Privacy Policy
Effective date: October 8, 2026. This policy describes what data Serifmark processes, for what purposes, and for how long. Terms are used consistently with the Terms of Service.
What we collect
- Account dataYour email address, a bcrypt hash of your password (the plaintext is never stored), email verification status and account status.
- CredentialsAPI keys and web session tokens. An API key's plaintext is shown exactly once at creation; the login session token is stored in your browser's localStorage with an expiry.
- Rendering dataThe Markdown source you submit is processed only during rendering and is not retained afterwards; rendered PDFs are delivered via short-lived signed links (10 minutes by default) and physically deleted after expiry. We keep render metadata (success, page count, duration, error codes) for billing reconciliation and service improvement.
- Anti-abuse signalsSignups and the visitor demo are rate-limited per IP address (3 signups and 10 demo renders per IP per day); signup is protected by Cloudflare Turnstile; disposable email domains are blocked.
What we don't do
- We never sell your personal data.
- No tracking cookies, third-party advertising or behavioral analytics.
Third-party processors
- CloudflareStatic hosting, Turnstile bot protection and email routing.
- CreemPayment processing. Subscriptions and packs are settled by Creem as Merchant of Record; it processes payment details and taxes under its own privacy policy.
Retention & deletion
Rendered files are physically cleaned up on a TTL schedule; render metadata is kept until account deletion. You can contact support@serifmark.com at any time to have your account and its data deleted — we handle it manually.
Changes to this policy
Material changes are announced on this page and on the site; continued use of the service means acceptance of the updated policy.