DDocument Forge Back to tools

Privacy

Privacy notice

Last updated: 2026-07-31

This notice explains what happens to the documents and text you put into Document Forge, which cookies exist, who the advertising partners are, and what you can control. It is written to be checkable: every claim below corresponds to behaviour you can observe in your browser's network tools.

Who is responsible

김성진 (Not disclosed) operates this site and is the controller for the limited processing described here. Privacy questions and requests: tttksj@gmail.com. Requests are answered within 5 business days.

What the browser does, and does not send

Character counting, HWPX text extraction, plain-text and Markdown preview, HTML sanitisation, the print-ready PDF view, and the writing-signal heuristic all run inside the page on your own device. No network request carries the contents of those files or that text. You can verify this: open the Network panel of your developer tools, drop a file in, and confirm that no upload appears — or disconnect from the network entirely and watch the tools keep working.

Because there is no upload in this path, there is nothing for us to store, retain, or delete, and nothing for a subpoena or a breach to reach.

The two paths that involve a server

Both are off unless the operator explicitly configures them, and neither happens silently.

  • Legacy HWP conversion. A binary .hwp file cannot be read in a browser. If the operator has configured a converter, the file you selected is sent to this application for exactly one conversion, written to a temporary directory scoped to that request, and deleted when the request finishes. It is not copied elsewhere, not indexed, and not used for any other purpose. If no converter is configured, the request is refused with a clear error rather than a fabricated result.
  • Optional server writing model. If the operator has configured an external model endpoint, your text is sent there only after you tick the consent box next to that specific request. The endpoint is chosen and disclosed by the operator; its own retention and terms apply to what it receives. Do not send confidential text through it.

Uploads are limited to 20 MB, and the application does not retain them after responding.

Technical information from ordinary requests

Like any website, this one receives the information needed to answer a request: your IP address, the requested URL, the time, your user-agent string, and the referring page. The hosting layer and any reverse proxy or CDN in front of the site may record these in access logs for security and abuse handling. These logs are not used to build a profile of you and are not combined with the contents of documents, because the application never receives those contents in the default path.

Your browser also sends an Accept-Language header, which is used once to choose an interface language. When the site runs behind a proxy that supplies a country code, that country code may be used for the same purpose. Neither value is stored.

Cookies and local storage

Document Forge sets no cookies of its own. Two values are stored locally in your browser, and both stay on your device:

  • document-forge-consent-v1 — whether you chose "Essential only" or "Allow optional cookies". Without it the banner would ask on every visit.
  • document-forge-language-v1 — your manual interface-language choice, if you made one.

Clearing site data in your browser removes both, which also resets your advertising choice to the default of "no optional cookies".

Advertising

This site is free and is intended to be funded by advertising. Advertising is handled as follows:

  • Nothing loads before you choose. Until you select "Allow optional cookies", no advertising script is downloaded and no request is made to an advertising domain. Choosing "Essential only", or making no choice at all, leaves the ad area empty. The site's Content-Security-Policy does not even permit the ad domains until advertising is switched on by the operator.
  • Who the partner is. When advertising is enabled, ads are served by Google AdSense (Google Ireland Limited / Google LLC, depending on your region). Google is a third-party vendor and uses cookies and similar identifiers to serve and measure ads.
  • What the partner receives. Advertising partners never receive your documents or the text you paste, because those never leave your browser. They do receive the standard information any embedded third party sees: your IP address, the page URL and title, referrer, user-agent, and interactions with the ad itself. Google may use a cookie such as the DoubleClick cookie, and may combine this with data it already holds to serve personalised ads.
  • Third-party vendors and networks. Google and its partners may use cookies or device identifiers to serve ads based on your prior visits to this and other websites. Vendors other than Google may also participate through Google's network.

Your advertising choices

  • Withdraw consent at any time by clearing this site's data in your browser; the banner reappears and no ad code loads until you allow it again.
  • Turn off personalised advertising across Google products at Google Ads Settings.
  • Manage third-party vendor cookies at aboutads.info or, in Europe, youronlinechoices.eu.
  • Review Google's own explanation of the data it processes as an advertising partner in the Google privacy & terms page for partner sites.

Legal bases, and where the data goes

Where the GDPR or a comparable law applies: serving the site and keeping it secure relies on legitimate interests; a configured HWP conversion or server model request relies on your explicit request and, for the model, your consent; advertising and any non-essential identifier relies on consent, which you give through the banner and can withdraw. Advertising partners are international, so enabling advertising means personal data such as your IP address may be processed outside your country under the transfer mechanisms those providers publish.

You may request access, correction, erasure, restriction, portability, or objection, and you may complain to your local supervisory authority. In practice, for the default browser-only use of this site there is usually no stored personal data to act on; the honest answer to an erasure request will often be that nothing was ever collected. If you are a California resident: this site does not sell personal information for money, and you may direct us not to share it for cross-context behavioural advertising by declining optional cookies.

Retention

Documents and text in the default path: never received, so never retained. A configured HWP conversion: the temporary file exists only for the duration of that request. Server-model text: transmitted for that request only; the operator does not retain a copy. Access logs: kept only as long as the hosting or proxy layer's configured window for security purposes. Local-storage values: until you clear them.

Children

The site is a general-purpose utility and is not directed to children under 13 (or the higher age of digital consent in your country). We do not knowingly collect personal information from children. Advertising, where enabled, is not targeted at children.

Security

The site is served over HTTPS with a restrictive Content-Security-Policy, framing and MIME-sniffing protections, and a narrow public file allowlist. API requests are rate-limited and reject cross-origin submissions. No security control is absolute; please report anything you find through the contact page.

Changes

Material changes will be reflected in the date at the top of this page. Enabling a new advertising partner, analytics provider, or server adapter counts as a material change and will be described here before or when it takes effect.

Return to Document Forge

© 2026 Document Forge.

About · Contact · Terms of use