Is it safe to upload a PDF to an online converter? The honest answer
By the getPDF team · Published 11 October 2026
The short answer
Usually nothing goes wrong, but you cannot verify it. An online converter uploads your PDF to its servers, converts it there and deletes it after a while, typically 1 to 2 hours by its own policy. For a public document that is fine. For a contract, a payslip or an ID, the safer choice is a converter that runs on your device, so the file never leaves it, and that claim is one you can test by turning Wi-Fi off.
Try it here, nothing is uploaded
The converter above runs in your browser: the PDF is read and the Word file is written on your device, and nothing is uploaded. It rebuilds the text, headings, lists and tables for editing; it does not copy the exact layout, and it says so before you start.
What happens to a PDF you upload
From the moment you click “Upload” on a typical online converter:
- The file travels to the company’s server, encrypted on the way by HTTPS.
- It is stored there, readable, because the server has to open it to convert it.
- The server converts it and stores the result for you to download.
- Both are deleted later, after the window the policy names.
- Around that, things you do not see: server logs, backups, monitoring tools, and the cloud providers the company rents its servers from (sub-processors, in GDPR terms).
None of this is sinister. It is how server software works. The point is only that steps 2 to 5 happen on machines you cannot inspect, under a policy you cannot audit.
What 6 popular converters say about your file
From each service’s own privacy policy, security page or tool page, checked on 11 October 2026.
| Service | How long files are kept | Where files are processed | Who runs it |
|---|---|---|---|
| iLovePDF | Deleted within 2 hours of processing; signed documents follow its signing service’s own terms | Its own servers, within the European Economic Area as a rule | ILOVEPDF S.L., Barcelona, Spain |
| Smallpdf | Deleted after 1 hour, per its safety page; its privacy notice promises that only to signed-in users and says “a reasonable period after last opened” otherwise | Servers in Ireland, per its own help pages | Smallpdf AG, Zürich, Switzerland |
| Adobe Acrobat online | Deleted unless you sign in to save; no time given | Adobe’s servers; its privacy policy names the US and India as main processing locations | Adobe Inc., US (Adobe Systems Software Ireland outside North America and Japan) |
| PDF24 (website) | Deleted within 1 hour of processing | Data centres in the EU | Geek Software GmbH, Germany |
| Sejda (website) | Tool pages say deleted after 2 hours; publicly shared files after 7 days | Its servers; cloud providers listed in the US and Europe | A Dutch company, per its privacy policy |
| PDF2Go | No time stated on the pages we checked | Servers in Europe, run by a hosting company under a data processing agreement | QaamGo Web GmbH, Radolfzell, Germany |
Read the table for what it is: these are honest, published policies from established companies, and short retention windows are good practice. They are also promises. The question is not whether they are true, but whether you need to rely on them for this particular file.
When it does go wrong
Policies describe intentions; breaches happen anyway. On 11 July 2024, Cybernews published research showing that 2 online PDF sites, PDF Pro and Help PDF, had left 89,062 user-uploaded files in an Amazon S3 storage bucket open to anyone: passports, driving licences, certificates and contracts among them (“Online PDF maker leaks user-uploaded documents”). The researchers contacted the operators several times without an answer, and the files were still exposed when the article went out.
Nobody who uploaded those files did anything unusual. They used a free converter the way millions of people do every day. That is the realistic shape of the risk: rare, not your fault, and impossible to undo once it happens.
A different risk comes from sites that only pretend to be converters. In March 2025 the FBI’s Denver field office warned that criminals use free online converter sites to install malware and to collect data from the files people submit. Those sites are a separate problem with their own warning signs, covered in fake PDF converter sites.
How to judge any converter in 2 minutes
Before you upload anything that matters, check 5 things:
- Who runs it. A legal notice or imprint with a company name, a country and a registration number. No company name is a bad sign on its own.
- The retention claim, in numbers. “Deleted after 1 hour” is a policy; “your files are safe” is not.
- Where processing happens. A named region or country, and for work files, whether data leaves the EU.
- For work files: a data processing agreement. Without one, your employer’s data protection rules usually rule the tool out for client or staff files; the GDPR guide explains why.
- Whether it uploads at all. Run the tool once, turn Wi-Fi off, run it again. A tool that keeps working never needed to send your file. The Wi-Fi off test shows how to confirm it in the browser’s network panel.
When uploading is genuinely fine
Most PDFs people convert are not secret: a public form, a published report, a menu, slides you are about to put online anyway, a document with no names or numbers in it. For those, an established online converter with a clear policy is a perfectly reasonable choice, and its retention window does not matter.
The line worth drawing is personal data: anything with someone’s name next to an account number, a salary, a diagnosis, an ID number or a signature. Those are the files where “probably fine” is not good enough.
The alternative: convert without uploading
Converters that run in the browser do the conversion on your device. The page loads its code, the file is read from your disk into the browser tab, and the result is saved back to your disk. Nothing is uploaded because there is nothing to upload to.
On getPDF that is every tool, and it is checkable rather than promised. The site’s content security policy only allows connections to its own address, the engine downloads with the first file you drop, and after that you can turn Wi-Fi off and keep working. The only message the site sends is a counter after each job: the tool id, success or failure, and a rough duration and size bucket. The privacy page explains the architecture in plain words.
For images rather than a document:
Try it here, nothing is uploaded
The honest part
A local converter removes 1 risk, the copy on someone else’s server. It is not better at everything.
- Layout. Our PDF to Word rebuilds the content for editing: headings, paragraphs, lists, tables, pictures. It does not reproduce the exact look of a page with columns and placed text boxes. Some server-based converters copy layouts more closely. If you need the layout and the file is not sensitive, they may be the better tool.
- Your device does the work. A very large file needs memory in your browser tab. Compressing our 203 MB, 100-page test scan took about a minute and up to about 1.4 GB of memory on a mid-range laptop; a phone may not give a tab that much.
- Your device still holds the result. The converted file lands in your Downloads folder like any other download. On a shared computer, delete it afterwards.
The short version: upload what you would not mind being read, and keep the rest on your device.
Questions
How long do online PDF converters keep my file?
By their own policies, checked on 11 October 2026: iLovePDF deletes within 2 hours of processing, Smallpdf after 1 hour on its safety page, a promise its privacy notice makes only to signed-in users, PDF24 within 1 hour, Sejda's tool pages say 2 hours. Adobe's online tools say files are deleted unless you sign in to save them, without a time.
Can the converter company read my document?
Technically, yes: the file has to be readable on their server to be converted. Reputable services limit who can access it and say so in their policies. What you cannot do is check that from outside.
Is a converter with HTTPS safe?
HTTPS protects the file on its way to the server. It says nothing about what happens on the server, how long the file stays there or who can reach it. Every serious converter has HTTPS; it is the minimum, not the answer.
Are converters that run in the browser really different?
Yes, if the claim is true: the file is processed on your device and never sent. You can check it in a minute by running the tool once, turning Wi-Fi off and running it again.
The tools for this job
Keep reading
- Fake PDF converter sites: 6 signs to spot them before you clickA fake PDF converter pushes .exe downloads, extensions and malware.
- Prove a PDF tool is local: the Wi-Fi off test, and what the network panel showsPDF tools without uploading: turn Wi-Fi off and a truly local tool keeps working.
- GDPR and online PDF tools: what is allowed at work, in plain wordsGDPR and online PDF tools: uploading a client PDF to a converter is processing personal data.
- Online PDF tools at work: a rule you can defendA workable rule for online PDF tools at work: what never goes to a converter, what may, and a 4-line policy IT can adopt.
- PDF privacy and protection: the complete guideWhat a PDF password really protects, how true redaction works, what metadata leaks, and how to send files safely.