Privacy Policy
Last updated: May 17, 2026
1. Overview
BlurPen is a free, browser-based image and PDF redaction tool. This Privacy Policy explains how BlurPen handles your data. The short version: your files never leave your device, and we are transparent about how the ad-supported model works.
BlurPen processes all files entirely client-side using the HTML5 Canvas API, PDF.js, and pdf-lib — all self-hosted in the application bundle. No file bytes, pixel data, or document content are ever transmitted to BlurPen's servers or any third party.
BlurPen is ad-supported. This means third-party advertising scripts (such as Google AdSense) run on the page and may collect standard browsing signals. This is separate from — and has no access to — any file you upload. These two facts coexist and both are disclosed here.
2. File Privacy — Absolute Guarantee
No file data ever leaves your browser. This is not a marketing claim — it is an architectural fact:
- All image and PDF processing is performed client-side via the HTML5 Canvas API and locally bundled libraries.
- No bytes of any uploaded file are transmitted to BlurPen's servers or any third party — ever.
- BlurPen has no server backend that receives or processes files.
- No file content is stored in
localStorage,sessionStorage, or any other browser storage. - EXIF metadata is stripped from exported images to prevent inadvertent location or device metadata leakage.
- These guarantees apply regardless of your ad consent status.
3. Advertising & Cookies
BlurPen is free because it is ad-supported. We integrate Google AdSense (and may test alternative networks such as Media.net or Ezoic). When you consent to personalised advertising, the ad network's JavaScript may:
- Set first- and third-party cookies for ad personalisation purposes.
- Collect standard browser signals: IP address, browser type and version, referring URL, and page URL.
- Build interest-based advertising profiles subject to Google's own Privacy Policy.
This data collection is governed by the ad network's privacy policy, not BlurPen's. It is entirely separate from any uploaded file or canvas data, which ad scripts have no technical access to (enforced by browser same-origin policy).
If you decline personalised ads, BlurPen will serve non-personalised ads (NPAs) — ads still appear, but without behavioural targeting.
4. Consent Management
A GDPR/CCPA-compliant consent banner is shown on your first visit before any personalised ad scripts execute. You can:
- Accept — personalised ads are served; consent stored in a first-party cookie.
- Decline — non-personalised ads are served; no behavioural tracking.
- Manage Preferences — available at any time via the "Manage Ad Preferences" link in the footer; this clears your stored consent and reopens the banner on next page load.
Consent is stored in a first-party cookie and persists across sessions until you clear it or change your browser settings.
5. Analytics
BlurPen may use a privacy-respecting analytics tool (such as Plausible or Fathom) to measure aggregate page views and feature usage. These tools use no cookies, perform no cross-site tracking, and are GDPR-compliant by default. No individual user sessions or file-content signals are ever tracked.
6. Your Rights (GDPR / CCPA)
Because BlurPen collects no personal file data, most data-subject rights (access, erasure, portability) do not apply to file processing. For ad-related data collected by the ad network, your rights are governed by that network's privacy policy (e.g., Google Privacy Policy).
You may opt out of ad personalisation at any time by clicking "Manage Ad Preferences" in the footer.
7. Contact
Questions about this Privacy Policy? Contact us at privacy@blurpen.com.