How long is it kept?
Look for a specific number — '1 hour', '24 hours'. Vague phrases like 'files are removed regularly' mean the answer is 'we'd rather not say'.
Merging a contract? Compressing a scan of your passport? Most free online PDF tools process your document on someone else's machine — and their retention policy is a paragraph nobody reads. Here's what actually happens, and what to use when the file matters.
It feels like the conversion happens in your browser. Usually it doesn't.
The moment you drop a file into the upload box, it travels to the provider's server. Browser-based tools that process files locally exist, but they're the minority — and almost none of them say so on the button you clicked.
Conversion, merging, OCR and compression run on their machines. That means the plain, unencrypted contents of your document exist in their memory and usually on their disk, however briefly.
Most services keep uploads for somewhere between one hour and several days, so you can re-download the result. Some say exactly how long. Many don't say at all, and 'files are deleted automatically' is not the same as 'files were never copied'.
Deletion claims are unverifiable from the outside. That's fine for a restaurant menu. It's a different decision for a signed contract, a bank statement, or a scan of your ID.
A public PDF you downloaded from a government site
A product brochure or price list already published online
Lecture slides, recipes, manuals, anything you'd email to a stranger
Files with no names, addresses, account numbers or signatures
Signed contracts, invoices and anything with a bank account on it
Passport, ID card and driving licence scans
Medical results, insurance claims, tax filings
Anything covered by a client NDA or GDPR at work
If a tool can't answer all three in plain language on its own site, treat it as a public noticeboard.
Look for a specific number — '1 hour', '24 hours'. Vague phrases like 'files are removed regularly' mean the answer is 'we'd rather not say'.
Server-side processing means the provider can read the file in the clear. Only client-side (in-browser) processing or end-to-end encryption removes that.
The jurisdiction on the imprint decides who can compel access to stored files. For work documents this is often the deciding factor, not the feature list.
None of these are PDF converters — that's the point. They solve the part the converter can't: keeping the file readable only by you, before and after you work on it. Pick by what you're protecting.
Encrypts files on your own machine before anything is uploaded. If you must move a sensitive PDF through the cloud, this is the layer that makes the cloud irrelevant.
End-to-end encrypted storage from the Proton Mail team, under Swiss jurisdiction. Sharing links are encrypted too, which is the usual leak point when you send a document on.
Straightforward cloud storage with an optional client-side encryption add-on, and a one-off lifetime plan instead of a subscription. Good when you want the files organised, not just hidden.
There is no single winner — there's a right answer per document.
For public documents, generally yes — the practical risk is low and the convenience is real. For anything with personal or contractual data, the honest answer is that you cannot verify what happens to the file after you upload it, so the decision should be based on how bad it would be if the contents leaked, not on how likely you think that is.
Reputable ones do delete uploads on a published schedule, and some are explicit about it. The problem isn't dishonesty, it's that deletion is unverifiable from outside and the file existed in plaintext on their systems in the meantime. If a service doesn't state a retention period at all, that silence is your answer.
Don't upload them to a free web tool. Identity documents are the single most valuable thing in a leaked dataset, and once a scan is out it cannot be revoked like a password. Use a desktop application, or encrypt the file locally before it touches any cloud.
Not automatically. Many extensions upload to the same backend as the website, and an extension additionally has permissions on every page you visit. Judge it on the same three questions: retention, who can read the file, and which jurisdiction applies.
Almost certainly, and that's fine. The point isn't to make every task complicated — it's to notice the small number of documents each year that genuinely shouldn't be handed to an unknown server, and treat those differently.
Set up one encrypted place for the documents that matter. After that, using a free converter for the harmless stuff is a decision instead of an accident.