Privacy

Why you should not upload contracts to a free PDF site

The upload takes four seconds and the download takes two more. What happens in between is the part nobody shows you, and for the document types people most often need converted — agreements, statements, ID scans, medical letters — it is the worst possible category of file to hand over.

There is nothing irrational about using a free online tool. For a pub quiz handout or a holiday itinerary, uploading it costs you nothing worth protecting. The problem is that the same convenient button sits in front of a signed NDA, a passport scan and a client contract, and those are not the same document at all.

What follows is not a warning to avoid the internet. It is the specific list of what happens to a file after you click Upload, which document types make that a bad trade, and a two-minute procedure you can use on any converter — including this one — to see for yourself where the processing happens.

What actually happens when you click Upload

The mechanics are worth knowing, because they explain why "we delete your file after two hours" is not the reassurance it sounds like.

Your file leaves your machine as an HTTP request. For a small file it is one POST with the document in the body; for a large one it is a chunked multipart upload. Either way the bytes are now on hardware you do not control, and they arrive as a complete copy.

  • The file is written to disk or object storage so that a worker process can open it. That write is usually the longest-lived artifact of the whole operation.
  • It acquires an address. Object storage keys and temporary URLs are generated for the job, and they are frequently derived from the original filename or a predictable identifier.
  • It passes through infrastructure you cannot see. A load balancer, a queue, one or more worker containers, a temporary directory, a CDN for delivery. Each of those is a place a copy can exist.
  • Requests and errors get logged. Web servers log paths, sizes and timestamps by default, and application error trackers often capture request metadata, occasionally including payload fragments.
  • Backups and disaster-recovery snapshots outlive the retention window. This is the part that makes "deleted after two hours" a statement about one storage layer rather than about the data.

None of this requires bad intent. It is simply what a server-side processing service is. The point is narrower and harder to argue with: a deletion promise cannot undo a transfer. Once the file has been uploaded, the only question left is how well someone else protects it, and how long a copy survives in a place you were not told about.

The business model matters too. A service that processes files for strangers at zero charge is either funded by advertising, funded by converting a fraction of users into subscribers, or funded by what it can learn from the files. The free tier of a typical converter is deliberately narrow — a watermark, two operations per hour, a mandatory sign-up — and those limits are the lever that produces the subscription. That is not a conspiracy; it is just worth remembering that the file you uploaded is the asset the business is built on.

What is inside the document you are handing over

The general advice to "be careful with sensitive files" is useless because it does not say which files those are. Here is the concrete list for the documents people most often need to merge, split, sign or compress.

  • A commercial contract. Both parties' legal names and addresses, bank account and IBAN details for payment, fee schedules, salary or day rates, IP assignment clauses and the definition of what counts as confidential. In a single file you have someone else's personal and financial data as well as your own.
  • A signed agreement. On top of the above: signature images, initials and sometimes a scanned passport page attached as identity verification.
  • An identity document. Passport, national ID card or driving licence. For identity theft this is the single most valuable document that exists, which is exactly why complete sets of them are the first thing taken in a breach.
  • A medical letter or insurance claim. Health information, which data protection law treats as a special category precisely because misuse is hard to undo.
  • A payslip, bank statement or tax return. Account numbers, national insurance or social security numbers, employer, income, and enough detail to answer security questions.
  • Someone else's contract. A client agreement or supplier quotation you hold under confidentiality. This is the awkward one: the clause may be breached by you the moment you upload it, not by the tool.

The risks, grouped

Taken one at a time these can each sound theoretical. They are more useful read as five separate ways the same four-second upload can go wrong.

  • Confidentiality and professional duties. If you work in law, accountancy, HR or medicine, your obligations to keep client material confidential usually do not distinguish between "sent to a colleague" and "uploaded to an anonymous web service". Sending client documents to a third party without a processor agreement can itself be a reportable incident.
  • Data protection law. In practice you are the controller of the document. Handing it to an unknown processor engages the obligations that come with that: a written processing agreement, appropriate security, and rules on transferring data to another country. A free anonymous tool offers you none of those, because it is not party to an agreement with you at all.
  • Trade secrets and commercial exposure. Pricing, margins, supplier terms, unreleased product plans. This is the category that quietly costs companies the most, because the loss is invisible until a competitor uses it.
  • Identity theft. A single ID scan is enough to start an account in someone's name. Aggregate thousands of them in one small website's storage and it becomes a target that is worth attacking and easy to sell.
  • Silent persistence. The failure mode people do not anticipate is that the file stays reachable. Misconfigured storage buckets, permissive CORS rules and object URLs that get crawled are a recurring cause of documents turning up in search engine caches.

Proportionality still applies. A restaurant menu is not a secret. The rule is not "never upload anything" — it is "match the handling of the document to what it actually contains", and for signed, identifying or confidential material the answer is that it should never leave your device.

How to check any converter in two minutes

You do not have to take anyone's word for how a tool works, including ours. Browsers give you the evidence directly. Do this once on any converter you are considering.

  • 1. Press F12, open the Network tab, and clear it so the list starts empty.
  • 2. Start the operation and watch the requests appear. Do not look at the pretty progress bar; look at the list.
  • 3. Find the request that carries your file. Click each request and look at two columns: the method, and the size of the request body (labelled Request Payload, Form Data or Size). A POST or PUT whose body is measured in megabytes is your document leaving the machine.
  • 4. Look at the order of events. If the large upload happens first and the processing happens after a server round trip, the work is happening remotely no matter what the page says. If no request carries a meaningful body while the CPU works, the processing is local.
  • 5. Test the claim with your largest file. This is the decisive one. A site that processes locally will not transfer an 80 MB scan anywhere, because there is nowhere to transfer it to.
  • 6. Check for the upload endpoint itself. Filter the request list by your own domain. On a genuinely local tool, every request to that origin is a GET for a page, script or stylesheet. There is no endpoint to POST a document to, so there is no code path that could send one.
  • 7. Read the retention clause, then read the subprocessor list. Find how long files are kept and who else handles them. If there is no stated retention period, assume the worst case.

One thing to expect while you do this. On this site — and on any ad-supported free site — you will see third-party requests in that Network panel. They are advertising, and they are how the tools are paid for. That is a real privacy consideration and it is stated in the privacy policy, including how to switch personalised advertising off. It is a different fact from your file being uploaded, and the distinction is easy to hold onto once you look for the specific thing: a request whose body contains your document.

What you genuinely give up by keeping files local

Local processing is not free of trade-offs, and a guide that pretends otherwise is not worth reading. Three costs are real.

  • Optical character recognition on poor scans. Turning a bad photocopy into searchable text needs real OCR models. It is not a browser job today, and no amount of marketing changes that.
  • High-fidelity PDF to Word conversion. Reconstructing the layout of a complex document as editable Word content is a hard server-side problem. Client-side conversions produce something, but not a faithful reconstruction.
  • Memory limits. Everything runs on your device, so a 500-page scan on a five-year-old phone will be slow, and a very large file can fail where a server with more memory would succeed.

Those are the things you pay. What you keep is the document itself, which for a signed agreement or an ID scan is very often the more valuable side of the trade.

Frequently asked questions

Is it safe to upload a PDF to an online converter?
It depends on what is in the PDF and how the tool is built. For a public flyer, nothing is at stake. For a contract, an ID scan or a medical document, assume that any site which processes the file server-side creates a copy you cannot account for — then verify whether it actually does, using the Network tab check above.
Does HTTPS protect my uploaded file?
It protects the transfer, not what happens afterwards. Encryption in transit means nobody can read the file while it travels. It says nothing about whether the receiving server writes it to disk, how long that copy lives, or who has access to it. Hence the phrase "encrypted in transit" sits comfortably next to "retained for 24 hours".
Can a site really delete my file when it says it does?
It can delete the copy it knows about. From outside, you cannot verify that, and the usual architecture leaves copies in logs, temporary directories and backups that outlive the retention window. The honest framing is that deletion promises are unverifiable from the outside, so the safe assumption is that an uploaded file persists in some form.
Is a paid converter safer than a free one?
Not automatically. Payment funds servers and staff; it does not by itself change where your file goes or how long it is kept. What matters is the architecture: whether the processing happens on your device, whether a processing agreement exists, and what the retention policy says. Read those rather than the price.
What if my contract includes a confidentiality clause?
Then uploading it to a third-party service may be a breach by you, regardless of what the service does with it. Uploading a client document to an unnamed website is the kind of disclosure confidentiality clauses and professional codes are written to prevent. Use a local tool, or ask the other party first.
How do I OCR a scan without uploading it?
Use the OCR built into your scanner or a desktop application that runs the model locally. Many multi-function printers ship with an OCR driver, and desktop PDF suites do this offline. Where you cannot avoid a web service, redact the identifying sections first — but be aware that redaction is often reversible if it is done incorrectly.

Do it here, in your browser

Related guides

Every tool on this site processes files on your device. Read the no upload policy to verify that yourself in the Network tab.