Per tool, by name

Most of these never send your file anywhere.

Not "we delete it quickly" — it never leaves your browser at all for seventeen of the eighteen tools. You can check that yourself: open any of them, turn off your network, and it still works. The list below names every tool and which of the two it is.

17 of 18 tools upload nothing Built from the same table the tools read

Draft. This describes what the software does today, accurately. It has not been reviewed by a lawyer.

The short version

  • Seventeen of eighteen tools upload nothing. The work happens in your own browser. Nothing is sent, so there is nothing for us to keep, lose or be asked for.

  • The one that uses a server holds your file in memory for the operation and discards it the moment the result returns. It is never written to a database.

  • No account is required for any tool. An account stores four things and no files — listed below.

  • No advertising and no tracking on a tool page, and no cookies for any of it. Three pages are the exception and they are named here: /collect-documents, /collect-documents-qr-code and /collect carry Meta's advertising pixel, which sets a cookie and tells Meta you were here — that is how we learn whether an advert brought somebody who then made a list. It is on those three pages and nowhere else: not on a tool page, not on the page somebody uploads a document to, and never anywhere a file is. Nothing on the page reports what you did with your file. Page views are counted, by a company named below, and that count is built so it cannot carry a document, a file name, or the code in a Collect link. The only other companies holding anything of yours are that counter and our sign-in provider, named below — and Google, only if you choose to sign in with a Google account — and the sign-in one only if you choose to make an account.

What an account stores

Four fields. There is no row for files, because there are no files to put in one.

  • email
  • password hash
  • today's counter
  • plan

Signing in is handled by Supabase, on servers in Mumbai, India. They hold your email address and the hash of your password, and nothing else — no file, no filename, and no record of which tool you used ever reaches them. Your run count stays on our own server, with the compression it counts.

If you signed in with Google, Google also knows you have an account here — that is what "sign in with Google" means, and it is the only thing they learn. They see no file, no filename, and nothing about which tool you used. Signing in with an email address and a password instead keeps them out of it entirely.

Deleting your account removes that row. Every tool keeps working afterwards at 5 server runs a day, exactly as it does for someone who never signed up.

What we count

Six things, all about the tools and none about your file. Your file is not on this list and cannot be: there is no column for a name, a size or a page count.

  • which tool ran
  • which tool ran before it
  • one of five words for the kind of file — pdf, image, data, text or other
  • the day it happened, and nothing finer
  • a random tag for this browser, with no name or email attached
  • searches that found nothing, so we can see which tool to build next

None of these counts is sent while you are working on a file. They are written down in your own browser and go out later, from the homepage or your dashboard, where no file is involved. Turning the counter off in your account settings also throws away anything still waiting to be sent.

The daily allowance

One tool on this site uses our server, so it is the only one with a daily limit — 5 runs without an account, 20 with one. Counting that means keeping three things:

  • which account it was — or a random tag your browser made up, if you have none
  • the day, in UTC, and nothing finer
  • how many server runs you have had that day

The tag is not the one the counter above uses, and the two are never joined: turning the counter off must not quietly reset what you are owed today. The other 17 tools are not counted here at all, because nothing about them costs us anything to run. This is also easy to get around — clearing your site data gives you a fresh tag and a fresh 5. We would rather say so than pretend a number in your own browser is a lock.

The honest half

  • A step that carries a file into the next tool writes it to your browser's own storage for the length of one page load, then deletes it on arrival. Nothing leaves the device, but "nothing is stored" would be the wrong word for that moment.

  • The one server tool sends your file over the network. It is encrypted in transit and discarded after the run, but if that is not acceptable for a document, use one of the 17 browser tools instead — they are listed by name on this page.

  • Your browser and your network provider still see what they always see. We cannot make claims about anything outside this page.

  • Cropping and watermarking hide, they do not delete. Content outside a crop frame is still inside the file. Both of those tools say so on the page.

Every tool, and where it runs

Generated from the same table the tools themselves read, so it cannot fall out of step with the software.

Your device 17 tools

Never uploaded. Closing the tab is the delete button.

  • Merge PDF
  • Split PDF
  • Sign PDF
  • Watermark PDF
  • Page Numbers
  • Crop PDF
  • Rotate PDF
  • OCR Scanned PDF
  • Convert Image
  • Resize Image
  • PDF to Word
  • Images to PDF
  • PDF to Images
  • PDF to Text
  • File Converter
  • QR Code
  • Text Tools
Our server 1 tool

Held in memory for the run, then discarded. Never stored.

  • Compress PDF

What leaves a tool page

From a tool page, your file never does. That is the whole product and it has not changed. Collect is the one exception on this site and it has its own entry below. Everything else that leaves every page is listed here — all of it, as you would find it in the Network tab.

  • Which tool you opened, and whether it finished. The tool's name — one of eighteen — and nothing else. Not your file's name, not its size, not how many pages it had. There is no field for any of those.

  • How fast the page loaded. This one is not ours: our hosting provider adds it to every page automatically. It measures the page, never the file.

Neither can carry anything about your document, because neither is given anywhere to put it. We would rather write this down than have you find it yourself.

Who else sees anything

  • Umami counts page views. They are a company, and they hold a record of which pages were opened, when, and roughly where from. No cookies, and nothing that follows you to another site — the count cannot tell one visit from the same person twice.

  • What they are given: the page address with any code removed, the page's title, your screen size and language, and the site you arrived from. Your country and browser are worked out from the request, as they are by every server you ever contact.

  • Four moments, if you use Collect: that a list was made, that its link was taken away, and that a document went — or did not, with one word for why, from a fixed list like “too big” or “no connection”. Not which documents, not whose list, not what was in it. There is no field for any of those.

  • Three questions, on the two Collect pages that ads point at: a strip at the foot of the page may ask what you do, how you collect documents today, and whether you will try this. Every answer is one of four buttons, and the button’s own word is the whole of what goes — there is nothing to type, and no box to type it in. That the strip was shown is counted too, so the answers have something to be a share of. Closing it sends nothing more.

  • What they are never given: your file, anything inside it, its name or size, your email address, or the code and key in a Collect link. A link you were sent arrives with all of that taken off, so nobody there can open a list or send anything into one.

Collect, which is the exception

  • The document itself, once. When somebody answers a Collect link, their browser prepares the document and sends it to us. We hold it in memory only long enough to put it into one email, and drop it. It is never written to a disk here and never opened.

  • Resend, who deliver that email. The document passes through them on its way to the inbox that asked for it, the same way any email does. We use them for nothing else on this site.

  • The list, for 30 days. What the request asked for, a tick against each line, the name of whoever made it, and the address the documents go to. After 30 days that is removed and the link stops working.

  • A list you chose to save, until you remove it. A saved list is what you asked for — its name, its lines and what each one should arrive as — with no link and nobody answering it. It is the one thing on this site kept without a deadline, because the point of it is next year. No document is ever part of one. Remove it from your dashboard and it is gone.

  • One line if the page breaks. If a script on the Collect pages throws, the browser sends us the error message and the file it came from, so we find out rather than you closing a page that did nothing. The message is stripped first — no file name, no address, no link, and no number longer than three digits — and it goes to our own server, not to anybody else.

  • Not the file's name, and not what is inside it. The attachment is named after the line it answers. If the sender's phone reads a number off a card, that reading happens on their phone and is never sent here.

How to reach us

Write to [email protected]. That includes asking what an account holds, asking for it to be deleted, or telling us something on this page is wrong — the last one is the most useful mail you can send.

It reaches a person, not a ticketing system, so a reply may take a day or two.

Stop guessing. Start with a preview.

Free every day. No card, no signup, no watermark.