Docfeather

Privacy notice

Last updated: October 2026

In short

Your files — PDFs and images — never leave your device. We do not set cookies ourselves, do not require an account, and do not embed content from other providers. When you open the site, our hosting provider Cloudflare processes technically necessary connection data, and we anonymously count which steps of our tools are used. If you write to us via the contact form, we use your email address and message only to reply. Details below.

1. Controller

Andrii Tokar
Tokar Software
Am Reinhardshof 55
97877 Wertheim
Germany
Email: info@tokar-it.de

2. Your files

PDF files and images you work on with our tools (compress, merge, JPG to PDF, PDF to JPG, ID card copy) are processed entirely in your web browser, on your own device. Neither the files nor their names or contents are transmitted to us, to Cloudflare or to any other third party.

3. Delivering the website (hosting by Cloudflare)

This website is delivered by Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA ("Cloudflare"). With every request, Cloudflare processes the data your browser sends automatically: your IP address, the date and time, the requested URL, if applicable the previously visited page (referrer), your browser's user agent, and technical details such as the status code and the amount of data transferred.

Purpose and legal basis: Delivering the site and protecting it against attacks and abuse (Art. 6(1)(f) GDPR). Our legitimate interest is to provide the website reliably, quickly, and securely.

Recipients: Cloudflare processes this data as our processor under a contract pursuant to Art. 28 GDPR (Cloudflare Data Processing Addendum). Processing may also take place in the USA and in other countries where Cloudflare operates data centers.

Transfers to third countries: For the USA, the European Commission has adopted an adequacy decision (EU-U.S. Data Privacy Framework, Implementing Decision (EU) 2023/1795, Art. 45 GDPR), under which Cloudflare, Inc. is certified. In addition, the data processing agreement with Cloudflare provides for the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR).

Retention: We do not keep server log files containing IP addresses ourselves. Cloudflare retains connection data only for as long as necessary to deliver the site and defend against attacks, and deletes it afterwards. More information: cloudflare.com/privacypolicy.

If Cloudflare considers a request suspicious, it may show a security check and, once you pass it, set a strictly necessary cookie ("cf_clearance").

4. Anonymous usage statistics

To check that our tools work, the scripts on our pages send short reports to our own server (hosted by Cloudflare): which tool is used, that the page was opened, that a file was added, that the result was created or a file could not be made smaller, or that an error occurred (error type "encrypted", "copy-protected" or "other"), that you started over or cleared the list, when a page is opened, where you came from — as one word from a fixed list ("Google", "Bing", "DuckDuckGo", "Ecosia", "Yahoo", "Yandex", "ChatGPT", "Perplexity", "another site", "direct" or "this site"), never the address of the previous page or what you searched for — the kind of device ("phone", "tablet" or "computer") and its operating system (such as "iOS", "Android", "Windows", "macOS") — one word each, not the model, browser version or screen size — for a finished result, roughly how long it took ("under 1 second", "1–3", "3–10", "10–30" or "over 30 seconds"), and that you clicked a button for a planned paid feature that is not yet available, and which one ("target size", "whole folder" or "quality slider"). For the ID card copy, also whether the card was found in the photo automatically and whether you moved its corners, rotated it or blacked out parts — only that it happened, not where or what. Each report includes only the selected setting (compression level, page size, image quality or file format) and the page language. Nothing about your files — name, contents, size — is transmitted.

We store only one counter per day for each combination of these attributes. We do not store IP addresses, user agents, or any identifiers; we set no cookies and store nothing on your device. The stored counters cannot be linked to you and are not personal data; they are therefore kept without a fixed retention period.

When a report is received, Cloudflare — as with every page request — briefly processes your IP address and the other connection data listed in section 3; this data is not included in the statistics. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is to detect errors, improve the tool and decide which features to build next.

If your browser sends the Global Privacy Control signal, no reports are sent.

5. Contact form

If you write to us via the contact form, we process your email address, your message and the page language in order to reply, and, to fend off automated spam, the time between opening the page and sending the message; this is only checked, not stored. The message is not stored on our website; Cloudflare (Email Routing, as our processor, see section 3) forwards it by email to our mailbox. Our email provider is mailbox.org, operated by Heinlein Hosting GmbH, Schwedter Straße 8/9A, 10119 Berlin, Germany, also acting as a processor under Art. 28 GDPR.

To prevent abuse, Cloudflare limits the number of messages per IP address; the IP address is only processed briefly for this purpose and not stored.

Legal basis: Art. 6(1)(b) GDPR where your request relates to a contract or to steps prior to entering into one, otherwise Art. 6(1)(f) GDPR; our legitimate interest is to answer inquiries. Retention: We delete your message once the inquiry has been fully resolved, unless statutory retention obligations apply.

6. Cookies and storage on your device

Apart from the special case mentioned in section 3, this website sets no cookies and uses neither local storage nor similar techniques. Scripts, fonts and libraries are loaded exclusively from our own domain.

7. Obligation to provide data, automated decisions

You are not legally or contractually required to provide any data. Without the connection data described in section 3, however, the website cannot be displayed, and without an email address we cannot reply to a message sent via the contact form. We do not use automated decision-making, including profiling (Art. 22 GDPR).

8. Your rights

Subject to the legal requirements, you have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18) and data portability (Art. 20). Because we do not store any data about page requests that would allow us to identify you, we are generally unable to attribute individual requests to a person (Art. 11 GDPR). You can reach us at info@tokar-it.de for any request.

You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), in particular in the Member State of your habitual residence. The authority competent for us is the State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg (Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg), Heilbronner Straße 35, 70191 Stuttgart, Germany (postal address: Postfach 10 29 32, 70025 Stuttgart), email: poststelle@lfdi.bwl.de, www.baden-wuerttemberg.datenschutz.de.

9. Right to object under Art. 21 GDPR

You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you that is based on Art. 6(1)(f) GDPR (sections 3, 4 and 5). We will then no longer process this data unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights and freedoms, or the processing serves the establishment, exercise or defense of legal claims. You can object informally, for example by email to info@tokar-it.de.