Privacy Policy
Last updated: September 3, 2026
Lemmafour is built so that the most private thing about it is the architecture, not a promise: your documents are processed on your device, in your browser. This page explains exactly what stays local, what our servers can see, and what we store.
Your documents stay on your device
All PDF and image processing — merging, splitting, editing, compressing, signing, form filling, converting — runs inside your browser using WebAssembly. When you open a file in a Lemmafour tool:
- The file's contents are not uploaded to our servers for processing.
- The results are generated on your device and saved by you, from your device.
- We cannot read, scan, or retain your documents, because they never reach us.
What is stored in your browser
To survive page refreshes and let you pick up where you left off, Lemmafour can keep working files and generated outputs in your browser's local storage (IndexedDB and localStorage) on your device only. Your theme preference is stored the same way. You can clear this at any time from the workspace controls or by clearing site data in your browser.
What our servers see
Like any website, loading Lemmafour requests the app's pages, scripts, fonts, and WebAssembly modules from our hosting provider. Standard web server logs (IP address, requested URL, browser user agent, timestamp) may be produced by the hosting infrastructure for security and reliability. These logs relate to loading the app itself — they do not contain your documents or their contents.
Analytics and tracking
Lemmafour does not use advertising trackers or general-purpose behavioral analytics. Paddle.js is loaded on the homepage and checkout. It is also loaded on interactive tool and account pages when the signed-in account is already linked to a Paddle customer, to support checkout and payment-recovery notices. Paddle may receive ordinary request metadata such as IP address, browser information, and page URL. For a signed-in paid customer, Lemmafour may also provide the opaque Paddle customer identifier that Paddle previously assigned to that account. This integration does not receive document files or document contents. Paddle's handling of this technical data is described in its privacy notice below.
Payments and paid access
Paddle is Lemmafour's authorized reseller and Merchant of Record. Paddle collects and processes the buyer, payment, tax, invoice, and subscription data needed to complete the order. Paddle's handling of that data is described in its privacy notice.
Accounts and sign-in
If you create an account, Lemmafour stores your verified email address, an opaque account identifier, account status, and security timestamps. Sign-in links and six-digit codes expire after 10 minutes and are stored only as keyed one-way verifiers; session credentials are also stored only as keyed verifiers. The browser receives a secure, HTTP-only session cookie.
The security page shows approximate active-session details so you can recognize and remotely sign out another browser. For each session, Lemmafour stores only a coarse browser family, operating-system family, device class, two-letter country code, and creation, last-active, and expiry times. It does not store a device model, city, precise location, hardware identifier, or browser fingerprint. Expired and revoked session records are removed after a limited security-retention period.
To limit automated sign-in abuse, the account service temporarily uses one-way, rotating identifiers derived from the submitted email address and source IP address. Raw IP addresses and browser user-agent strings are not stored in account or session tables. Full browser user-agent strings are reduced to the coarse categories described above and then discarded. The email delivery provider receives the destination address and authentication message so it can deliver the requested email. Authentication emails contain no trackers or remote images.
Lemmafour's entitlement service receives opaque Paddle transaction, subscription, and event identifiers; the purchased offer; entitlement status and expiry; and limited technical records needed to prevent replay, process renewals, and provide support. It will not receive full card details or the contents of your documents.
Payment-record retention
Active entitlement records will be kept while access is valid and as needed afterward for support, disputes, fraud prevention, and legal obligations. A one-way fingerprint of a redeemed one-time purchase is retained so the same purchase cannot ever restart its 24-hour access period. Payment event identifiers and minimal processing records are retained as needed to prevent duplicate fulfillment, reconcile failures, handle disputes, and meet legal obligations. The records contain no document contents, buyer name, email address, or card details.
Support correspondence
If you email us, we receive the address, message, and attachments you choose to send. We keep support correspondence only as long as reasonably needed to answer the request, maintain an audit trail, or meet legal obligations.
Your rights
Because we do not hold your documents, there are no server copies of those files for us to delete or export. Account controls let you change your verified email, sign out other sessions, or delete your Lemmafour account. Account deletion removes the sign-in email, disables the account, and revokes every session. It does not remove files stored locally in your browser or files you downloaded. Minimal entitlement, security, and payment processing records may be retained where needed for replay prevention, reconciliation, fraud prevention, disputes, tax, or other legal obligations.
Paddle controls the buyer, payment, tax, invoice, and subscription records it holds as Merchant of Record. Deleting a Lemmafour account does not delete those separate records. Paddle provides a buyer data deletion process and may retain some transaction data where legally required. For privacy questions or requests about Lemmafour support or entitlement records, contact support@lemmafour.com.
Who we are
Lemmafour is operated by Ankit Kumar Chauhan, a sole proprietor based in Moradabad, Uttar Pradesh, India. This policy may be updated as the product evolves; material changes will be reflected in the date above.