PDF300 Guides

Is it safe to use online PDF tools? What happens to your files

By LeDeuxions · Published 28 September 2026

“Online PDF tool” covers two very different things: tools that process your file on your own computer, and tools that upload it to someone else’s. Knowing which one you are using is most of the answer.

Two kinds of online tool

Browser-based tools download code to your browser, and that code does the work on your own device. The PDF is read from your disk into the browser tab, processed in memory, and written back to your disk as a download. It is never sent over the network. Modern JavaScript libraries such as pdf.js (from Mozilla) and pdf-lib make this possible for many everyday jobs: merging, splitting, rotating, adding page numbers, converting pages to images.

Server-based tools upload your file to a remote computer, process it there, and send back the result. Some jobs genuinely need this: OCR engines, Office-document converters and high-quality compressors are large programs that do not run well in a web page. The trade-off is that your file exists, at least briefly, on a machine you do not control.

Neither is automatically unsafe. But they carry different risks, and a site should tell you which is which.

How to tell which one you are using

Be wary of blanket claims like "your files never leave your device" on a site that also offers OCR or Word-to-PDF conversion; those almost always need a server.

What can go wrong with server tools

Most reputable services delete uploaded files after a short time, but the risks worth thinking about are:

What can go wrong with browser tools

Browser tools remove the upload risk, but they are not magic:

A simple rule for sensitive documents

For passports, ID cards, medical records, contracts and bank statements: prefer browser-based tools whenever one exists for the job. Use a server tool only when you need something only a server can do, and when the site tells you what happens to the file. Remove what you do not need to share before uploading anywhere — Redact permanently blacks out areas in your browser, and metadata editing clears author names and software details hidden in the file.

How PDF300 handles your files

We would rather say exactly what happens than make a claim that sounds better.

Browser tools — never uploaded. Merge, Split, Rotate & reorder, Crop, N-up, Page numbers, Watermark, Signature & stamp, Redact, PDF to Image, Image to PDF, PDF to Text, Compress (image mode) and Metadata editing all run in your browser with pdf.js, pdf-lib and JSZip. The file is not sent to us or anyone else.

Server tools — uploaded, processed, deleted. High-quality compress, Compress to target size, OCR and searchable PDF, Set password, Remove password, Remove metadata, Repair, and the server versions of page numbers, N-up and watermark, plus Office to PDF, run on a server we operate ourselves. Files travel over HTTPS through Cloudflare's network to that server. Each file is processed in a temporary folder (or in memory) that is removed as soon as the result is returned. We do not store copies, and we do not look at the contents. The size limits are 100 MB per file, or 30 MB for OCR.

What we do record. A simple page-view counter records which page was visited, without cookies and without storing your IP address. Server tools are free for a limited number of uses per day; to count those, the gateway keeps a per-day counter keyed to your IP address or an anonymous browser key, which expires within about a day. Advertising, where it appears, is served by Google and uses cookies as described in our privacy policy.

Each tool page on PDF300 states whether that tool runs in your browser or on the server, so you can choose before you add a file.

Checklist

  1. Does the site say, per tool, whether files are uploaded?
  2. If uploaded: does it say when files are deleted?
  3. Is there a privacy policy and a way to contact the operator?
  4. Can you do the job in the browser instead?
  5. Have you removed information the recipient does not need?
← All guides