Booklet PDF
Privacy

Privacy Policy

Last updated: August 17, 2026

MTTech LLC ("we", "our", or "us") provides PDF Booklet Maker (also referred to as BookletPDF) for iPhone, iPad, and Mac, together with its website, API, store, and support services. This policy explains what information is processed, how it is collected and used, who receives it, how long it is kept, and the choices available to you. Some features differ by platform; rewarded advertising is available only on iPhone and iPad.

Your Documents Stay Private

PDF conversion and document scanning take place on your device. We do not upload your PDFs, scanned pages, document names, file paths, or document content to our servers for conversion, analytics, advertising, account synchronization, or support.

Files remain on your device unless you choose to export, print, share, or save them with an operating-system service. If you enable iCloud document storage, Apple transfers and stores the selected files in your iCloud account; our server does not receive them.

Cover images you choose, text you type into a cover, and searches within the downloaded cover list also stay on your device. The app sends only the catalog request or ownership action described below, not your search text or edited cover content.

Installation and App Information

The app creates a random BookletPDF installation UUID. It is not an IDFA, hardware serial number, or identifier assigned by your device manufacturer. We use it to distinguish an installation for analytics deduplication, support, notifications, inbox delivery, abuse prevention, wallet synchronization, referral safeguards, and feature entitlements.

The installation UUID is pseudonymous while you are signed out. If you voluntarily sign in, it can be associated with your BookletPDF account, so installation and related usage information may then be linked to that account.

The app may send this random identifier together with limited technical information such as platform, app version and build, locale, request time, and feature or event information. Like most internet services, our web server and API infrastructure may also process IP address, requested path, user agent, timestamps, and security logs to deliver the service, diagnose failures, rate-limit requests, and prevent abuse.

Analytics and Diagnostics

We use first-party analytics and Google Firebase Analytics to understand app opens, document imports by page count, conversions, exports, purchases, rewarded-ad results, coin activity, referrals, support submission, notification-inbox use, feature usage, and reliability. A daily app-open event is sent at most once per installation per calendar day. Events use UUIDs so a network retry does not create a duplicate in our first-party system.

Our first-party analytics endpoint accepts only an approved set of metadata, such as booklet type, page count, platform, app version and build, locale, product identifier, coin amount or balance, and sanitized error domain or code. It rejects arbitrary fields and does not accept PDF names, paths, or content.

We keep detailed events in our first-party analytics store for up to 30 days. Older events are reduced to daily totals and active-installation counts, after which the detailed event rows and installation identifiers in those rows are deleted. Aggregated statistics may be retained for historical reporting.

Google Firebase Crashlytics processes crash stack traces, app and operating-system versions, device model and state, timestamps, and pseudonymous Firebase or Crashlytics installation identifiers so we can diagnose crashes. Before an app error is sent, BookletPDF removes the original system error details that can contain a document path or file name. Firebase Analytics and Crashlytics data is processed and retained by Google under Firebase's terms and privacy practices.

Optional Account and Wallet Synchronization

You do not need an account to open PDFs, convert or export documents, watch a rewarded ad, restore an existing purchase, or contact support. Sign in with Apple is voluntary except when you choose to start a new Pro purchase, where it is used to link that purchase safely to an account.

If you sign in, we receive Apple's stable account identifier and, only when Apple makes them available, your name and email address. We store account sessions, the random installations connected to the account, an opaque App Account Token, account benefits, account preferences such as whether push alerts are enabled, referral and promo codes and redemptions, Pro grants, owned catalog designs, and wallet information. Wallet information can include current coin balance, revision, change reason, installation identifier, app version and build, synchronization time, and an audit of coin purchases, grants, or spending.

Cover Store and Catalog

The app downloads published catalog metadata, low-resolution thumbnails, pricing, and selected design files from our server. Normal request metadata, including the installation UUID, accompanies those requests. A signed-in account is required to claim or unlock account-bound store artwork. We then store the catalog item, version, source of the claim, coin price paid where applicable, wallet operation, and acquisition time so the design remains available to the account.

Cover-list search is performed on your device and the search words are not sent to us. Text, fonts, colors, and other edits you apply to a downloaded design remain on your device and are not added to the catalog record.

Purchases and Pro Access

Pro and coin-pack purchases are processed by Apple through StoreKit. We do not receive or store your payment-card number or App Store payment credentials. To verify access, fulfill coins once, process refunds, and prevent duplicate delivery, the app or Apple's App Store Server Notifications may provide us with a cryptographically signed transaction. We store transaction and original-transaction identifiers, product identifier, purchase environment, ownership type, purchase, fulfillment, and revocation dates, fulfillment or refund state, the signed transaction, and the opaque App Account Token when present.

A coin pack can be fulfilled to a signed-out wallet. In that case, the server stores an opaque wallet identifier, a one-way hash derived from the installation UUID, a hashed wallet credential, balance and operation records, and the App Account Token assigned to the wallet. If that wallet is later claimed after sign-in, it becomes linked to the account.

Restoring a purchase does not require Sign in with Apple. Existing verified StoreKit access remains available while signed out. If an existing Pro user later signs in voluntarily, the current verified StoreKit transaction may be synchronized to the account.

Support Requests

If you contact support through the app or website, we process the topic, title, message, optional reply email, request status and time, and limited client context such as platform and app version. App requests may include the random installation UUID. For rate limiting, we store a salted hash of the source IP address rather than the raw address in the support request.

To alert our operator, the support topic, title, message, request number, platform, and app version may be sent to a private operator chat through the Telegram Bot API. The alert deliberately excludes your reply email, installation UUID, IP hash, user agent, and account credentials. Telegram processes the alert content according to its own privacy practices. Replies may be delivered through the app's inbox and an optional push notification.

Notifications

If you allow notifications, Firebase Cloud Messaging and Apple Push Notification service process a device push token and delivery information. Our server stores the FCM token with the random installation UUID, platform, app version and build, locale, enabled state, and registration timestamps. Push notifications are a delivery alert; the app's authenticated or installation-scoped inbox remains the source of the message. You can disable push notifications in BookletPDF Settings or in system settings. When disabled in the app, the server marks the installation's tokens as disabled and messages remain available from the inbox endpoint. If you sign in, this preference is also stored with your profile and applied when that profile is used on another installation.

Rewarded Advertising

On iPhone and iPad, free users may voluntarily choose to watch a rewarded ad to receive a coin. BookletPDF does not show forced banner, interstitial, or app-open ads. BookletPDF does not call the advertising provider's initializer or request an ad until you choose the rewarded-ad action. macOS does not include or present rewarded ads.

The iOS advertising stack uses Yandex Mobile Ads and includes mediation components that can allow an ad to be supplied by Google Mobile Ads, AppLovin, Digital Turbine, Mintegral, or myTarget. Depending on the provider and ad served, these companies may process IP address, coarse location inferred from IP, device or vendor identifiers made available by the operating system, device and operating-system information, network information, advertising data, ad and product interactions, and crash, performance, or other diagnostic data to deliver, secure, limit fraud, measure, and improve advertising.

Some bundled advertising SDK privacy manifests classify device identifiers or advertising data as linked data or as data used for cross-app advertising or measurement. We disclose those practices in the App Store privacy details. The current app does not request permission under Apple's App Tracking Transparency framework and therefore does not receive the IDFA. We pass a no-consent signal when initializing Yandex Mobile Ads. We do not send ad providers your PDFs, scans, support messages, account name or email, BookletPDF account identifier, or BookletPDF installation UUID.

Service Providers

We use service providers only for the functions described above:

  • Apple for Sign in with Apple, StoreKit purchases, App Store Server Notifications, iCloud when you enable it, and Apple Push Notification service.
  • Google Firebase for analytics, crash reporting, diagnostics, Firebase installations, and cloud messaging.
  • Yandex Mobile Ads and its enabled mediation partners (currently Google Mobile Ads, AppLovin, Digital Turbine, Mintegral, and myTarget) for voluntary rewarded advertising, fraud prevention, delivery, and measurement on iPhone and iPad.
  • Telegram to deliver privacy-minimized support alerts to our private operator chat.
  • Hosting and infrastructure providers to operate and secure our website, API, database, encrypted backups, and catalog files.

We require providers receiving personal data from us or through SDKs we select to protect it in a manner consistent with this policy and applicable law, and to use it only for the services described or as otherwise disclosed to you. These providers may process information in countries other than your own under their terms. Learn more in the Apple Privacy Policy, Firebase Privacy and Security documentation, Google's partner data explanation, Yandex Ads Privacy Policy, and Telegram Privacy Policy.

Website Data and Cookies

Our public website does not contain third-party advertising or BookletPDF product analytics. It processes ordinary web request information described above. Essential session and security cookies may be used for forms, sign-in, and administrative access; they are not used by us to build an advertising profile. If you submit the website contact form, the Support Requests section applies.

Retention, Deletion, and Your Choices

  • Detailed first-party analytics events are kept for up to 30 days; the non-identifying daily totals produced from them may be retained for historical reporting.
  • Account, wallet, referral, preference, benefit, and catalog-ownership records are kept while the account is active and are removed through in-app account deletion, except for the limited records described below.
  • Push registrations are kept while needed to deliver your selected notification service. Disabling push marks the registrations inactive and deletes the app's current Firebase token where available.
  • Support requests and operational or security logs are kept while needed to answer the request, secure and troubleshoot the service, resolve disputes, prevent abuse, and maintain necessary business records, then deleted or de-identified when no longer needed.
  • Verified purchase and fulfillment records are kept as needed to maintain access, process refunds, prevent duplicate coin delivery, prevent fraud, and meet accounting or legal obligations.
  • Encrypted disaster-recovery backups use a rolling schedule of recent, daily, weekly, and up to 12 monthly snapshots. Deleted data can remain in a protected backup until that snapshot expires; backups are not used for ordinary product or advertising activity.
  • Third-party providers apply the retention schedules in their own policies.

You can use the core app without an account, decline a rewarded ad, decline or disable notifications, manage iCloud in Apple settings, avoid submitting support information, and sign out at any time. The current app does not request IDFA access. You can contact us to object to or ask us to stop processing personal information where applicable.

Signed-in users can choose Delete Account in the app without contacting support. The app asks you to authenticate again. After Apple confirms authorization revocation, deletion removes the mobile account and its sessions, wallet and wallet operations, benefits and grants, preferences, referrals, catalog ownerships, account-linked Pro transaction records, and support requests matching the account email. It also removes raw first-party analytics events, push registrations, targeted inbox messages, achievements, and support requests for installation UUIDs connected to the account at deletion time. Consumable purchase records are stripped of the account token, signed transaction, wallet link, and device-derived wallet identifiers, leaving only a replay-safe purchase and fulfillment record needed to prevent the same transaction from delivering coins again.

Non-identifying aggregate analytics, protected backup snapshots, de-identified fraud-prevention records, and records that must be retained for legal, accounting, security, dispute, refund, or duplicate-fulfillment reasons may not be removed immediately by account deletion. Data for an installation that was never connected to the deleted account cannot automatically be located from that account. You may contact us to request access, correction, or deletion of personal information or installation-scoped data, subject to applicable law. We may need information sufficient to locate the relevant record and verify the request.

Security

We use transport encryption, access controls, credential redaction, signed Apple transaction verification, randomized or hashed identifiers where appropriate, and restricted administrative access. No method of transmission or storage is completely secure, but we work to limit the information collected and protect what is necessary to operate the service.

Children's Privacy

PDF Booklet Maker is not directed to children under 13, and we do not knowingly collect personal information directly from children. If you believe a child has provided personal information, contact us so we can review and delete it where appropriate.

Changes to This Policy

We may update this policy as the app or its services change. We will post the updated policy on this page and change the "Last updated" date.

Contact Us

For privacy questions or requests, contact:

MTTech LLC
Email: tokhirov.mukhammadjon@gmail.com