Privacy Policy

Last updated: 11.08.2026

1. Introduction

Welcome to BookletPro ("we," "our," or "us"). Your privacy matters to us. This Privacy Policy explains what information BookletPro processes and how it is protected when you use:

Sections 3, 4, 5 and 7 apply to the Apps, sections 8 to 11 to the Web App; the remaining sections, section 6 among them, apply to both. Together we call them the "Services".

The controller responsible for this processing under the GDPR is:

Fabian Thanner, Adlhaming 4, 4655 Vorchdorf, Austria · [email protected] (see Imprint)

2. Your documents stay with you

BookletPro turns your PDFs into print-ready booklets entirely on your device. In the Apps the processing happens locally on the device; in the Web App it happens inside your browser tab. In both cases the PDFs you import, the booklets you generate, your chosen page ranges, binding margins and page numbers are never uploaded to us or any third party. Our servers never receive your documents, their file names or their contents.

3. Analytics (Apps)

We do not collect personally identifiable information in the Apps. With your consent, we use Firebase Analytics (Google LLC) to collect anonymous usage data that helps us improve the app:

The event schema is closed: an event can only carry values from a fixed set. It therefore contains no file names or paths, no free text, no email address and no account id, and page and sheet counts are only ever reported as ranges rather than exact numbers. The content of your PDFs is never included. This data is not linked to your identity.

4. Analytics Consent (Apps)

When you first open BookletPro, you are asked whether to enable anonymous analytics. Collection is switched off when the app is installed and is only switched on once you agree. The legal basis is your consent, Art. 6(1)(a) GDPR.

You can change this choice at any time in the app under About → Enable Analytics. Switching it off stops collection and also resets the app instance identifier Firebase uses, so your device is not recognised again if analytics are ever switched back on. Withdrawing your consent does not affect the lawfulness of the processing carried out on the basis of it before the withdrawal (Art. 7(3) GDPR). The Web App contains no analytics at all.

5. Crash reporting (Apps)

The Apps include Firebase Crashlytics (Google LLC). If the app crashes, a crash report is sent to Google on our behalf so that we can find and fix the fault. A report contains technical information about the crash — where in the program it happened, the app version, the operating system version and the device model — together with an installation identifier that Crashlytics generates. It contains no document content, no file names and no email address; the app passes Crashlytics no data of its own.

Crash reporting operates independently of the analytics setting described in section 4. The legal basis is our legitimate interest, Art. 6(1)(f) GDPR, in identifying and repairing faults that make the app unusable. You can object to this processing at any time under Art. 21(1) GDPR by writing to [email protected].

6. Advertising

BookletPro shows no advertising. Neither the Apps nor the Web App display ads, in the free version or in PRO.

Versions of the Apps before 3.0 showed occasional non-personalized full-screen ads through Google AdMob. The AdMob SDK was removed in version 3.0, together with the consent flow that served it: no ad is requested, no advertising identifier is read, and no data is sent to an ad network. The Web App has never shown ads.

7. In-App Purchases (Apps)

BookletPro PRO is offered as an auto-renewing yearly subscription and as a one-time lifetime purchase through Apple’s App Store. Payments and entitlements are handled by Apple, which is the seller towards you and decides on that processing itself. The Apps send nothing to a server of ours: your entitlement is read on the device from StoreKit and verified there. We do not collect or store any payment information, and we learn nothing about you from a purchase in the Apps. Subscriptions are managed in your Apple Account settings.

8. Your BookletPro account (Web App)

Creating booklets in the Web App requires a free account, so that we can tell free and PRO users apart. Sign-in is passwordless: you enter your email address and we send you a one-time sign-in link. We never ask for or store a password.

For this we store on our servers:

We do not store your documents, file names, booklet settings, a usage profile, or a Stripe customer id. The legal basis for this processing is the performance of our contract with you (Art. 6(1)(b) GDPR); without an account we cannot tell free and PRO users apart, so providing the email address is necessary to use the Web App.

9. Cookies and local storage (Web App)

The Web App sets exactly one cookie, and only after you sign in: bp_session on the domain .bookletpro.app. It contains a random session token, is HttpOnly, Secure and SameSite=Lax, and expires after 30 days. Our server stores only a hash of that token. This cookie is strictly necessary to keep you signed in — we use no tracking, advertising or analytics cookies.

Your browser’s local storage holds three entries, none of which ever leaves your browser:

All of these, and the session cookie, are needed to provide functions you have expressly asked for, and none of them is used to recognise you across sites or to build a profile. Under §165(3) of the Austrian Telecommunications Act 2021 (TKG 2021) they therefore require no consent, which is why the Web App shows no cookie banner. You can end a session at any time by signing out, which deletes the cookie and the server-side session; the local storage entries can be cleared in your browser.

When you start a checkout or update your payment method, Stripe may set its own cookies for fraud prevention; see the Stripe Privacy Policy.

10. Payments in the Web App (Stripe)

PRO purchases in the Web App are processed by Stripe using Stripe Managed Payments, where Stripe acts as merchant of record: Stripe is the seller towards you and handles payment processing, invoicing and taxes.

We pass Stripe your email address and your internal account id so the purchase can be assigned to your account; Stripe reports the payment status back to us. We never receive or store your card details or billing address. Invoices and receipts shown in your account are fetched live from Stripe. Because Stripe is the seller, it decides on the payment data it processes in its own right and is not merely acting on our instructions. The legal basis for the data we pass on is the performance of your contract (Art. 6(1)(b) GDPR). See the Stripe Privacy Policy.

11. Server logs and abuse protection (Web App)

Requests to our API pass through Cloudflare, which acts as a proxy and protects against attacks. To prevent abuse (for example mass sign-in emails) our API counts requests per IP address in memory only, for a short time window; these IP addresses are not written to our database and not used to profile you. A counter is discarded once its window has run out — at most 15 minutes — and the whole store is lost whenever the service restarts.

Technical error messages are logged on our servers for troubleshooting. They never contain document content, and never an email address: where a log line needs to refer to one, it carries a short non-reversible hash instead, so that two lines about the same incident can be tied together without the address being written down. Error logs are kept only for as long as they are needed to investigate a fault. The legal basis is our legitimate interest in operating the service securely (Art. 6(1)(f) GDPR).

12. Third-Party Services

We use Firebase Analytics (Google LLC) to understand anonymous app usage in the Apps (section 3) and Firebase Crashlytics (Google LLC) for crash reports (section 5). For more details, see the Firebase Privacy Policy.

In-app purchases are processed by Apple, which is the seller. See the Apple Privacy Policy for details.

For the Web App we additionally use: Stripe (payments, see section 10; Stripe contracts with European businesses through its Irish company and involves its United States group companies as onward processors), Cloudflare (delivery and protection, see the Cloudflare Privacy Policy) and Apple iCloud Mail (Apple Inc.), which delivers your sign-in and email-confirmation messages; see the Apple Privacy Policy.

Beyond these, and beyond the people who maintain the servers, no one receives your data. We do not sell it, share it with advertisers or pass it to data brokers. We may disclose data where we are legally obliged to do so.

The servers that run the Web App and its API are our own hardware in Austria: no hosting company holds that data, and there is no processor between you and us for it.

This website — the pages you are reading — is hosted by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany, in their Frankfurt data centre, as our processor under a data processing agreement. Both locations are within the European Union.

13. Transfers outside the EU/EEA

Our own servers are in the European Union, and so is the company that hosts this website. Some of the other recipients named in section 12 are established in the United States or may access data from there: Google LLC (Firebase Analytics and Crashlytics), Apple Inc. (App Store purchases, iCloud Mail delivery), Stripe (payments, through its United States group companies) and Cloudflare, Inc. (delivery and protection). Where those services process personal data, it may therefore be transferred to a country outside the EU/EEA.

For such transfers we rely on the safeguards required by Chapter V of the GDPR:

Despite these safeguards, we cannot rule out that authorities in the recipient country have access rights under their own law that would not exist in the EU, or that the legal remedies available there are weaker. You can request further information about the safeguards for a particular transfer, and a copy of them where we are able to provide one, at [email protected].

14. Data Retention and Deletion

Web App. Sign-in links, email-change tokens and expired sessions are deleted automatically once they expire; a sweep runs every hour. Account data (email address, entitlement) is kept for as long as your account exists, so that a purchase you made stays available to you. An account that has never bought anything and has not been used for two years is deleted automatically, together with everything attached to it; a daily sweep does this. Accounts with a purchase are not swept. Records required for accounting purposes are retained by Stripe for the statutory retention periods.

Apps. Analytics data is stored in our Google Analytics property and deleted once the retention period configured there expires: two months for the individual events, fourteen months for the per-installation records, counted from the last activity. Crash reports are deleted by Google after 90 days. Both are held without a name, an email address or an account id; if you switch analytics off, the app instance identifier is reset as well (section 4).

You can delete your Web App account yourself at any time, in the account panel of the Web App. Deletion is immediate and final: the account, its sessions, its entitlements and any unclaimed purchase held under its address are removed, and access to PRO in the Web App ends with it. You can also write to [email protected] from the address the account uses.

15. Your rights

In the Apps, analytics are collected only with your consent and are anonymous, so we do not hold data there that identifies you; no advertising data is processed at all. Crash reports are covered by section 5. For the Web App we process the personal data listed in section 8.

If you are in the EU/EEA, you have the right:

To exercise these rights, contact [email protected]. We do not sell personal data and we do not use it for automated decision-making or profiling. Residents of California can opt out of analytics at any time by disabling them in the app.

16. Children’s Privacy

BookletPro is not directed to children under 13 and does not knowingly collect data from them.

17. Changes to This Policy

We may update this Privacy Policy from time to time. The "Last updated" date above reflects the latest revision.

18. Contact Us

If you have any questions, contact us at [email protected].