DDocument Forge Back to tools

Privacy

Privacy notice

Last updated: 2026-08-24

This notice explains what happens to the documents and text you put into Document Forge, which cookies exist, who the advertising partners are, and what you can control. It is written to be checkable: every claim below corresponds to behaviour you can observe in your browser's network tools.

Who is responsible

김성진 (Seoul, South Korea) operates this site and is the controller for the limited processing described here. Privacy questions and requests: tttksj404@gmail.com. Requests are answered within 5 business days.

What the browser does, and does not send

In the default browser-only path, character counting, local HWP and HWPX rendering, plain-text and Markdown preview, HTML sanitisation, the print-ready PDF view, and the writing-signal heuristic all run inside the page on your own device. No network request carries the contents of those files or that text. You can verify this: open the Network panel of your developer tools, drop a file in, and confirm that no upload appears — or disconnect from the network entirely and watch the document tools keep working after the renderer has loaded.

Because there is no upload in this path, there is nothing for us to store, retain, or delete, and nothing for a subpoena or a breach to reach.

The path that can involve a server

Document files are not sent to this application in the public workflow. The optional writing model is off unless the operator configures it, and it never runs silently.

  • Legacy HWP rendering. A binary .hwp file is rendered on your own device with a self-hosted browser WebAssembly component. The application sanitises the generated SVG before displaying it in a sandboxed frame and uses the browser's print dialog for PDF saving. The source file is not uploaded. Because font availability and complex layout can vary, check the saved PDF before using it for an official or high-fidelity purpose.
  • Optional server writing model. If you tick the consent box next to that specific request, the public edge deployment sends the text to Cloudflare Workers AI using the @cf/meta/llama-3.2-3b-instruct model. The application does not attach a storage service or retain a copy, but Cloudflare processes the request under its Workers AI data-use terms. Do not send confidential text through it. An origin deployment may use a separately configured HTTPS endpoint instead.

Local document input is capped at 20 MB. HWP rendering is also limited to 150 pages so the browser remains responsive.

Daily server-model allowance

The optional server writing model has a small daily allowance. The application stores only a short-lived anonymous session hash and the daily usage count needed to enforce that limit; document contents and pasted text are not stored in the usage record. When the allowance is exhausted, the server model stops until the next daily window. There is no account balance, paid checkout, subscription, or overage billing.

Technical information from ordinary requests

Like any website, this one receives the information needed to answer a request: your IP address, the requested URL, the time, your user-agent string, and the referring page. The hosting layer and any reverse proxy or CDN in front of the site may record these in access logs for security and abuse handling. These logs are not used to build a profile of you and are not combined with the contents of documents, because the application never receives those contents in the default path.

Your browser also sends an Accept-Language header, which is used once to choose an interface language. When the site runs behind a proxy that supplies a country code, that country code may be used for the same purpose. Neither value is stored.

Cookies and local storage

Document Forge uses one essential HttpOnly cookie for an anonymous daily server-model allowance and two local values that stay in your browser:

  • df_session — a random persistent browser identifier with a maximum one-year lifetime. It does not contain your email or document text; the server stores only its hash with the daily usage count for the optional server-model allowance. Clearing it creates a new anonymous identifier.
  • document-forge-consent-v1 — whether you chose "Essential only" or "Allow optional cookies". Without it the banner would ask on every visit.
  • document-forge-language-v1 — your manual interface-language choice, if you made one.

Clearing site data in your browser removes these values, resets your advertising choice to the default of "no optional cookies", and starts a new anonymous allowance identity.

Advertising

This site is free and is intended to be funded by advertising. Advertising is handled as follows:

  • Nothing loads before you choose. Until you select "Allow optional cookies", no advertising script is downloaded and no request is made to an advertising domain. Choosing "Essential only", or making no choice at all, leaves the ad area empty. The site's Content-Security-Policy does not even permit the ad domains until advertising is switched on by the operator.
  • Who the partner is. When advertising is enabled, ads are served by Google AdSense (Google Ireland Limited / Google LLC, depending on your region). Google is a third-party vendor and uses cookies and similar identifiers to serve and measure ads.
  • What the partner receives. Advertising partners never receive your documents or the text you paste, because those never leave your browser. They do receive the standard information any embedded third party sees: your IP address, the page URL and title, referrer, user-agent, and interactions with the ad itself. Google may use a cookie such as the DoubleClick cookie, and may combine this with data it already holds to serve personalised ads.
  • Third-party vendors and networks. Google and its partners may use cookies or device identifiers to serve ads based on your prior visits to this and other websites. Vendors other than Google may also participate through Google's network.

Your advertising choices

  • Withdraw consent at any time by clearing this site's data in your browser; the banner reappears and no ad code loads until you allow it again.
  • Turn off personalised advertising across Google products at Google Ads Settings.
  • Manage third-party vendor cookies at aboutads.info or, in Europe, youronlinechoices.eu.
  • Review Google's own explanation of the data it processes as an advertising partner in the Google privacy & terms page for partner sites.

Legal bases, and where the data goes

Where the GDPR or a comparable law applies: serving the site and keeping it secure relies on legitimate interests; the local document tools process data on your device; a server-model request relies on your explicit request and consent; advertising and any non-essential identifier relies on consent, which you give through the banner and can withdraw. Cloudflare Workers AI and advertising partners are international, so enabling those features may process personal data such as your IP address or submitted text outside your country under the transfer mechanisms those providers publish.

You may request access, correction, erasure, restriction, portability, or objection, and you may complain to your local supervisory authority. In practice, for the default browser-only use of this site there is usually no stored personal data to act on; the honest answer to an erasure request will often be that nothing was ever collected. If you are a California resident: this site does not sell personal information for money, and you may direct us not to share it for cross-context behavioural advertising by declining optional cookies.

Retention

Documents and text in the default document path: never received, so never retained by this application. Server-model text: transmitted for that request only; the application does not retain a copy, while the model provider's handling follows its published data-use terms. Daily usage records: an anonymous session hash, UTC day, and count needed to enforce the allowance. Access logs: kept only as long as the hosting or proxy layer's configured window for security purposes. Local-storage values: until you clear them; the essential session cookie lasts for its stated expiry or until you delete it.

Children

The site is a general-purpose utility and is not directed to children under 13 (or the higher age of digital consent in your country). We do not knowingly collect personal information from children. Advertising, where enabled, is not targeted at children.

Security

The site is served over HTTPS with a restrictive Content-Security-Policy, framing and MIME-sniffing protections, a narrow public file allowlist, and sandboxed HWP preview output. API requests are rate-limited and reject cross-origin submissions. No security control is absolute; please report anything you find through the contact page.

Changes

Material changes will be reflected in the date at the top of this page. Enabling a new advertising partner, analytics provider, or server-side processing feature counts as a material change and will be described here before or when it takes effect.

Return to Document Forge

© 2026 Document Forge.

About · Contact · Terms of use