The file you are least likely to think about
Think about the last time you used an online PDF tool. Almost certainly it was for something boring: splitting a 40-page contract to send one clause, rotating a scanned page so it printed straight, merging two documents. Boring is exactly why it is dangerous — nobody performs a risk assessment for a tax return they are splitting into quarters.
A PDF is a container format. It can hold a full identity document: name, date of birth, address, national ID number, signature, bank details, and a photo of a face. It is also a format that basically every library can read, which makes it a favourite target for automated scrapers. A single uploaded payslip can be enough to answer an application question, and it never expires.
What "we delete your file after 1 hour" actually means
Most conversion services are honest in their privacy policy and still unsafe in practice, because the risk is architectural rather than intentional:
- The file exists in temporary storage. It is written to disk so the worker can read it, then deleted on a timer. During that window it is reachable by anything with bucket access — a misconfigured policy, a third-party SDK, a rogue operator, or an unrelated vulnerability in the storage layer.
- It crosses the network in plaintext to the wrong people. Even with HTTPS, the operator's infrastructure sees the content. "Encrypted in transit" protects you from passive eavesdroppers, not from the server you uploaded to.
- Derivatives multiply. A conversion produces new files: thumbnails, page images, text extractions, OCR output, search indexes for the upload feature most products have. Your document is now in five places instead of one.
- Logs record that it happened. IP address, user agent, file size, filename. Your filename alone frequently contains your full name and the document type.
- Retention outlives the promise. Backups, snapshots and CDNs do not honour a one-hour deletion window. Deleting the primary object is not deleting the data.
None of this requires a malicious company. It is what happens when you hand a sensitive file to infrastructure you cannot inspect.
The local-first alternative
A PDF library compiled to WebAssembly can do the same work with the file never leaving your machine. That is exactly how PDF Studio works: the document is read through the browser File API into a typed array, every operation runs against that buffer, and the result is handed back to you as a download. There is no upload request to intercept, because the code never makes one.
What that buys you concretely:
- Works offline. Once the page has loaded, disconnect. Merge, split, rotate and reorder still function, because nothing is being fetched.
- No third party sees the page count. Not the size, not the name, not the fact that you have a document at all.
- Inspectable by definition. The processing runs in the tab you are already reading this article in. There is no server-side code path you have to trust on faith.
- Same tool, same cost, no account. The same engine that powers commercial desktop software is available here for free because the compute is yours.
Related local-first tools worth knowing: Document Redactor for blacking out personal data before you send a document to someone else, PDF Compress to shrink a file for email limits, and PDF Table to Excel when the real goal is the numbers rather than the document.
Where local-first does not help
Being straight about the boundary: this approach protects the file, not everything around it. A page running heavy client-side code still talks to its origin server, so a compromised site or a malicious browser extension remains a risk. And if a document is password-protected with a weak password, local processing does not make it unbreakable — the password is still the weakest link. The gain is specific and real: your document bytes are never transmitted to a third party, which removes the single most common leak path.
A habit worth building
Before the next upload, ask one question: would I be comfortable if the file were read by someone I will never meet? If the answer is no, look for a tool that runs locally first. For most people the deciding factor is not capability — the local versions now cover merging, splitting, signing, compression, OCR and conversion. The deciding factor is simply that one of the two options hands your identity to a stranger and the other does not.