Privacy
Why you should not upload contracts to a free PDF site
The upload takes four seconds and the download takes two more. What happens in between is the part nobody shows you, and for the document types people most often need converted — agreements, statements, ID scans, medical letters — it is the worst possible category of file to hand over.
There is nothing irrational about using a free online tool. For a pub quiz handout or a holiday itinerary, uploading it costs you nothing worth protecting. The problem is that the same convenient button sits in front of a signed NDA, a passport scan and a client contract, and those are not the same document at all.
What follows is not a warning to avoid the internet. It is the specific list of what happens to a file after you click Upload, which document types make that a bad trade, and a two-minute procedure you can use on any converter — including this one — to see for yourself where the processing happens.
What actually happens when you click Upload
The mechanics are worth knowing, because they explain why "we delete your file after two hours" is not the reassurance it sounds like.
Your file leaves your machine as an HTTP request. For a small file it is one POST with the document in the body; for a large one it is a chunked multipart upload. Either way the bytes are now on hardware you do not control, and they arrive as a complete copy.
- The file is written to disk or object storage so that a worker process can open it. That write is usually the longest-lived artifact of the whole operation.
- It acquires an address. Object storage keys and temporary URLs are generated for the job, and they are frequently derived from the original filename or a predictable identifier.
- It passes through infrastructure you cannot see. A load balancer, a queue, one or more worker containers, a temporary directory, a CDN for delivery. Each of those is a place a copy can exist.
- Requests and errors get logged. Web servers log paths, sizes and timestamps by default, and application error trackers often capture request metadata, occasionally including payload fragments.
- Backups and disaster-recovery snapshots outlive the retention window. This is the part that makes "deleted after two hours" a statement about one storage layer rather than about the data.
None of this requires bad intent. It is simply what a server-side processing service is. The point is narrower and harder to argue with: a deletion promise cannot undo a transfer. Once the file has been uploaded, the only question left is how well someone else protects it, and how long a copy survives in a place you were not told about.
The business model matters too. A service that processes files for strangers at zero charge is either funded by advertising, funded by converting a fraction of users into subscribers, or funded by what it can learn from the files. The free tier of a typical converter is deliberately narrow — a watermark, two operations per hour, a mandatory sign-up — and those limits are the lever that produces the subscription. That is not a conspiracy; it is just worth remembering that the file you uploaded is the asset the business is built on.
What is inside the document you are handing over
The general advice to "be careful with sensitive files" is useless because it does not say which files those are. Here is the concrete list for the documents people most often need to merge, split, sign or compress.
- A commercial contract. Both parties' legal names and addresses, bank account and IBAN details for payment, fee schedules, salary or day rates, IP assignment clauses and the definition of what counts as confidential. In a single file you have someone else's personal and financial data as well as your own.
- A signed agreement. On top of the above: signature images, initials and sometimes a scanned passport page attached as identity verification.
- An identity document. Passport, national ID card or driving licence. For identity theft this is the single most valuable document that exists, which is exactly why complete sets of them are the first thing taken in a breach.
- A medical letter or insurance claim. Health information, which data protection law treats as a special category precisely because misuse is hard to undo.
- A payslip, bank statement or tax return. Account numbers, national insurance or social security numbers, employer, income, and enough detail to answer security questions.
- Someone else's contract. A client agreement or supplier quotation you hold under confidentiality. This is the awkward one: the clause may be breached by you the moment you upload it, not by the tool.
The risks, grouped
Taken one at a time these can each sound theoretical. They are more useful read as five separate ways the same four-second upload can go wrong.
- Confidentiality and professional duties. If you work in law, accountancy, HR or medicine, your obligations to keep client material confidential usually do not distinguish between "sent to a colleague" and "uploaded to an anonymous web service". Sending client documents to a third party without a processor agreement can itself be a reportable incident.
- Data protection law. In practice you are the controller of the document. Handing it to an unknown processor engages the obligations that come with that: a written processing agreement, appropriate security, and rules on transferring data to another country. A free anonymous tool offers you none of those, because it is not party to an agreement with you at all.
- Trade secrets and commercial exposure. Pricing, margins, supplier terms, unreleased product plans. This is the category that quietly costs companies the most, because the loss is invisible until a competitor uses it.
- Identity theft. A single ID scan is enough to start an account in someone's name. Aggregate thousands of them in one small website's storage and it becomes a target that is worth attacking and easy to sell.
- Silent persistence. The failure mode people do not anticipate is that the file stays reachable. Misconfigured storage buckets, permissive CORS rules and object URLs that get crawled are a recurring cause of documents turning up in search engine caches.
Proportionality still applies. A restaurant menu is not a secret. The rule is not "never upload anything" — it is "match the handling of the document to what it actually contains", and for signed, identifying or confidential material the answer is that it should never leave your device.
How to check any converter in two minutes
You do not have to take anyone's word for how a tool works, including ours. Browsers give you the evidence directly. Do this once on any converter you are considering.
- 1. Press F12, open the Network tab, and clear it so the list starts empty.
- 2. Start the operation and watch the requests appear. Do not look at the pretty progress bar; look at the list.
- 3. Find the request that carries your file. Click each request and look at two columns: the method, and the size of the request body (labelled Request Payload, Form Data or Size). A POST or PUT whose body is measured in megabytes is your document leaving the machine.
- 4. Look at the order of events. If the large upload happens first and the processing happens after a server round trip, the work is happening remotely no matter what the page says. If no request carries a meaningful body while the CPU works, the processing is local.
- 5. Test the claim with your largest file. This is the decisive one. A site that processes locally will not transfer an 80 MB scan anywhere, because there is nowhere to transfer it to.
- 6. Check for the upload endpoint itself. Filter the request list by your own domain. On a genuinely local tool, every request to that origin is a GET for a page, script or stylesheet. There is no endpoint to POST a document to, so there is no code path that could send one.
- 7. Read the retention clause, then read the subprocessor list. Find how long files are kept and who else handles them. If there is no stated retention period, assume the worst case.
One thing to expect while you do this. On this site — and on any ad-supported free site — you will see third-party requests in that Network panel. They are advertising, and they are how the tools are paid for. That is a real privacy consideration and it is stated in the privacy policy, including how to switch personalised advertising off. It is a different fact from your file being uploaded, and the distinction is easy to hold onto once you look for the specific thing: a request whose body contains your document.
What you genuinely give up by keeping files local
Local processing is not free of trade-offs, and a guide that pretends otherwise is not worth reading. Three costs are real.
- Optical character recognition on poor scans. Turning a bad photocopy into searchable text needs real OCR models. It is not a browser job today, and no amount of marketing changes that.
- High-fidelity PDF to Word conversion. Reconstructing the layout of a complex document as editable Word content is a hard server-side problem. Client-side conversions produce something, but not a faithful reconstruction.
- Memory limits. Everything runs on your device, so a 500-page scan on a five-year-old phone will be slow, and a very large file can fail where a server with more memory would succeed.
Those are the things you pay. What you keep is the document itself, which for a signed agreement or an ID scan is very often the more valuable side of the trade.
Frequently asked questions
Is it safe to upload a PDF to an online converter?
Does HTTPS protect my uploaded file?
Can a site really delete my file when it says it does?
Is a paid converter safer than a free one?
What if my contract includes a confidentiality clause?
How do I OCR a scan without uploading it?
Do it here, in your browser
Related guides
Every tool on this site processes files on your device. Read the no upload policy to verify that yourself in the Network tab.