Privacy Policy

Last updated 2026-10-01

Legebla ("we", "us") provides a document API that turns HTML, web pages, templates and Markdown into PDFs or images, and processes PDF files you supply. This page explains what happens to your data when you use it.

Zero data retention, by default

The HTML, Markdown, URLs, template data and PDF files you send, and the resulting PDF or image, are processed in memory, in an isolated, ephemeral worker, for the duration of a single request. Nothing is written to a database or persistent disk by default. Once the response is sent, the render worker and its contents are discarded.

Files, fetched pages and delivery to your storage

PDF files you upload or link to for merge or split are processed the same way and are not kept. Pages and files we fetch from a URL you give us are fetched at request time and are not kept after the request. If you include credentials for a page (headers, cookies or HTTP Basic auth), they are sent only to that page's own origin, never included in errors or warnings, and removed from our logs. If you use upload, the finished file is sent from memory straight to the pre-signed URL you provide, on storage you control; we do not keep the file or create a download link for it. Once delivered, the file is held by your storage provider under your own arrangements with them.

What we do log

We keep operational logs and usage counters needed to run the service and bill accounts correctly (timestamps, endpoint called, page count, response size, HTTP status, API key identifier). If you use upload, logs record the destination's host and path, never the signature or query string. Logs do not include your document's HTML, Markdown, URL contents, template data, uploaded files or any credentials you send.

Where processing happens

Rendering infrastructure is EU-hosted. We do not operate region-selectable or data-residency-guaranteed deployments today — if that is a hard requirement for you, contact us before integrating.

Payments

Paid subscriptions are handled by Polar.sh, acting as Merchant of Record. Polar processes your payment details and billing information directly — we do not receive or store full card numbers. See Polar's own privacy policy for how they handle payment data.

Account & contact data

Creating an account requires an email address, used for authentication, service notices and support. We do not sell or share this data with third parties for marketing.

Your rights

You can request access to, correction of, or deletion of your account data at any time by emailing support@legebla.com. Because we operate zero data retention by default, there is nothing to delete on the document side by design.

Changes to this policy

We'll update the date at the top of this page when this policy changes materially. Continued use of the API after a change constitutes acceptance of the update.

How we handle your documents — zero data retention

Every render runs in an isolated, ephemeral worker — your HTML, URLs, files and data exist only in memory for the duration of that single request and are discarded immediately after the result is returned or delivered. There is no document database and no long-lived storage in the render path, by default.

Questions? Email support@legebla.com.