Start with the data path, not the slogan
“Private” is not a single technical feature. A useful comparison follows the document from the moment you choose it to the moment you delete it:
| Question | Why it matters | How to check |
|---|---|---|
| Where do the bytes go? | An upload gives a third party a copy | Watch the Network tab while the tool runs |
| How long are they kept? | Retention decides how long a copy can leak | Read the retention and deletion policy |
| Is an account required? | An account ties documents to an identity | Try the tool without signing in |
| What are the limits? | Limits show where processing happens | Look for size, page or daily caps |
| Who else is involved? | Analytics, ads and integrations are third parties | Read the privacy policy and the Network tab |
| Can you verify the output? | You should be able to check it and keep the original | Open the result before deleting anything |
A five-minute test you can run yourself
- Open the tool’s page and your browser’s developer tools (usually F12 or right-click, Inspect), then the Network tab.
- Clear the list, then add a harmless test PDF, not a real document.
- Run the operation and watch the list. Sort by size.
- If a request roughly the size of your file is sent out, the tool uploaded it. Small requests for analytics, fonts or scripts are ordinary.
- Repeat with the tool’s other features, since one feature may be local and another not.
The test shows where the file goes, but it cannot show what a server does with data you did send, which is why the retention policy still matters.
What “local” does not cover
- The page itself. A site can still use analytics, advertising and hosting logs, which are about visits, not document contents.
- Your device. A shared or unlocked computer, a browser extension that reads pages, or an unsecured downloads folder can expose a file that never left your device.
- The result. The output file is saved on your device, and any copy you send on is out of the tool’s hands.
A worked example: what FreePDFKit says, and does not say
FreePDFKit’s privacy policy says that most PDF operations run in your browser and that, for a locally processed file, the document contents are not received, stored or inspected on its servers. It also says what does involve third parties: aggregate page and device information through Google Analytics, advertising cookies when ads are enabled, and ordinary hosting and error logs, and that it does not intentionally send PDF contents, file names or document text to analytics or advertising providers. Contact-form messages are kept to answer them, so the policy asks you not to send confidential documents there.
It is also upfront about limits that matter for trust: there is no OCR, Sign PDF adds a visual signature rather than a legal digital one, and the Word, Excel, PowerPoint and Repair tools are marked best-effort, so their output should be reviewed. Use that kind of plain statement as the standard when you read any tool’s policy, and run the test above rather than relying on the page’s own claims.
Which kind of tool for which document
| Situation | Reasonable choice |
|---|---|
| A confidential contract or HR file, simple task | A browser-local tool you have tested, or offline desktop software |
| A very large scan or a heavy conversion | Desktop software, or a cloud tool if its data policy is acceptable |
| OCR or a conversion the browser cannot do | A desktop app or a cloud service with clear retention terms |
| A legally binding signature | A certified e-signature service |
| Regulated records with audit or retention rules | A managed enterprise system |
Questions to ask before processing a sensitive PDF
- Does the privacy policy separate local operations from optional integrations?
- Does the page say whether files are uploaded?
- Are account, size and usage limits visible before you start?
- Can you check the result without overwriting the original?
For the mechanics behind these answers, see browser-local processing versus cloud upload, the decision table, and the iLovePDF and Smallpdf comparisons.
People also ask
Common questions
Are browser-local PDF tools completely offline?
Not always. The page and its libraries have to load first. After that, a given operation may run on your device without sending the document anywhere, but some features fetch extra files on demand, such as fonts for non-Latin scripts.
Are cloud PDF tools unsafe?
Not automatically. Cloud tools can have strong security, but the document does leave your device. Review how long it is kept, how it is deleted, who can access it and whether an account is required.
What is the most important privacy question to ask?
Where do the document’s bytes go, how long are they kept, and who can access them? Everything else follows from that.
How can I check what a PDF site sends?
Open your browser’s developer tools, go to the Network tab, run the tool on a harmless test file, and look for large requests that carry the file. Small requests for analytics or fonts are normal; a request the size of your file is an upload.
Is a browser tool more private than desktop software?
Not necessarily. Desktop software that works offline keeps a file as private as a local browser tool does. The browser’s advantage is convenience: nothing to install.
Why can local tools have lower file limits?
The browser uses your device’s memory and processor. FreePDFKit accepts files up to 256 MB, or 128 MB on browsers that report 4 GB of memory or less, and Office conversions up to 25 MB.