A Dark Vector Cognition product
Privacy and processing

Where your PDF goes, and what we keep.

Your file goes over HTTPS to pdfmd.dev, then to a conversion worker we run on Modal, a cloud compute service, and the Markdown or searchable PDF comes back to your browser. Results get no link. You keep every right to your documents.

Memory-only Data describes ordinary text-to-Markdown conversion. OCR uses private temporary files, removed after processing.

What happens to a file

The site runs on Vercel. The page you upload from sends the file to our server function, which counts its pages, checks your allowance and passes it to the conversion worker. The worker runs on Modal. It returns Markdown or, for OCR, a searchable PDF, and the server function sends the result to your browser.

For ordinary text-to-Markdown conversion, our code does not save the file, the Markdown or the file name, and there is no results link to share. It holds the file in memory only: the server function reads an upload with a 4 MB cap and the worker reads a PDF from a link with a 50 MB cap, neither writes it to a file, and both release it, and the Markdown, when the response is sent, whether the conversion worked or not. Vercel and Modal run that code on their infrastructure. How their systems buffer a request, and how long they keep request logs, is set by them; we have not measured it, so we do not claim that nothing ever touches their disks.

OCR is different: it uses a private temporary directory for each worker request, containing the input PDF, working files and result. Our code removes that directory on success, failure and worker timeout, after ending the OCR process and its child processes. The result is returned in the response and has no saved public download link. A browser cancellation or server timeout does not prove the worker stopped at that moment; the worker has its own deadline and cleanup. Hosting providers may buffer requests and keep logs under their own policies, which we have not measured.

If you convert from a link rather than an upload, the worker fetches that link. The site you name sees a request from us, not from you.

No cookies and no accounts

This site sets no cookies. There is no login and no signup on the free tool, and nothing is gated behind giving us an address.

PDFMD in an AI assistant

The connector at pdfmd.dev/mcp receives the public PDF URL your assistant sends, processes it through the ordinary text-to-Markdown cloud path without OCR, and returns Markdown to that assistant. It does not receive your whole chat or read local attachments. The assistant provider handles the returned text under its own policy. No result is saved by our application or assigned a download link.

We record bounded tool names, outcomes, response-time ranges, identifiable assistant families and our own test markers in Vercel Web Analytics and runtime logs. These connector measurements contain no source URLs, document text, file names, API keys, IP addresses, cookies or raw user agents. Counts represent calls, not unique people. Aggregate history is used to compare usage over time; hosting-provider log retention is controlled by Vercel.

Requests carrying Do Not Track or Global Privacy Control skip measurement, as do connector URLs containing query parameters. The existing rate limit and page accounting still apply. Removing the connector from your assistant stops its future calls. Updated 28 September 2026: added the assistant connector and its aggregate measurement.

What the counters hold

We count how many conversions succeed, how many fail, and how many pages were converted, so we know whether the tool works and what it costs to run. These are daily totals. They are not attached to a person, a file or a session, and a page count says nothing about what was on the page.

Analytics

We use Vercel Web Analytics, which is cookieless and does not fingerprint visitors or follow them across sites. Events carry fixed codes and page counts in coarse ranges, never a file name, a link or any text from a document.

Global Privacy Control

If your browser sends a Sec-GPC header, or the older DNT header, we honour it: the analytics script is not loaded for you, and our own server-side counters skip your visit.

Rate limiting

The free allowances are per address, so one caller cannot use them up for everyone. That needs a per-address tally, kept for the current UTC day and then expired. It is a protection, not a measurement.

Payments and API keys

Plans are paid on Stripe's hosted checkout page, so card details go to Stripe, not to us. We store an API key only as a hash, with its plan, its Stripe customer and subscription identifiers, its status and billing period, and when it was created.

Logs

Our hosts keep short-lived request logs, which include IP addresses. We do not export them or build profiles from them.

Changes and contact

If this page changes in a way that is less generous, the change will be stated plainly here. Questions to hello@darkvectorcognition.ai.