Privacy policy
Your files stay on this device
PDFForge is a local-only PDF utility. Document bytes, extracted text, metadata, filenames, and passwords stay on your device. This policy describes the actual product behaviour as of 14 September 2026.
What we do not collect
- PDF files, images, generated downloads, or ZIP archives.
- Camera frames, OCR text, or gallery photos used by Scan Document.
- Document text, thumbnails, metadata, filenames, or passwords.
- Accounts, profiles, cookies for tracking, or payment information.
- Analytics events, advertising identifiers, or error reports that contain file content.
How processing works
Tools run inside this browser tab and a same-origin Web Worker. Files are read with the browser File API, processed in memory, and saved through a local download. There is no document upload API and no server-side document store.
Temporary browser data
Previews use short-lived object URLs. Those URLs, worker jobs, and in-memory buffers are released when you clear files, finish or cancel a job, leave the page, or close the tab. IndexedDB, localStorage, and sessionStorage are not used for documents. If you opt in on Private Recipes, this browser may store step settings only (never PDFs, filenames, or passwords) under a non-document localStorage key. The service worker may cache the public app shell and hashed static assets only.
Service worker cache
PDFForge never caches uploaded documents, generated files, extracted text, passwords, or PDF/ZIP responses. Navigations are fetched from the network when available. If the network is unavailable, the precached shell and offline page can still load.
Hosting and logs
Indexed tool pages use paths such as `/tools/merge-pdf`, so a host can log which public tool you opened. Document bytes are still never uploaded. Use `/workspace#merge-pdf` when you want the tool name to stay in the URL hash, which browsers do not send to the host. PDFForge application code does not log filenames, document text, metadata, or passwords.
Camera and on-device OCR
Scan Document may open the camera only after you click Open Camera, and only in a secure context (HTTPS or localhost). Video tracks stop when you cancel, hide the tab, leave the page, or finish. Gallery photos, warped pages, and OCR text stay in memory. OCR models are loaded from this site on demand and are not precached by the service worker. There is no cloud OCR. Camera permission is limited to this origin; microphone remains disabled.
Local document hashes
Document Integrity fingerprints files with Web Crypto in this tab (SHA-256 or SHA-512). Compare and Verify Hash only show whether two digests match. Hashes you copy stay in your clipboard. PDFForge does not upload files or hashes and does not store them after you leave the page.
Browser extensions
A per-request Content-Security-Policy nonce blocks page scripts that are not issued by PDFForge. If an extension still injects extension-scheme resources, PDFForge shows a warning. Use a clean browser profile without extensions for sensitive files.