Skip to content

Is it safe to upload a PDF to an online converter? The honest answer

By the getPDF team · Published 11 October 2026

The short answer

Usually nothing goes wrong, but you cannot verify it. An online converter uploads your PDF to its servers, converts it there and deletes it after a while, typically 1 to 2 hours by its own policy. For a public document that is fine. For a contract, a payslip or an ID, the safer choice is a converter that runs on your device, so the file never leaves it, and that claim is one you can test by turning Wi-Fi off.

Try it here, nothing is uploaded

PDF · any size · many at once

The converter above runs in your browser: the PDF is read and the Word file is written on your device, and nothing is uploaded. It rebuilds the text, headings, lists and tables for editing; it does not copy the exact layout, and it says so before you start.

What happens to a PDF you upload

From the moment you click “Upload” on a typical online converter:

  1. The file travels to the company’s server, encrypted on the way by HTTPS.
  2. It is stored there, readable, because the server has to open it to convert it.
  3. The server converts it and stores the result for you to download.
  4. Both are deleted later, after the window the policy names.
  5. Around that, things you do not see: server logs, backups, monitoring tools, and the cloud providers the company rents its servers from (sub-processors, in GDPR terms).

None of this is sinister. It is how server software works. The point is only that steps 2 to 5 happen on machines you cannot inspect, under a policy you cannot audit.

From each service’s own privacy policy, security page or tool page, checked on 11 October 2026.

Service How long files are kept Where files are processed Who runs it
iLovePDF Deleted within 2 hours of processing; signed documents follow its signing service’s own terms Its own servers, within the European Economic Area as a rule ILOVEPDF S.L., Barcelona, Spain
Smallpdf Deleted after 1 hour, per its safety page; its privacy notice promises that only to signed-in users and says “a reasonable period after last opened” otherwise Servers in Ireland, per its own help pages Smallpdf AG, Zürich, Switzerland
Adobe Acrobat online Deleted unless you sign in to save; no time given Adobe’s servers; its privacy policy names the US and India as main processing locations Adobe Inc., US (Adobe Systems Software Ireland outside North America and Japan)
PDF24 (website) Deleted within 1 hour of processing Data centres in the EU Geek Software GmbH, Germany
Sejda (website) Tool pages say deleted after 2 hours; publicly shared files after 7 days Its servers; cloud providers listed in the US and Europe A Dutch company, per its privacy policy
PDF2Go No time stated on the pages we checked Servers in Europe, run by a hosting company under a data processing agreement QaamGo Web GmbH, Radolfzell, Germany

Read the table for what it is: these are honest, published policies from established companies, and short retention windows are good practice. They are also promises. The question is not whether they are true, but whether you need to rely on them for this particular file.

When it does go wrong

Policies describe intentions; breaches happen anyway. On 11 July 2024, Cybernews published research showing that 2 online PDF sites, PDF Pro and Help PDF, had left 89,062 user-uploaded files in an Amazon S3 storage bucket open to anyone: passports, driving licences, certificates and contracts among them (“Online PDF maker leaks user-uploaded documents”). The researchers contacted the operators several times without an answer, and the files were still exposed when the article went out.

Nobody who uploaded those files did anything unusual. They used a free converter the way millions of people do every day. That is the realistic shape of the risk: rare, not your fault, and impossible to undo once it happens.

A different risk comes from sites that only pretend to be converters. In March 2025 the FBI’s Denver field office warned that criminals use free online converter sites to install malware and to collect data from the files people submit. Those sites are a separate problem with their own warning signs, covered in fake PDF converter sites.

How to judge any converter in 2 minutes

Before you upload anything that matters, check 5 things:

  1. Who runs it. A legal notice or imprint with a company name, a country and a registration number. No company name is a bad sign on its own.
  2. The retention claim, in numbers. “Deleted after 1 hour” is a policy; “your files are safe” is not.
  3. Where processing happens. A named region or country, and for work files, whether data leaves the EU.
  4. For work files: a data processing agreement. Without one, your employer’s data protection rules usually rule the tool out for client or staff files; the GDPR guide explains why.
  5. Whether it uploads at all. Run the tool once, turn Wi-Fi off, run it again. A tool that keeps working never needed to send your file. The Wi-Fi off test shows how to confirm it in the browser’s network panel.

When uploading is genuinely fine

Most PDFs people convert are not secret: a public form, a published report, a menu, slides you are about to put online anyway, a document with no names or numbers in it. For those, an established online converter with a clear policy is a perfectly reasonable choice, and its retention window does not matter.

The line worth drawing is personal data: anything with someone’s name next to an account number, a salary, a diagnosis, an ID number or a signature. Those are the files where “probably fine” is not good enough.

The alternative: convert without uploading

Converters that run in the browser do the conversion on your device. The page loads its code, the file is read from your disk into the browser tab, and the result is saved back to your disk. Nothing is uploaded because there is nothing to upload to.

On getPDF that is every tool, and it is checkable rather than promised. The site’s content security policy only allows connections to its own address, the engine downloads with the first file you drop, and after that you can turn Wi-Fi off and keep working. The only message the site sends is a counter after each job: the tool id, success or failure, and a rough duration and size bucket. The privacy page explains the architecture in plain words.

For images rather than a document:

Try it here, nothing is uploaded

PDF · any size

The honest part

A local converter removes 1 risk, the copy on someone else’s server. It is not better at everything.

  • Layout. Our PDF to Word rebuilds the content for editing: headings, paragraphs, lists, tables, pictures. It does not reproduce the exact look of a page with columns and placed text boxes. Some server-based converters copy layouts more closely. If you need the layout and the file is not sensitive, they may be the better tool.
  • Your device does the work. A very large file needs memory in your browser tab. Compressing our 203 MB, 100-page test scan took about a minute and up to about 1.4 GB of memory on a mid-range laptop; a phone may not give a tab that much.
  • Your device still holds the result. The converted file lands in your Downloads folder like any other download. On a shared computer, delete it afterwards.

The short version: upload what you would not mind being read, and keep the rest on your device.

Questions

How long do online PDF converters keep my file?

By their own policies, checked on 11 October 2026: iLovePDF deletes within 2 hours of processing, Smallpdf after 1 hour on its safety page, a promise its privacy notice makes only to signed-in users, PDF24 within 1 hour, Sejda's tool pages say 2 hours. Adobe's online tools say files are deleted unless you sign in to save them, without a time.

Can the converter company read my document?

Technically, yes: the file has to be readable on their server to be converted. Reputable services limit who can access it and say so in their policies. What you cannot do is check that from outside.

Is a converter with HTTPS safe?

HTTPS protects the file on its way to the server. It says nothing about what happens on the server, how long the file stays there or who can reach it. Every serious converter has HTTPS; it is the minimum, not the answer.

Are converters that run in the browser really different?

Yes, if the claim is true: the file is processed on your device and never sent. You can check it in a minute by running the tool once, turning Wi-Fi off and running it again.

The tools for this job