PDFresh guide
Browser-Side PDF Tools and Privacy
Learn what browser-side PDF processing means, what no-upload workflows protect, what they do not guarantee, and what aggregate analytics may collect.
Short answer
Browser-side means the selected PDF is loaded and processed by JavaScript in your browser for supported workflows. The PDF file, file name, thumbnails, extracted text, and output PDF are not sent to PDFresh analytics.
How this differs from upload tools
Server-side PDF tools upload a document to a remote service for processing. PDFresh's supported workflows load local JavaScript and PDF libraries, process the selected file in the page, and create a browser download.
Trust still matters
Browser-side processing reduces document exposure to the site operator, but it still requires trusting the page code, the browser, the device, and installed extensions. It does not protect a compromised computer.
Same-origin libraries
PDFresh serves PDF.js, the PDF.js worker, and pdf-lib from its own /vendor/ paths instead of loading them from public CDNs at runtime. That makes the runtime dependency easier to inspect and less dependent on third-party script hosts.
How to check generally
A technical user can open browser DevTools, choose the Network tab, select a PDF, and verify that PDF contents are not posted to a remote endpoint during the workflow. Normal page assets and optional aggregate analytics events are different from sending the document.
Analytics boundary
Anonymous aggregate events can record page views and tool actions such as export_success. They are designed not to include PDF contents, file names, extracted text, thumbnails, output files, full referrer URLs, cookies, or persistent browser IDs.
Tested example
During a local review, selecting and exporting a small PDF loaded same-origin scripts and worker files, then created a browser download. The workflow did not require uploading the source PDF to PDFresh.
Limits
Browser-side processing does not guarantee compatibility with every PDF, prevent infrastructure logs from existing for normal page requests, audit browser extensions, or prove that every future tool will have the same data flow. Read the specific tool page and Privacy Policy when that distinction matters.