Privacy Policy
Last updated: 7 August 2026
FileHook is built around a simple stance: we want to do the editing, not own your data. Most tools run inside your browser and your document never becomes something we read. This page says what we actually collect, what runs on the page, and what we keep in your browser.
What we collect
Your file, usually not at all. Opening a PDF in the editor reads it straight into the tab. Nothing is uploaded, so there is nothing for us to hold. Three things do send the document to our server, because they can't work any other way: making a Share link, sending a document out for signature, and reading a scanned statement or receipt that has no text in it. A Share upload sits in temporary cloud storage and is deleted when the link expires, two hours after you make it. Documents sent for signature follow the rule under "Signature requests" below.
Nothing, if you only edit. Editing asks for no email, no name, no account.
Your account, if you make one. Some parts of FileHook do need an account: sending a document out for signature, the invite program, and a paid plan. If you sign up we store your email address and the records tied to it (your signature requests, your invite credits, whether your plan is free or paid). Card numbers never reach us. Our payment processor handles the payment and tells us only that it succeeded.
Support messages. If you email us or use the feedback button, we keep what you sent so we can reply.
Server logs. Our hosting and storage providers keep standard request logs (IP address, user agent, timestamp) for short periods to run the service and stop abuse. We don't sell them or build profiles from them.
Analytics, and how to turn them off
The first time you visit, a notice asks whether you agree to analytics. Until you press Allow, none of the scripts below are on the page at all. This is not a banner that sets a flag while the tracker loads anyway: with no answer, or with "No thanks", the analytics scripts are never requested and no analytics cookie is set.
If you allow them, two things load. The first is Google Analytics (gtag.js). It records page views, which tool you opened, and a few product events such as "a file was uploaded" or "a file was downloaded", along with your country, browser, and the site you came from. It sets cookies named _ga and _ga_<id> in your browser to tell a repeat visit from a new one. That data goes to Google, which handles it under its own privacy terms and may process it outside your country. The second is a lighter usage and page-speed counter from our hosting provider, which counts page views and times how fast pages load. It sets no cookies.
What analytics never receive: your document, its text, its filename, or anything you typed into it. The events carry the name of the tool and nothing about the file. We leave filenames out on purpose, because a filename often carries a person's name or an account number.
Error reports run either way. When something in the app crashes, we send the error message, the stack trace, the page address, and browser details to an error monitoring service, plus a timing sample from about one in ten page loads. This is how we find out the editor broke, so it is not part of the analytics choice. It sets no cookies, records nothing about your document, and is not used to follow you around the web.
Change your answer
Your choice is stored in this browser. You can switch it here at any time, and switching off also clears the analytics cookies from this browser.
Checking your setting.
Cookies and browser storage
FileHook keeps most of its state on your device instead of on our servers. Here is the whole list.
Needed for the site to work
- Your answer to the analytics notice, so we stop asking.
- Your language choice, in a cookie named
fh_locale, set only when you pick a language. - Your sign-in session, if you have an account, so you stay signed in between pages.
- A daily count of finished files, because the free plan allows 10 a day across all the tools.
- Signatures you chose to save for reuse. For a visitor with no account these stay on the device and go nowhere else. If you sign in, they can be synced to your account so they follow you between devices.
- An invite code, if you arrived through someone's referral link, so the credit reaches the right person after you confirm your email.
- Small interface memories: whether you dismissed the install prompt, and how many Smart Fill runs you have used.
- The document you are moving between tools. When you click "continue editing" the file is held in your browser's own database for the hop, then deleted once the next tool picks it up.
Set only after you allow analytics
- Google Analytics'
_gaand_ga_<id>cookies, which last up to two years unless you clear them.
Clearing site data in your browser removes every item above. The editor keeps working, it just forgets your saved signatures and your preferences.
What we don't do
- We don't read, search, or index the contents of your PDF, and we don't train any model on it.
- We don't run advertising networks, ad pixels, or retargeting tags. There is no Meta Pixel and no ad tech on this site.
- We don't sell your data, and we don't hand it to data brokers.
- We don't put a watermark on your exports or hold your file hostage behind an email form.
Where your file lives
For most tools, on your device and nowhere else. The PDF is read into the tab and the finished file is written back out from the tab. It is never sent anywhere, so a slow connection makes no difference and an offline tab still works.
For the three cases that do upload (Share links, signature requests, and scanned pages with no text), the file sits in temporary cloud storage while the job runs. A Share upload is removed by an automated cleanup once its two hours are up. No backups, no archive, no "just in case" copy.
Editing itself is local either way. Keystrokes, font measurement, color sampling, and undo history all run in client-side JavaScript and never leave your tab.
Signature requests
Documents you send for signature work differently from the editor, because the file has to outlive your browser tab for the signer to open it. A document sent for signature is kept while the request is active and for 30 days after it completes or closes, then deleted. The two-hour rule above does not apply to these files.
Each request also keeps an audit trail: the emails and names of the people on the request, and a record of when the document was sent, opened, agreed to, and signed. For signing events we record the signer's network address and browser details, because that record is what makes the signature verifiable later. The audit trail appears on the certificate attached to the finished document and is retained with the request record.
Your rights
If you have an account, you can ask us for a copy of what we hold about you, ask us to correct it, or ask us to delete the account and its records. Email us and we will do it. Deleting the account removes your email, your saved signatures, and your invite records. Completed signature requests keep their audit trail, because that is the proof the signature was valid and the other people on the request rely on it too.
FileHook is not directed at children under 13 and does not knowingly collect their information.
Changes
If we update this policy, we'll change the "Last updated" date above. If we add a new kind of collection or a new third party, we'll ask for your analytics consent again rather than quietly reusing the old answer.
Contact
Questions, concerns, or a bug to report? Get in touch via the email listed on the homepage.
This policy is provided as-is and reflects the actual product today. If you need formal legal review for a specific compliance need, consult a lawyer.