Privacy at a glance
ClonyPDF (“we”, “our”, “us”) provides free online tools for working with PDFs and images, including the Passport Photo Maker. This policy explains what happens to the files you upload, what limited information we collect, and what rights you have over that information.
We built ClonyPDF so that it needs as little data from you as possible. There is no sign-up, no profile, and no marketing list. The short version is above; the detail follows.
Who this policy covers
This policy applies to clonypdf.com and every tool hosted on it, including our PDF compressor, merge, split, protect and PDF editor tools, the Passport Photo Maker, and the guidance pages that support them. You can see the full list on our tools directory.
It does not cover websites we link to. If you follow a link to a government passport authority or any other external site, that site’s own privacy policy applies.
How we handle your files
Files are transferred over an encrypted HTTPS connection, processed, made available for you to download, and then deleted. Three points matter most:
- Automatic deletion. Uploaded files and generated results are removed within one hour. Deletion is enforced by a scheduled cleanup task, and expired files are also swept whenever the tool next runs.
- Unguessable filenames. Each upload is stored under a randomly generated identifier, and the storage directories are configured to refuse direct browsing.
- No human review. We do not open, read, view or inspect the contents of your documents, and we do not use them to train any model.
Processing happens on infrastructure we operate, using software installed on our own servers. Uploads are limited to 15 MB per file.
One deliberate exception: if you choose to download a print sheet as a PDF, that document is assembled on our server rather than in your browser, because generating a print-ready PDF requires server-side rendering. It is subject to the same one-hour deletion rule as every other file.
Passport photos and facial images
The Passport Photo Maker works with photographs of your face. A facial image can identify you, and in some jurisdictions it is treated as a special category of personal data. We therefore want to be precise about what happens to it.
What happens in your browser
Face detection, alignment, cropping, background replacement and the compliance checks all run locally on your device using your browser’s own processing. For the standard editing flow, the photo does not need to be sent to us at all, and we never receive a face template, biometric measurement or any derived identifier.
What happens on our servers
A photo reaches our servers only if you use a feature that requires it — for example handing an image from one tool to another, or exporting a printable sheet. In those cases the image is stored temporarily under a random identifier and deleted within one hour, exactly like any other upload. We do not enrol faces, run recognition against any database, or match your photo to any other person or record.
If you would rather no image ever touch our servers, complete your photo in the editor and download the JPG result directly.
What we keep, and for how long
Retention periods below reflect how the service is actually configured, not a best-case description.
| Data | Retention | How it is enforced |
|---|---|---|
| Files you upload (PDF, JPG, PNG, WEBP, HEIC) | Deleted automatically within 1 hour | Scheduled cleanup task plus an on-request sweep of expired files |
| Files our tools generate for you to download | Deleted automatically within 1 hour | Same 1-hour expiry as the source upload |
| Abuse-prevention counters derived from your IP address | Rolling 1-hour window, then discarded | Rate limiter (20 requests per hour, per IP) |
| Analytics measurements (Google Analytics 4) | Governed by Google Analytics data-retention settings | Held by Google, not on our servers |
| Server access logs | Held by our hosting provider under its standard log policy | Standard web-server logging |
Information we collect
ClonyPDF does not require registration, so we hold no name, email address or password for you. We do process a small amount of technical information:
- IP address — used to enforce rate limits (currently 20 requests per hour, per address) and to block abuse. It is held only as a short-lived counter within a rolling one-hour window.
- Browser and device information — browser type and version, operating system and screen size, so tools render and behave correctly.
- Aggregate usage statistics — which pages and tools are used, collected through analytics as described below.
- Technical file attributes — file type, size and image dimensions, checked to validate the upload and warn you if a photo is too small to print well.
We do not build advertising profiles, and we do not attempt to identify individual users from this information.
Third-party services
We keep third parties to a minimum. The ones involved in delivering this site are:
- Our hosting provider — operates the servers that run ClonyPDF and maintains standard access logs.
- Google Analytics — aggregate usage measurement, as described above.
- Google Fonts — serves the typeface used across the site.
Your files are not sent to any external processing service. PDF and image operations are performed by software running on our own infrastructure. No outside vendor receives your documents or photos.
Our guidance pages link to official government sources so you can verify photo requirements at first hand. Those are informational links only — no data about you is transmitted to them unless you click through.
Legal bases for processing
If you are in the United Kingdom, European Economic Area or another region with comparable law, we rely on the following bases:
- Performance of a service you requested — processing an uploaded file so we can return the result you asked for.
- Legitimate interests — keeping the service secure and available, including rate limiting and abuse prevention.
- Consent — analytics cookies, where consent is required in your jurisdiction. You can withdraw it at any time through your browser or the opt-out link above.
Where a facial image is processed on our servers as part of a feature you have chosen to use, that processing is carried out to deliver the result you requested and the image is deleted within one hour.
Your privacy rights
Depending on where you live, you may have the right to access, correct, delete, restrict or object to the processing of your personal data, to data portability, and to withdraw consent. California residents additionally have the right to know what is collected and to opt out of any sale or sharing of personal information — we do not sell or share personal information.
In practice, most of these rights resolve themselves quickly here: we hold no account for you, and uploaded files are already deleted within an hour. If you want a file removed sooner, or you have a request about technical data such as logs, email support@clonypdf.com or use our contact page. We aim to respond within 30 days.
Because we do not ask who you are, we may need enough detail — such as the approximate time of your visit — to locate any record before we can act on a request.
How we protect your data
- Encrypted transport. All traffic is served over HTTPS, with HTTP requests redirected and strict transport security enabled.
- Upload validation. Every upload is checked against an allowed list of file types by inspecting the actual file contents, not just its extension, and images are checked for dimensions that could be used to exhaust server memory.
- Isolated, unguessable storage. Temporary files use random identifiers, are stored with restrictive permissions, and their directories refuse direct listing or execution.
- Short-lived access. Download links expire with the file, and results are served with caching disabled so they are not retained by intermediaries.
- Rate limiting. Per-address request limits reduce automated abuse of the tools.
No online service can promise absolute security, and we do not claim to. What we can say is that the shortest-lived data is the safest data, which is why our default is to delete rather than retain.
International data transfers
ClonyPDF is available worldwide, so the servers processing your request and the third-party services listed above may be located in a different country from the one you are in. Where personal data is transferred internationally, we rely on the safeguards offered by those providers, including standard contractual clauses where applicable.
Children’s privacy
ClonyPDF is intended for general use and is not directed at children under 13. We do not knowingly collect personal information from children.
We recognise that adults often use our tools to prepare passport photographs of a child — for example with our baby passport photo guide. A photograph uploaded in that situation is treated exactly like any other upload: it is processed, made available to you, and deleted within one hour. It is never retained, catalogued or used for any other purpose.
If you believe a child has provided us with personal information, contact support@clonypdf.com and we will remove it promptly.
Changes to this policy
We may update this policy to reflect changes to our tools, our infrastructure or legal requirements. When we do, we revise the “last updated” date at the top of this page. Material changes to how we handle your files will be described here rather than made silently.
This policy sits alongside our terms of service, which cover acceptable use of the tools.
Contact us
For any question about this policy, a privacy request, or a concern about how your data has been handled: