Privacy Policy

Last updated: January 15, 2024

1. File Processing

All PDF processing happens locally in your browser.

When you use PDFTools:

  • Files are read from your device using the File API
  • Processing occurs using WebAssembly libraries (pdf-lib, PDF.js, Tesseract.js)
  • Results are generated as Blob objects in memory
  • Downloads happen via object URLs — no server involved

At no point are your files uploaded to our servers or any third-party servers.

2. Data We Don't Collect

Your PDF files or document content
Personal information (name, email, etc.)
IP addresses (beyond standard server logs)
Third-party analytics or behavioral tracking
Cookies for marketing or advertising
Device fingerprints

3. Data We May Process

The only requests that leave your own files' processing path:

  • Google Fonts: web fonts (Geist) are fetched from fonts.googleapis.com / fonts.gstatic.com
  • Library and worker files: PDF.js, Tesseract.js (including OCR language data) and pdf-lib are served from this site itself — no third-party CDN is contacted
  • Usage events: anonymous product events (tool name, success/failure, duration — never file names or content) are sent to this site's own endpoint; no third-party analytics is involved

None of these contain your document data.

4. No Server-Side Processing

Every tool on this site — including password protection (AES-128) and PDF to Word conversion — processes your files directly in your browser. Nothing is uploaded to any server, now or ever, so no file data is covered by a server-side section of this policy.

If server-side features are ever added, they will be optional and clearly labeled, and we will update this policy before launching them, committing to:

  • Files uploaded via HTTPS to our processing servers only with your explicit action
  • Files processed and deleted immediately after (within minutes)
  • No files stored permanently
  • You will be clearly informed before any upload occurs
  • You can choose the client-side alternative where one exists

5. Third-Party Services

PDFTools does not integrate with:

  • Google Analytics / Google Tag Manager
  • Facebook Pixel / Meta tracking
  • Advertising networks
  • Customer data platforms
  • Error tracking services (Sentry, etc.)

If we add analytics in the future, it will be privacy-friendly (Plausible, Fathom, or self-hosted) and clearly disclosed.

6. Cookies & Local Storage

The only cookie PDFTools sets is a first-party language-preference cookie (one year), saved when you pick a language so the site remembers your choice. It contains no identifiers and is never sent for tracking.

We may use localStorage or sessionStorage for:

  • User preferences (theme, language)
  • Temporary UI state (recent tools)

This data never leaves your browser and can be cleared at any time.

7. Children's Privacy

PDFTools is not directed at children under 13. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us.

8. Security

We implement security best practices:

  • HTTPS enforced via HSTS
  • Content Security Policy headers
  • No external scripts beyond required libraries
  • Regular dependency updates
  • Subresource integrity for CDN assets

9. Your Rights

Since we don't collect personal data, there's no data to access, rectify, or delete. If you have questions about your privacy, contact us.

10. Changes to This Policy

We may update this policy as features evolve. Changes will be posted here with a new “Last updated” date. Significant changes will be announced on the homepage.

11. Contact

Questions about this policy? See our Contact page, which lists the channels that actually exist in this build.