pdfmakeTOOLKIT
Legal

Privacy

This policy explains how your documents and personal information are handled when you use this site. Most tools process your file on your own device and never transmit it. The sections below set out what that covers, what information is recorded, and what rights you have.

The short version

Most tools on this site open your file in your browser and work on it there. The file is not sent to us, no copy is kept, and the data is released from memory when the tab is closed. A contract merged here does not leave your device.

Every tool on this site works this way. Operations that would require a server to process your file are not offered at all, rather than offered with a caveat.

How to tell which is which

There is no exception to look out for. Every tool page carries the same label, and every tool behaves the same way, because tools that could not work this way were left out.

The label is checkable rather than something you have to believe. Watch the network activity in your browser while a browser-side tool runs: the page and its libraries arrive, and after that nothing goes out carrying your document. The cookies page sets out how to run that check step by step.

Why it is built this way

The usual model for online PDF tools is to upload your file, process it on a server, hand back a link, and delete the file after some stated period. That works, and for some operations it is the only option. But it means your document existed, however briefly, on a machine you do not control, and you are relying on a deletion policy you cannot verify.

For operations that can run locally, that trade is unnecessary. Merging, splitting, rotating and compressing are all things a browser can do, so they are done in the browser.

What information is actually held

No account is required and none is offered, so there is no profile attached to your use of the site and nothing to sign up for. Document contents are never received for browser-side tools, because they never leave your device.

The server delivering these pages keeps ordinary request logs: the page requested, a timestamp, a browser user-agent string, and an IP address. That is what a web server records in order to function and to defend itself against abuse. It is not linked to any document you process, because no document reaches it.

Those logs are held only as long as they are useful for security and diagnostics, and are not sold, rented, or shared for marketing. There is no analytics platform, no advertising network, and no tracking pixel anywhere on this site.

Legal basis, for those who need one named

Where the UK GDPR or EU GDPR applies, the lawful basis for keeping server logs is legitimate interests: running a website securely and diagnosing faults. The interest is narrow, the data is minimal, and nothing is used to build a profile or to market anything.

No consent banner is shown because no consent is required. Consent obligations apply to non-essential storage and tracking, and this site does neither.

Your rights over that data

Where data protection law applies to you, you have the right to ask what is held about you, to have it corrected or erased, to object to its processing, to ask for it in portable form, and to complain to your national supervisory authority.

In practice the honest answer to most such requests is that there is very little to give you. For browser-side tools your documents were never received, so there is nothing to disclose or delete. Server logs contain an IP address rather than a name, so identifying your records usually needs you to supply the address and an approximate time.

Write to contact@pdf-make.com and mark the subject as a privacy request so it is not missed. We aim to respond within one month.

Children

This site is not directed at children and collects no personal information from anyone, including children. There is no registration, no profile and no content aimed at a young audience.

If you believe a child's personal information has somehow reached us, write to the address above and it will be removed.

Where data goes geographically

For browser-side tools, nowhere — your file stays on your device, whatever country you are in.

The pages themselves are delivered by a hosting provider and the libraries by a content delivery network, both of which operate servers in multiple countries. A request for a page or a script may therefore be served from, and logged in, a country other than your own. This is ordinary for any website and applies to the request, not to your documents.

Third-party code and what it can see

Three open-source libraries are fetched from a public content delivery network to do the PDF work: pdf-lib, pdf.js and JSZip. Typefaces are fetched from a font service. Both providers see your IP address and standard request details, as any host does for a resource loaded from it. Neither receives your file. The libraries execute locally and do not transmit anything.

Serving these files from this domain instead would remove the external requests entirely. Whether that has been done is recorded on the cookies page, which covers third-party requests in more detail.

What local processing does not protect you from

It keeps your file off other people's servers. It does nothing about the machine you are sitting at, and it has no reach at all once you forward a document to someone else.

These limits are stated so that the scope of the protection offered is clear.

Changes to this page

If how any of this works changes, this page changes with it, and so do the labels on the tool pages. Keeping the label and the behavior in step is the commitment worth making.

Material changes will be described here rather than quietly folded in. The version published at the time you use the site is the one that applies.

Contact

To make a request about your personal information, to ask how a particular tool handles your files, or to raise anything else covered by this policy, write to the email address below. Please mark privacy requests clearly in the subject line so they are routed correctly.