can refer to pictures, fonts and scripts held elsewhere. When PDF Parcel turns an HTML file into pages, those requests are blocked rather than made — so adding a saved web page to a merge does not tell its author that you did.
-
A list, so that a crash does not cost you your work
The app keeps a list of the files you added: their names, the arrangement of the pages, and a bookmark that lets it reopen them where they are. The list holds none of their contents, and no password.
-
A password stays in memory
A password you type to open a protected PDF is held in memory while the app runs and is never written to a file. It is discarded when you remove that document, and when the app quits.
-
Settings, and one date
Interface language, appearance and the default export size, plus flags recording that you have exported before. If you subscribe, one entry more: the date your subscription is paid through, so you are not asked to restore the purchase at every launch. Never your Apple Account, and nothing about your payment.
-
When it uses the network
One service, on three occasions, each of them something you pressed: opening the Pro window, which asks the App Store what the subscription costs where you are; subscribing; and restoring a purchase. Nothing at launch, nothing on a timer, and nothing at all if you never open that window. Your documents are not part of any of it.
-
What the app cannot control
Once the merged PDF exists it is an ordinary file. If you share it, open it in another program, or save it into a folder that another service synchronises, it travels by that route — your action, and that service's behaviour, which this policy does not reach. macOS's own crash and analytics reporting is likewise Apple's, and yours to configure in System Settings; PDF Parcel has no crash reporting of its own.
5 · Buying the subscription
PDF Parcel is sold in the Mac App Store, and Apple is the seller. The purchase is a contract between you and Apple: Apple takes the payment, holds the subscription, renews and cancels it, and handles refunds. I do not see your name, your address, your Apple Account or your payment details, and there is no PDF Parcel account for any of that to attach to.
What Apple receives, and what Apple does with it, is governed by Apple's own privacy policy rather than by this one. It is at apple.com/legal/privacy, and restating it here would only risk describing it wrongly.
What reaches me as the developer is the sales reporting Apple makes available in App Store Connect: counts by day and by territory. It does not name a buyer.
Apple Inc. is based in the United States, so a purchase involves a transfer there. That transfer is Apple's, on the basis of the agreement between you and Apple.
6 · Your rights
These rights are yours against the controller in section 1, for the personal data that controller processes. Here, that is the server logs in section 3 and nothing else.
-
Access · Art. 15
Confirmation of whether data about you is processed, and a copy of it.
-
Rectification · Art. 16
Correction of data about you that is inaccurate or incomplete.
-
Erasure · Art. 17
Deletion, where one of the grounds the Article lists applies.
-
Restriction · Art. 18
Processing held still rather than continued, in the cases listed there.
-
Portability · Art. 20
What you provided, in a structured, commonly used, machine-readable form.
-
Objection · Art. 21
An objection, on grounds relating to your situation, to the log processing that rests on Art. 6(1)(f).
No consent is asked for anywhere on this site or in the app, so there is none to withdraw.
How to use them. Write to the address in section 1. An access request is awkward here for an honest reason: a log line is not filed under a name, so there is nothing to look you up by. If you make one, give the approximate time and the page you visited, and I will ask the host what its logs hold for that request and answer with what comes back.
Complaining. You may complain to a supervisory authority under Art. 77 GDPR. The one competent for the controller's seat is Der Hamburgische Beauftragte für Datenschutz und Informationsfreiheit in Hamburg, at datenschutz-hamburg.de. You may complain instead to the authority where you live or work.
Nothing is required of you. There is no form, no account and nothing you must provide to use this site or the app. The IP address in a server log is not something you supply; it is how a page reaches you.
No automated decisions. There is no automated decision-making in the sense of Art. 22 GDPR, and no profiling.
7 · Version, and language
This version is dated 13 September 2026. The app has not been released yet; if what it does changes, this page changes with it and that date moves. There is no mailing list to announce it on, so the date is how you tell.
This policy is published in English and in German. The German version is the binding one — the controller is in Germany and the supervisory authority reads German, so a difference between the two is settled in favour of the German text. It is at Datenschutzerklärung.