Privacy Policy
Last updated: 6 May 2026
Who we are
Carbonform is operated by Chris Ilabaca, a UK sole trader. Our contact address is hello@carbonform.dev. The website is carbonform.app.
We are the data controller for any personal data you share with us directly (such as your email address when joining the waitlist or creating an account).
What we collect and why
Free plan (in-browser demo)
When you use the free demo, your PDF is processed entirely inside your own browser using WebAssembly. The file is never uploaded to our servers. We do not see it, store it, or transmit it. No personal data from your document is collected.
Waitlist and account registration
We collect your email address when you join the waitlist or create an account. We use this to:
- Send you product updates and your account details.
- Provide support when you contact us.
We do not sell your email address or share it with third-party marketers.
Pro and Team plans (server-side processing, planned)
Paid plan features that require server-side processing (shared template library, audit log, multi-seat sync) are planned for the launch of paid tiers. When those features ship, PDFs handled server-side will be transmitted over TLS in transit, stored temporarily to process your request, and deleted within 24 hours of upload. The exact retention windows and encryption details will be confirmed in a published infrastructure note before paid plans go live. We will not use your documents to train AI models, and we will not share them with third parties.
Until paid plans launch, no Carbonform server processes your PDFs. The browser-based demo is the only product currently active, and it transmits nothing.
Usage data
We collect minimal server-side logs (IP address, browser type, pages visited) for security and debugging purposes. Logs are retained for up to 30 days and then deleted. We do not currently use any third-party analytics. When we add analytics, we will update this policy and choose a tool that does not require consent under PECR (such as Plausible Analytics, which does not set cookies or fingerprint users).
Cookies
Carbonform does not set any non-essential cookies. We do not use advertising, tracking, or analytics cookies. The only cookies that may be set are strictly necessary session cookies required for your account login. No cookie consent banner is required under PECR because we only use essential cookies.
Lawful basis for processing
We process personal data under the following lawful bases (UK GDPR Article 6):
- Contract: to provide the service you have signed up for (account, billing, file processing).
- Legitimate interests: to maintain server security logs and prevent abuse.
- Consent: for any optional marketing emails (you can unsubscribe at any time).
Data retention
- Free plan demo: no data stored (in-browser only).
- Pro and Team uploads (when paid plans launch): planned retention up to 24 hours, exact windows confirmed at launch.
- Account data (email, billing): retained while your account is active and for up to 90 days after deletion to satisfy UK accounting record-keeping obligations.
- Security logs and submission records: retained for 30 days.
- Stripe (our payments processor): retains billing records per their own policy, see stripe.com/gb/privacy.
Data residency
We aim to host paid plan data within the UK or EU at launch. We will not transfer personal data to countries outside the UK or EEA without appropriate safeguards (such as Standard Contractual Clauses) and will document the chosen host before paid plans go live.
Your rights
Under UK GDPR, you have the right to:
- Access the personal data we hold about you.
- Rectify any inaccurate data.
- Erase your data (right to be forgotten), subject to our legal obligations.
- Restrict or object to processing.
- Portability of your data in a machine-readable format.
- Withdraw consent at any time for processing based on consent.
To exercise any of these rights, email hello@carbonform.dev. We will respond within 30 days.
You also have the right to lodge a complaint with the UK supervisory authority, the Information Commissioner's Office (ICO), at ico.org.uk.
Contact
For any privacy-related questions, contact us at hello@carbonform.dev.
Changes to this policy
We may update this policy from time to time. When we do, we will update the "Last updated" date at the top of this page. Continued use of Carbonform after changes constitutes acceptance of the updated policy.