Skip to content

Are online PDF tools safe?

Last updated August 3, 2026

Mostly, yes — and that is the boring answer. The large PDF sites are competent operations that encrypt in transit, delete on a schedule and have far more to lose from a breach than you do. Treating them as reckless would be wrong.

The useful question is different: does this tool upload my file, and did it tell me? Most do, and most do not say so anywhere you would see it. For a holiday itinerary that is irrelevant. For a term sheet, a bank statement, a medical letter or an employment contract, it is a decision you would probably want to make deliberately.

Check any tool in two minutes

This works on whatever you use, including Penstead. No account, no special software.

  1. Open the tool’s page and press F12 (or Cmd+Option+I on a Mac).
  2. Go to the Network tab and tick Preserve log.
  3. Drop in a PDF and run whatever the tool does.
  4. Sort the requests by Size, largest first.

If a request appears that is roughly the size of your file, the file was uploaded. If nothing of that size leaves, the work happened on your machine. It is that blunt — a document cannot be processed on a server it never reached.

Questions worth asking a tool that does upload

  • How long is the file kept, and is that written down anywhere binding?
  • Is deletion automatic, or does it depend on someone running a job?
  • Is the file reachable by an unguessable link, and does that link expire?
  • Who at the company can read it, and would you know if they did?

A tool with good answers is a fine choice. A tool with no answers is not necessarily bad, but you are trusting rather than knowing, and it is worth being clear which of those you are doing.

What Penstead does, stated plainly

Run the test above on us and you will see nothing of your file leave for most of what we do. Editing, merging, splitting, organising, cropping, compressing, OCR, redaction, form filling and signing something yourself all run inside the browser tab. That is a property of how it is built, not a policy we could quietly change — and it is also why those tools have no daily cap: they cost us nothing to provide.

Three things do use a server, and we would rather say so here than have you find out:

  • Converting Office files to PDF. Rendering a .docx faithfully needs a real document engine. The file is sent, converted, and discarded immediately — never stored.
  • Share links. The document is stored so the person you send it to can open it.
  • Signature requests. Same reason — your signers have to be able to open the document, so it is held behind an unguessable link that is never listed or searchable, and you can delete it whenever you like.

The privacy policy says which feature is which, and it is the same list. If a page here ever claims something runs locally when the network tab says otherwise, that is a bug worth telling us about.

One thing that is genuinely unsafe, whoever you use

Drawing a black box over text and calling it redacted. The words stay in the file, selectable by anyone who opens it, whether the tool ran on your machine or on a server — this has embarrassed governments and law firms repeatedly. Here is how to test it in thirty seconds, and it is worth doing before you send a redacted document to anybody.