Swiss software from Cham (Zug)
AI analysis in the EUFADP & GDPR compliant
PDF Splitter

Privacy policy

This is a translation. Only the German version is legally binding.

Last updated: October 2026. This statement applies to the website pdf-splitter.ch and the web app "PDF Splitter".

1. Controller

Agenturen Mani, sole proprietorship, owner: Sepehr Mani, Hinterbergstrasse 21, 6330 Cham, Switzerland, UID CHE-222.132.361. Contact for data protection matters: info@hyperpage.ch, +41 78 267 85 60.

We comply with the Swiss Federal Act on Data Protection (FADP) and, where applicable, the EU General Data Protection Regulation (GDPR).

2. Summary

  • Your PDFs are never stored on our servers. Splitting and assembling the files takes place in your browser.
  • To detect document boundaries, the pages are transmitted in encrypted form to Google Cloud (Vertex AI) in data centres in the EU, analysed and then discarded. They are not used for training AI models.
  • We only store what is necessary for your account and your subscription: e-mail address, password hash, plan, payment references, naming rules and counters (number of pages and analyses).
  • We only set analytics and advertising cookies with your consent and only on the website, never in the tool.

3. Your documents

3.1 Processing in the browser

Selected or scanned PDFs are opened in your browser. Page preview, splitting, naming and ZIP creation take place locally on your device. Once the browser tab is closed, the files are removed from memory.

3.2 AI analysis

For the analysis, the PDF is sent in encrypted form (TLS) to our server at Cloudflare and from there transmitted to Google Cloud Vertex AI without intermediate storage. We exclusively use Google's EU endpoint ("eu"), with which data and its processing remain in the EU. Google processes the data as our processor, does not store the content (Vertex AI data caching is disabled for our project) and does not use it for training. We only receive back the detected page ranges, file name suggestions and document data. These results are neither stored nor logged.

For each analysis, only statistics without content are stored: time, number of pages and documents, AI model used, number of tokens, duration and success. These statistics are used to bill the quotas and to control costs, and are deleted after 24 months.

3.3 Scanning with your mobile phone

When scanning with the mobile phone camera, the photos are assembled into a PDF on the phone. When scanning via QR code, the pages are transferred end-to-end encrypted from the phone to your computer. The key is contained only in the QR code and is never sent to a server. The transfer runs via a relay at Cloudflare, which cannot read the content and stores nothing. A session is valid for a maximum of 15 minutes.

4. Account, subscription and communication

For your account we process: e-mail address, password (only as a cryptographic hash), selected language, role, plan and subscription status, Stripe customer and subscription references, naming rules, usage counters, and the times of registration and last login. The purpose is to provide the service and to perform the contract (Art. 6(1)(b) GDPR). The data is held in a Cloudflare database located in the EU and is retained until your account is deleted.

If you already had an account with the previous version of PDF Splitter, your account data (including password hash) was migrated from the previous system (Google Firebase) so that you can log in as before. On your first login, your password hash is converted to the new format.

Logins use a secure session cookie (HttpOnly, Secure). Sessions expire after 30 days. Password reset links are valid for 1 hour.

We send system e-mails (e.g. for resetting your password) via our e-mail provider Hostpoint AG, Rapperswil-Jona, Switzerland.

5. Payments

We process payments via Stripe Payments Europe Ltd., Dublin, Ireland (a group company of Stripe, Inc., USA). You enter card details directly with Stripe; we only receive references, the subscription status and invoice information. Stripe is partly responsible itself for payment processing. Further information: stripe.com/ch/privacy.

6. Website, security and logs

The website and app are delivered via Cloudflare, Inc. (global network, database in the EU). When you access them, Cloudflare processes technically necessary connection data (e.g. IP address, time, requested address, browser) for delivery and to protect against attacks. To protect against misuse, we limit login attempts and analyses; for this we use an irreversible, secret hash of your IP address, which is deleted after 2 days at the latest. Registration and the free trial are protected against bots with Cloudflare Turnstile.

7. Cookies, analytics and advertising

The only necessary cookie is the session cookie for login. We store your cookie choice in your browser's local storage.

Without cookies and without consent, we keep our own anonymous statistics: per day, we count visits, free tests, sign-ups and purchases and the source they came from (for example Google, Meta or direct, derived from the referring website and campaign parameters in the link). For this, your browser remembers the source only while the tab is open (session storage). We store no IP address, no identifier and nothing that could identify you. When you sign up, we also store the source in your account to see which channels lead to customers.

Only if you consent do we load Google Tag Manager (Google Ireland Ltd.) with Google Analytics and Google Ads, as well as the Meta Pixel (Meta Platforms Ireland Ltd.), on the website. This allows us to measure how many visitors find us through our advertising and register. With your consent, we also report the events "Registration" and "Subscription completed" to Meta server-side (Conversions API) with a hashed e-mail address. You can withdraw your consent at any time via "Cookie settings" at the bottom of the page; we will then delete the analytics and advertising cookies that have been set. There is no tracking whatsoever in the tool (dashboard).

8. Disclosure abroad

The account data and the AI analysis remain in the EU, which under Swiss law offers an adequate level of data protection. Individual providers (Cloudflare, Google, Stripe, Meta) are companies headquartered in the USA or their subsidiaries. Insofar as data may reach the USA, we rely on certification under the Swiss-U.S. or EU-U.S. Data Privacy Framework or on standard contractual clauses.

9. Retention

DataDuration
Your PDFs and analysis resultsnot stored
Account and subscription datauntil the account is deleted; accounting records in accordance with the statutory period (10 years) at Stripe
Sessions30 days
Password reset links1 hour
IP hashes for misuse protection2 days
Usage statistics without content24 months

10. Your rights

You have the right to information, rectification, erasure, data portability and objection, as well as the right to withdraw consent. To exercise these rights, write to us at info@hyperpage.ch. You may also lodge a complaint with the Federal Data Protection and Information Commissioner (FDPIC) or, in the EU, with the competent supervisory authority.

11. Processing on behalf of business customers

If you process personal data of your clients or employees with PDF Splitter, we act as your processor. Our data processing agreement (DPA) applies to this.

12. Changes

We amend this statement when our service or the legal situation changes. The version published on this page at any given time applies.