Privacy policy
Written to be read, not to cover ourselves. If anything here does not match what the product does, that is a mistake on our part and we want to hear about it.
In force since
The essentials, in thirty seconds
Most of our tools never see your file. They run inside your browser: the file is processed on your own machine and is never sent to any server. This is not a matter of trusting us — you can check it yourself by opening the Network tab of your browser's developer tools and confirming that no request carrying your file ever leaves.
Every page tells you which of the two modes it uses, with a visible indicator and no small print:
- 🟢 Local processing — your file never leaves your device. We do not receive it, we do not store it, we cannot see it.
- 🔵 Cloud processing — some operations (video, audio, document conversion, OCR) simply cannot be done in a browser. In those cases the file is uploaded to our servers, processed, and automatically deleted within a maximum of one hour.
We never use your files to train artificial intelligence models, and we never share or sell them to anyone. No exceptions and no escape clauses.
The rest of this document explains the detail.
1. Who is responsible for your data
| Controller | Juan Camilo Ortiz Serna |
| Address | Calle 47 Sur # 64D - 92, Medellín, Antioquia, Colombia |
| Contact email | privacidad@raudela.com |
| Site | https://raudela.com |
This policy applies to raudela.com and to all of its applications: Raudela PDF, Raudela Media and Raudela Images.
2. The two processing modes
This distinction is the most important one in the document, because it determines whether your data exists for us at all.
2.1 Local processing tools
They run entirely in your browser, through code that is downloaded to your machine and does its work there.
With these tools:
- We do not receive your file. Not its contents, not its name, not its metadata.
- There is nothing to delete, because there never was anything to store.
- They work without needing to create an account.
- They keep working even if you lose your internet connection once the page has loaded.
Our content security policy (CSP) declares connect-src 'self', with no third-party exceptions. In practical terms: even if one of our software dependencies were malicious, your browser would stop it from sending your file to any external destination. It is not just that we do not want to: the browser does not let us.
Processing also happens inside an isolated Web Worker, with no access to your session cookies.
2.2 Cloud processing tools
Some operations are technically impossible in a browser: compressing video, transcribing audio, converting office documents, optical character recognition. For those, the file is uploaded.
When that happens:
| What we receive | The file you upload and the result we generate |
| Where it is stored | Encrypted Cloudflare R2 storage |
| For how long | One hour at most. Deletion is automatic and runs even if the operation failed |
| Safety net | A lifecycle rule in the infrastructure guarantees deletion within 24 hours even if something in the application were to fail |
| Who can see it | Nobody as a matter of routine. There is no human review of files |
| Download links | Signed, single-use and expiring |
There are no backup copies of your files. Deleted means deleted.
3. What personal data we process
3.1 If you do not create an account
Practically none. You can use the local tools without identifying yourself.
We record only aggregated, anonymous usage statistics (which pages are visited, from which country, with what kind of device) through a cookie-free analytics tool that neither builds profiles nor tracks users across sites. That is why this site does not show you a cookie banner: we have none for you to consent to.
3.2 If you create an account
Signing in is done with Google or Microsoft. We request basic identity permissions only (openid, email, profile). We do not ask for —and could not obtain— access to your Drive, your mail, your contacts or your files on those services.
From that we store:
| Data | What for |
|---|---|
| Email address | Identifying you and sending you service communications |
| Display name | Showing it in the interface |
| Profile picture | Showing it in the interface |
| Provider identifier | Recognising you when you sign in again |
We never store your password, because we never see it: authentication is performed by Google or Microsoft.
3.3 Service usage data
To apply each plan's quotas we keep a record of the cloud operations you run: which tool, when, how long it took, whether it finished successfully, and how many credits it consumed.
This record does not include the name or the contents of your files. Our internal rules forbid logging file contents or personal data beyond your user identifier.
Local processing tools generate no individual record at all: only an aggregate counter, with no link to your account or to your files.
3.4 Payment data
We do not process credit card data. We do not see it, we do not receive it and we do not store it.
Subscriptions are handled through Paddle, acting as Merchant of Record: that is, Paddle is the legal seller of the subscription and is responsible for the charge and for taxes. You provide your payment details to Paddle, under their own privacy policy.
Out of that process we keep only the status of your subscription (active, cancelled, payment pending) and its renewal date.
3.5 The personal data your files may contain
A file you upload may contain personal data belonging to other people: a contract with the name and ID number of the counterparty, an invoice with a client's details, a photo someone appears in. That has a legal consequence worth understanding, because it changes who answers for what.
With respect to that data you are the controller —you decide which file to process and for what purpose— and we act solely as processor, on your behalf and on your instructions. Your instructions are the operation you request when you press the button: no other.
In that capacity, and in accordance with article 28 of the GDPR:
| Subject matter and purpose | Carrying out the operation you request on the file. Nothing else |
| Duration | That of the operation, up to a maximum of one hour |
| Type of data and categories of data subjects | Whatever you decide to include in the file. We do not know it in advance and we do not inspect it |
| Instructions | The requested operation. We do not process that data for any purpose of our own |
| Sub-processors | The providers listed in section 6, bound by the same obligations |
| On completion | It is deleted. No copy remains |
We do not analyse, index or profile the contents of your files, and we do not use them to train models. There is no human review of files.
With local tools none of this ever comes about: the file does not leave your device, so we are not processors of anything, because we process no data at all.
What this means for you: if you are going to process files containing other people's personal data as part of a professional activity, check that you have a lawful basis for doing so. That check is yours to make, because you are the one who knows where the data came from and the purpose it was collected for.
4. The legal basis for each processing activity
In accordance with article 6 of the GDPR:
| Processing | Legal basis |
|---|---|
| Account and authentication | Performance of the contract |
| Cloud file processing | Performance of the contract |
| Usage counters and quota enforcement | Performance of the contract |
| Subscription status | Performance of the contract |
| Aggregated cookie-free analytics | Legitimate interest (understanding use of the service without identifying anyone) |
| Security and abuse-prevention logs | Legitimate interest |
| Retention of billing records | Legal obligation |
In Colombia, processing is carried out with your prior, express and informed authorisation, in accordance with Law 1581 of 2012.
5. How long we keep each thing
| Data | Retention |
|---|---|
| Files processed in the cloud | 1 hour (24 h as an absolute infrastructure limit) |
| Files from local tools | Not applicable: we never receive them |
| Account data | For as long as the account exists |
| Operation records | For as long as the account exists, for history and quotas |
| Billing records | For the period required by applicable tax law |
| Aggregated analytics | Contains no personal data; kept indefinitely and anonymously |
6. Who else is involved
These are our processors. None of them uses your data for their own purposes.
| Provider | What it does | Where |
|---|---|---|
| Microsoft Azure | Application servers and database | European Union or United States |
| Cloudflare | Distribution network, protection, temporary file storage (R2) and aggregated cookie-free analytics | Global network |
| Paddle | Subscription billing as legal seller | United Kingdom / European Union |
| Resend | Sending service emails (receipts, notices, deletion confirmations) | United States |
| Google · Microsoft | Authentication, if you choose to sign in with them | Global |
We do not sell your data to anyone. We do not run advertising. We do not pass information to data brokers.
We could be compelled to hand over information if a valid court order requires it. In that case, and unless legally prohibited, we would notify you. It is worth remembering that with the local tools there would be nothing to hand over.
International transfers
Some providers are located outside Colombia and the European Economic Area. Those transfers rely on the standard contractual clauses approved by the European Commission or on adequacy decisions, depending on the provider.
7. Your rights
You can exercise them by writing to privacidad@raudela.com. We will respond within a maximum of fifteen (15) business days for enquiries and fifteen (15) business days for complaints, in accordance with Law 1581 of 2012, and within the one month period set by the GDPR.
| Right | What it means |
|---|---|
| Access | Knowing what data of yours we hold |
| Rectification | Correcting it if it is wrong |
| Erasure | Deleting it |
| Portability | Receiving it in a reusable format |
| Objection | Objecting to processing based on legitimate interest |
| Restriction | Asking us to suspend a processing activity without deleting the data |
| Withdrawing authorisation | Withdrawing your consent at any time |
Deleting your account
It is in your account settings and does not require writing to us or explaining why.
Deleting it removes your profile, your linked identities, your operation history and your usage counters. Only the billing records that tax law requires us to keep are retained, dissociated from your identity as far as possible.
If you think we got it wrong
You can complain to the supervisory authority:
- Colombia: Superintendency of Industry and Commerce (SIC)
- European Union: the data protection authority of your country of residence
We would appreciate hearing from you first, but it is not a requirement.
8. Security
- All traffic travels encrypted over HTTPS with TLS 1.2 or above.
- Files are processed in isolated containers. We never execute the contents of a file as code.
- Download links are signed, single-use and expiring.
- Access to production systems is restricted and audited.
- Software dependencies are pinned by exact version and hash, with automated vulnerability review.
No system is infallible. Should a breach affecting your personal data occur, we will notify you and report it to the competent authorities within the legal deadlines.
9. Minors
The service is not directed at children under 14, and we do not knowingly collect their data. If we detect an account belonging to someone under that age without their guardians' authorisation, we will delete it.
10. Cookies
We use technical session cookies only, needed to keep you signed in if you log in. Without them, access would not work.
We use no advertising, tracking or analytics cookies, and that is why this site does not ask you for cookie consent: there is nothing optional to consent to.
11. Changes to this policy
If we change it substantially, we will let you know by email —if you have an account— and through a visible notice on the site, at least thirty (30) days in advance.
The version history is public in the project repository.
12. Contact
privacidad@raudela.com
Write in Spanish, English or Portuguese.