Privacy Policy
This policy explains what information Ettlio handles, why, how long it is kept, and the choices you have.
Last updated:
The short version: there are no accounts and no analytics tools, and we do not sell personal information. Most tools run in your browser. The PDF Merger uploads your files to our server and they are removed automatically within about an hour. No advertising is shown at the moment. Details are below.
Introduction
This website, ettlio.com (“Ettlio”, “we”, “us” or “our”), offers free online tools for text, email, PDF and security tasks, plus a blog (together, the “Service”). The Service is free to use and does not require you to sign in or create an account.
The Service is operated by [OPERATOR NAME - to be completed]. For the purposes of the GDPR, the operator is the data controller for personal data handled through this website. We have not published a legal entity, registration number or jurisdiction on this page; where such details are needed they are marked as placeholders and will be added when available.
You can reach us about anything in this policy at privacy@ettlio.com. Your use of the Service is also covered by our Terms of Service.
Information We Collect
We aim to handle as little information as possible. It falls into four groups.
1. Information you send us
If you use the contact form, we receive the name, email address, subject and message you enter. We also record your IP address, your browser’s user-agent string and the time of sending with the message. This happens only if you choose to write to us.
2. Information handled by the tools
Text or files you put into a tool are used only to produce the result you asked for. Whether a tool sends anything to our server depends on the tool; see How We Handle Files and Tool Input.
3. Technical information from your visit
Like any website, our web server and hosting provider receive technical information whenever your browser requests a page: your IP address, the requested address, the time, your browser and device type, and the referring page. Hosting providers commonly keep this in standard access and error logs. We do not run our own analytics or tracking on top of it (see Analytics). We do not control the hosting provider’s log settings and have not set a retention period for them.
4. Cookies and browser storage
The site sets a small number of cookies and stores one setting in your browser. These are listed in Cookies and Browser Storage.
What we do not collect
- No accounts, so no usernames or passwords.
- No payments, so no card or bank details.
- No analytics or behavioural tracking tools of our own.
- We do not knowingly collect special-category data, and we do not sell personal information.
How We Use Information
- To provide the tools — running the tool you chose and returning the result.
- To reply to you — answering messages sent through the contact form.
- To keep the Service secure — the contact form uses a session token, a hidden spam-trap field and a per-session limit on messages; the PDF upload endpoint checks a session token and validates files.
- To fix problems — technical errors are written to a server error log.
- To meet legal obligations — for example, responding to a lawful request.
We do not use your information for automated decisions that have legal or similarly significant effects.
Legal Basis (GDPR)
If the GDPR or UK GDPR applies to you, we rely on the following legal bases:
| Activity | Legal basis |
|---|---|
| Running a tool on input you submit | Performance of what you asked us to do (Art. 6(1)(b)), or our legitimate interest in providing the Service (Art. 6(1)(f)) |
| Replying to a contact form message | Legitimate interests (Art. 6(1)(f)) — answering a request you started |
| Security measures and error logging | Legitimate interests (Art. 6(1)(f)) — keeping the Service working and safe |
| Strictly necessary cookies and storage | Legitimate interests; no consent is required for storage that is strictly necessary |
How We Handle Files and Tool Input
Tools that work entirely in your browser
These tools run in your browser with JavaScript. Your input is not sent to our server:
- Duplicate Line Remover
- Email Extractor & Validator
- Password Generator (passwords are generated on your device and are not transmitted)
- Word Counter, Case Converter and Base64 Encoder/Decoder — for their normal, live operation
Optional “Verify with Server” buttons
The Word Counter, Case Converter and Base64 Encoder/Decoder each have an optional server-check button. Only if you click it, the text currently in the box is sent to our server, processed to return a result, and sent back. The application does not save that text to disk or write it to its own logs. (As with any web request, your hosting provider’s standard server logs may record that a request was made, but not the text you posted.)
PDF Merger (server processing)
Merging PDFs requires uploading your files. For that tool:
- Files are sent over HTTPS to
api/process-pdf.php. - Each file is checked (extension, file type and PDF signature) and stored under a random name in a temporary folder that is not publicly readable.
- The uploaded source files are deleted when the request finishes, whether the merge succeeded or failed.
- The merged result is stored under a long, random, hard-to-guess file name so that you can download it. It is not password protected: anyone who has the exact link could download it while it exists.
- Any uploaded or generated file older than one hour is removed by an automatic cleanup. The cleanup runs whenever the PDF endpoint is used, and, if the site owner has set it up, on a schedule. On a very quiet site a merged file could therefore remain a little longer than an hour until the next cleanup runs.
- Upload folders are configured so files cannot be listed or executed as scripts.
- We do not open, read or analyse your documents beyond what is mechanically needed to merge them.
Because files are removed quickly and are not linked to an account, we cannot recover a file for you afterwards. Keep your own copy of every original.
If your documents are confidential or regulated (for example under a non-disclosure agreement, professional secrecy rules or HIPAA), check that using an online tool is allowed before uploading. Offline software is the safer choice for highly sensitive material.
Cookies and Browser Storage
A cookie is a small text file your browser stores for a website. The site currently uses only the items below.
| Item | Purpose | Duration | Consent needed? |
|---|---|---|---|
Session cookie (PHP session, default name PHPSESSID) |
Holds a security token that protects forms and the PDF upload from cross-site request forgery, and counts contact-form messages per session for spam protection. It contains no personal profile. | Until you close your browser | No — strictly necessary |
Theme setting (tbh-theme, in your browser’s local storage) |
Remembers whether you chose light or dark mode. It stays on your device and is not sent to us. | Until you clear your browser data | No — strictly limited to your own preference |
We do not use analytics cookies.
Managing cookies
- There is currently no cookie notice because the site sets no non-essential cookies. If that changes, a notice will appear and the “Cookie Settings” link in the footer will let you change your choice.
- You can block or delete cookies and site data in your browser settings. Blocking the session cookie may stop the contact form and PDF Merger from working; clearing local storage resets your theme choice.
Advertising
No advertising is currently shown on this site, and no advertising cookies are set.
The site’s code contains support for Google AdSense, but it is switched off. If advertising is enabled in future, ad scripts will load only after you accept advertising cookies in a cookie notice, and this policy will be updated at the same time to describe the ad partners and your choices.
Analytics
We do not currently use Google Analytics or any other analytics or tracking service, and we do not set analytics cookies. If that changes, we will update this policy before it takes effect and, where required, ask for your consent first.
Third-Party Services and Links
- Web hosting provider — stores the site and its files, delivers pages, and typically keeps standard server logs. It also sends the email generated by the contact form. The provider is [HOSTING PROVIDER - to be completed].
- Tailwind CSS content delivery network — page styling is loaded from
cdn.tailwindcss.com, so your browser makes a request to that service when a page loads, and it can see your IP address and browser details in the normal way.
The site may also link to external websites. Once you follow a link, this policy no longer applies, and we are not responsible for the content or privacy practices of other sites.
How We Share Information
We do not sell your personal information. We disclose information only:
- to the service providers listed above, to the extent needed to run the site and deliver email;
- where the law requires it, for example a court order or a valid request from a public authority;
- where necessary to investigate abuse or fraud, enforce our Terms, or protect users or the public; and
- if the Service is transferred to a new operator, in which case we will update this policy.
Data Retention
| Data | Retention |
|---|---|
| Files uploaded to the PDF Merger | Deleted when the request finishes |
| Merged PDF results | Removed by automatic cleanup once older than one hour (see the note in the PDF Merger section) |
| Text handled in your browser | Not sent to us; not retained by us |
| Text sent with “Verify with Server” | Not stored by the application |
| Contact form messages | Delivered to our mailbox and also appended to a private log file on the server. There is no automatic deletion at present, so messages are kept until we remove them. We will delete a message on request (see Your Rights). |
| Hosting provider server logs | Set by the hosting provider; we have not defined a period |
| Session cookie | Deleted when you close your browser |
| Theme setting | Stays on your device until you clear it |
Data Security
We use measures that fit the small amount of data we handle:
- HTTPS for the site and for file uploads.
- Validation of uploaded PDFs by extension, file type and file signature, with size and count limits.
- Upload folders that cannot be listed or executed, and random names for stored files.
- Automatic deletion of temporary and generated files.
- A CSRF token on the contact form and the PDF upload, and spam protection on the contact form.
- Standard security headers such as
X-Content-Type-Options,X-Frame-Optionsand a referrer policy. - The contact message log and the application error log are stored in a folder that is blocked from web access.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we become aware of a personal data breach that must be reported, we will notify the relevant authority and affected people as the law requires.
Your Rights
Depending on where you live, you may have rights over personal data we hold about you. Because the site has no accounts, the only personal data we are likely to hold is a contact form message and any related log entries.
If the GDPR or UK GDPR applies
You may ask us for access to your data, correction, erasure, restriction of processing, portability, and you may object to processing based on legitimate interests. Where processing is based on consent, you may withdraw it at any time. You also have the right to complain to your local data protection authority.
If you live in California or another US state with a privacy law
To the extent the law applies to us, you may ask what personal information we hold, request a copy, and ask us to correct or delete it. We do not sell personal information. We will not treat you differently for making a request.
How to make a request
Email privacy@ettlio.com or use the contact form and choose “Privacy or data request”. Tell us the email address and approximate date of the message so we can find it. We may need to verify that the request is yours. We aim to respond within one month, or within the time the law that applies to you requires.
International Data Transfers
Our hosting provider’s servers may be in a country other than yours, and files and messages you send may be processed there. By using the Service you understand that your information may be processed in another country. Where the law requires safeguards for such transfers, we will rely on those available from our providers.
Children’s Privacy
The Service is not directed at children under 13 (or under the age of digital consent in your country, if higher), and we do not knowingly collect personal information from them. If you believe a child has sent us personal information, contact privacy@ettlio.com and we will delete it.
Do Not Track and Global Privacy Control
We do not respond to the browser “Do Not Track” setting, because there is no agreed standard for it; however, we do not track you across websites. No advertising or tracking scripts are loaded, so there is nothing for such signals to switch off.
Changes to This Policy
We may update this policy when the site or the law changes. The “Last updated” date above shows the current version. If we add features that change how information is handled, such as analytics or advertising, we will update this page before they take effect.
Contact Us
- Privacy enquiries: privacy@ettlio.com
- General enquiries: support@ettlio.com
- Contact form: ettlio.com/contact-us
- Operator: [OPERATOR NAME - to be completed]
- Postal address: [POSTAL ADDRESS - to be completed]
If you are in the EEA or UK and are not satisfied with our response, you may complain to your national data protection authority.