Skip to content

PDF privacy and protection: the complete guide

By the getPDF team · Published 11 October 2026

The short answer

A PDF leaks in 4 places: the visible text, hidden content under drawn boxes and in older saved versions, the metadata, and the copy that lands on a converter’s server when you upload. Each has 1 fix: a user password with AES-256 encryption locks opening, true redaction removes content instead of covering it, a metadata pass strips names and dates, and a tool that runs on your device never makes a server copy at all. Every tool on this site works that way: nothing is uploaded, and you can check by turning Wi-Fi off after a tool’s first run.

The 4 places a PDF betrays you

Most people picture 1 risk: someone reads the file who should not. In practice a PDF carries confidential data in 4 distinct layers, and each one fails in its own way.

A PDF file opened into 4 stacked layers. Layer 1, visible content, is handled by redaction. Layer 2, hidden content such as text under drawn boxes and older page versions, is handled by true redaction. Layer 3, metadata such as author and dates, is handled by metadata removal. Layer 4, the copy on a converter’s server, exists only after an upload; a tool that runs on your device never creates it.1. Visible contentnames, numbers, the text itselfredact what must not travel2. Hidden contenttext under boxes, older page versionstrue redaction removes it too3. Metadataauthor, dates, editing history, XMPstrip it in 1 pass4. The server copyexists only after an uploada local tool never makes oneLayers 1 to 3 travel inside the file. Layer 4 is the one you cannot see or delete yourself.
The 4 risk layers of 1 PDF, and the tool that handles each. The fourth layer only exists if you upload the file somewhere.

Layer 1 is the visible content. The account number in the table, the salary in paragraph 3. If the wrong person must not read it, it has to come out of the file before the file travels, and that is redaction’s job.

Layer 2 is content you cannot see but a reader can find. Text sitting under a drawn black box. An invisible text layer from OCR. Older versions of pages that an editor left inside the file when it saved changes by appending instead of rewriting. This layer is where most famous privacy failures happen, because a visual check tells you nothing about it.

Layer 3 is the metadata. Author names (usually the login name, stamped in automatically), creation and modification dates, the software used, and the XMP store where some editors keep history entries. You never typed most of it, and it travels with every copy.

Layer 4 is the copy on someone else’s server. It appears the moment you upload the file to an online converter, and from then on its fate is governed by that company’s retention policy, backups and logs, none of which you can inspect. It is the only layer you cannot fix after the fact, which is why the honest answer is not to create it.

The rest of this guide takes the layers in turn: what a password protects, how real redaction works, what the metadata pass removes, why the server copy is the risk people underestimate, and how to send the finished file.

Passwords: what a user password protects, and what an owner password only requests

PDF has 2 kinds of password, and they could hardly be more different.

A user password encrypts the file. With AES-256, the cipher current PDFs use, the content is mathematically unreadable without the password: not hidden, not flagged, unreadable. Brute-forcing the key is off the table, so the password itself is the only way in, and also the weak point. A short guessable password undoes strong encryption; 4 random words hold up.

An owner password does not encrypt anything a reader sees. It sets permission flags on an openable file: no printing, no copying, no editing. Those flags are a request. Polite viewers like Acrobat honour them; plenty of tools ignore them. That is why a PDF can open without asking anything and still refuse to print: it carries owner-only protection, which is an honour system, not a wall.

User password Owner password
Opening the file Blocked without the password Opens freely
How it works AES-256 encryption of the content Permission flags on the file
“No printing”, “no copying” Not its job Sets the flags, viewers decide
Protects against Anyone without the password Honest viewers only
Use it for Real secrecy “Please do not change this”

Set both in the protect tool below: drop the file, choose a user password for secrecy, tick permissions if you also want them, save. The encryption is applied on your device; the password never exists anywhere but your machine and your head.

Try it here, nothing is uploaded

PDF · any size

The reverse direction exists too: Unlock PDF removes a password from a file when you type that password in. It never cracks one, and we say so on the tool page: a tool that opens files you cannot open yourself would be a break-in tool, and AES-256 cannot be cracked anyway. If the file only carries owner-password restrictions, unlocking lifts those on a file that is legitimately yours; check what a file actually carries with Inspect first.

Redaction: covering is not removing

The most dangerous button in PDF privacy is the black rectangle in a normal editor. It looks like redaction. It is a shape, drawn on top of text that is still in the file. Select the area underneath, copy, paste into a text editor, and the “redacted” words appear in full. This exact mistake has repeatedly turned published government reports and court filings into news stories, because readers copied the text out from under the boxes within hours of publication.

True redaction deletes. When you mark an area in Redact PDF and apply, the tool removes what is under the box, not just from view but from the file: the text letter by letter, the image pixels, drawings, links, notes and form field values in the area. And because editors can leave older versions of pages inside a file when they save by appending, the saved result is tested by searching every byte of the output, older page versions included. That check is part of the tool’s automated tests. The getPDF editor writes every save in full for the same reason, so even a plain edit leaves no older page version behind; the one exception is a digitally signed file, which is appended to so its signature stays valid, and the editor says so. You can repeat the spirit of the test yourself in 2 minutes: open the saved file, select all, copy, paste into a plain text editor, and confirm the removed words do not come back.

Redaction is visible by design. A reader sees that something was removed, and for a bank statement going to a landlord or a contract going outside the company, that is exactly right. If nobody may know something was removed at all, redaction is the wrong tool and rewriting the document is the honest one.

Finding everything to redact is its own problem: account numbers hide in footers repeated on 40 pages, in tables, in filled form fields. The redaction tool includes a finder for personal data that lists the email addresses, phone numbers, IBANs, card numbers, US Social Security numbers, UK National Insurance numbers and VAT numbers it detects in the file (dates too, if you tick them), each one ready to mark for removal. It shortens the search; the judgement about what must go stays yours, because no pattern recognises a name or “the tenant in flat 4”.

Redact PDFRemoves content, not just a black box. Free, runs on your device.

Metadata: what the file says about you when nobody opens it

Metadata is the layer people skip because no page shows it. A typical PDF exported from an office suite carries the author (the logged-in user’s name), a title, the creating application and version, and creation and modification dates. Many files carry a second store, XMP, where some editors keep editing history. Together they can reveal who wrote a document, at which employer, with which tools, and when it was really last changed, which is exactly the set of facts an anonymous submission, a tender or a published report should not disclose.

Two tools cover this layer. Inspect reads a file without changing it and shows what it carries: the document properties (author, title, subject, the programs, the dates in readable form), permissions, encryption, digital signatures, document scripts, and attachments by file name. It is the 10-second look before anything leaves your machine. Remove PDF metadata then strips the lot in 1 pass: author, title, dates, creator application, the XMP store, which quick cleaners often miss, and hidden application data. The pages themselves are untouched.

Remove metadataAuthor, dates, XMP, hidden data. Free, runs on your device.

A half-measure to avoid: clearing the visible Author field in some editors leaves the XMP copy behind. That is the gap the 1-pass removal exists to close. Inspect lists the document properties, not the XMP packet, so for the XMP side rely on the removal tool’s result, which counts the packets it removed.

The server copy: the risk you cannot audit

Here is how most online PDF tools work, in their own words: you upload the file, their servers process it, and the copy is deleted after a while. iLovePDF says within 2 hours; Smallpdf’s safety page says 1 hour, while its privacy notice promises that only to signed-in users (both checked on 11 October 2026). For that window, and in whatever backups and logs surround it, your contract exists on infrastructure you cannot see, under promises you cannot verify.

Usually nothing goes wrong. Sometimes it does: in July 2024, Cybernews researchers found that 2 converter sites, PDF Pro and Help PDF, had left more than 89,000 uploaded files open in cloud storage, among them passports, driving licences and contracts. That is not told here to frighten anyone; it is a dated fact that sets the stakes. The people who uploaded those files did nothing unusual. They used a free converter the way millions do.

There is also a legal layer. Under GDPR, uploading a file that contains someone else’s personal data to a converter is processing personal data, and the converter becomes a processor working for you. Doing that with a client’s contract or an applicant’s CV through a random free tool, with no data processing agreement, is often simply not allowed at work. (This guide explains the rules in plain words; it is not legal advice.)

The clean way out is to not create the server copy at all. Every getPDF tool runs entirely on your device: the file is opened, processed and saved in your browser, and the only things fetched from the server are the page and the engine that does the work. That claim is checkable, not a promise:

  1. Load the tool page and run it once on any file. The engine (4.6 MB) downloads with that first file, and from then on your browser keeps it.
  2. Turn Wi-Fi off, or switch to airplane mode.
  3. Drop your file and run the tool again. It still works, because there is nothing to send and nowhere to send it.

For the technical reader there is a stronger guarantee: the site’s content security policy is set to connect-src 'self', which means the browser itself refuses any connection except to the site’s own origin. An upload is not merely avoided; it is technically impossible, and the privacy page explains the whole architecture in plain words. The one thing the site does send is an anonymous counter after a tool finishes: the tool id, success or failure, a duration bucket and a file-size bucket. Never a file, never a file name.

Sending the file: realistic options, in order of effort

Protection ends at your machine’s edge unless the sending step holds up too. The realistic options, from least to most effort:

  1. Send less. Redact what the recipient does not need before anything else. A landlord needs your name, the period and the balance, not your card number and every purchase. Reducing what travels protects more than armouring it.
  2. Strip the metadata. The 10-second pass above, so the file does not carry your author name and editing dates along with it.
  3. Flatten completed forms. Flatten PDF turns form fields and notes into fixed page content, so a recipient cannot un-fill your answers or lift a pasted signature onto another document. Be clear about what flattening is not: it is not encryption and it is not redaction. The text is still readable and copyable; covered content is not removed.
  4. Encrypt with a user password and send the password by a different channel: a text message or a call, never the same email thread. This protects against a wrong forward, a stolen inbox and interception in one move.
  5. For recurring exchanges, an expiring link on a drive you already use beats attachments, because access can be revoked and logged. For signatures with legal weight, see the signing and filling guide.

For most confidential files, options 1, 2 and 4 together take under 5 minutes and cover the threats that actually occur.

What no PDF tool protects you from

This is the part tool pages usually skip.

The recipient. Once the right person opens the file, every protection has done its job and is finished. They can save it, forward it, print it. If they can see a page, they can screenshot it, and no permission flag prevents that. Trust in the recipient is a decision no software makes for you.

A weak password. AES-256 moves the entire fight to the password. A pet’s name with a year on the end falls to guessing in hours; the encryption around it is irrelevant. Length beats cleverness: 4 random words, stored in a password manager at the moment you set them.

A forgotten password. We do not crack passwords, for your own files or anyone else’s, because the same tool would be a break-in tool, and because against AES-256 it would not work. If a password is gone, the realistic paths are the sender, the original source or a backup.

Permission flags against a determined reader. “No printing” and “no copying” are requests. They organise honest workflows; they stop nobody who has decided not to be stopped. If a document must provably not change, you need a certificate signature, not flags.

What you do after the file is clean. A perfectly redacted, metadata-free, encrypted PDF posted to the wrong channel is still a leak. Tools remove data from files; they do not make the judgement about where the file may go.

Everything above runs on your device, free, with no account and no task limits. The honest architecture is the point: you should not have to trust a privacy promise when you can run a tool once, turn Wi-Fi off and watch it keep working.

Questions

Does a password on a PDF really keep people out?

A user password does: it encrypts the file with AES-256, and without the password the content is unreadable. An owner password does not; it only sets permission flags (no printing, no copying) that viewers may ignore. If secrecy matters, set a user password.

Is drawing a black box over text enough to redact it?

No. In a normal editor the box is a shape placed on top; the text underneath stays in the file and copies out with select-all. True redaction deletes the text, the image pixels and the objects under the box, and you can verify it: select all in the saved file and paste into a text editor.

Are my files uploaded when I use these tools?

No. Every tool runs in your browser, on your device. You can check it yourself: run a tool once, so its engine is in your browser, then turn Wi-Fi off, and the tool still works. The site's content security policy only allows connections to itself, so an upload is technically impossible, as the privacy page explains.

Can getPDF remove a password I forgot?

No. Unlock removes a password you type in; it never cracks one. AES-256 cannot be brute-forced, so no honest tool can open the file without the password. The realistic paths are the sender, the original source (a bank portal, an HR system) or a backup.

Does removing metadata change the pages of my PDF?

No. The pages, text and images stay byte for byte as they were. What goes is the data about the file: author name, title, creation and modification dates, the software that made it, and the XMP store where editing history can live.

The tools for this job