Skip to content

Principles

What we build by.

These are working rules, not values on a wall. When a feature conflicts with one of them, the feature changes or doesn’t ship.

Humans stay in control

Technology should extend what people can do without taking away their say in it.

Software should make the decision easier to make, not make it for you without asking. Automation that acts on your behalf should be visible, reversible and easy to switch off.

In practice

  • Nothing irreversible happens without a clear action from you
  • Originals are never overwritten; you save a new copy
  • Automated steps show what they changed

Privacy by architecture

Don’t collect sensitive information the product doesn’t need.

The strongest privacy promise is the one the architecture enforces. If a feature can run on your device, it should. Data we never receive cannot leak, be sold or be demanded from us.

In practice

  • Process on the device where practical
  • No accounts unless a feature requires one
  • No analytics or tracking by default

Seen in PDF Editor

There is no server that could receive a document. Editing, OCR and redaction run in the browser tab.

Transparency over claims

Where practical, you should be able to inspect how a product behaves.

A privacy policy is a promise. A published list of network connections that you can check in your own browser is evidence. We prefer evidence.

In practice

  • Document every network connection
  • Show what is stored, and let you delete it
  • Publish known limitations next to features

Seen in PDF Editor

Every network connection the app can make is listed, and the security policy is shown live.

Useful before impressive

Solve the problem first. Add novelty only when it makes the result better.

A feature earns its place by making the work better, not by making a better demo. Sometimes that means leaving the fashionable feature out.

In practice

  • Start from a real task someone has
  • Prefer the boring technology that works
  • Leave out features that trade away the core promise

Seen in PDF Editor

No cloud “chat with your PDF” feature, on purpose: it would mean uploading your document.

No artificial friction

Don’t weaken software on purpose to sell the upgrade.

Watermarks, page limits, trial timers and nag screens are friction added deliberately. If something is limited, it should be because of a real constraint, and we should say which one.

In practice

  • No watermark that disappears if you pay
  • No invented limits on size or usage
  • Every limitation has a stated reason

Seen in PDF Editor

No paid tier, no watermark, no page or file size limits. Donating unlocks nothing.

Engineering is the product

Security, reliability, accessibility and performance come first, not last.

People feel quality even when they cannot name it: the page that loads instantly, the control that works with a keyboard, the file that opens everywhere. That work is the product, not polish on top of it.

In practice

  • Strict security policies enforced by the browser
  • Keyboard and screen reader support as a requirement
  • Standard, portable output formats

See the principles applied.