Tested 23 August 2026

Are free PDF tools safe?

I uploaded the same test PDF to 13 popular online PDF tools and watched the network panel to see whether the file left the browser. Then I read what each privacy policy actually says about keeping it. Of the 13 tools, 10 sent the file to a server, 1 did not, and 2 I could not settle either way.

The short version

"Server-side" is not a synonym for "unsafe", and it is worth killing that idea before the table. Sending a file to a server is how you get OCR, how you handle a 2 GB document on a phone, and how you run conversions that no browser can do. Several of the tools below are run by established companies with real security programmes, and the ones with the tightest published retention windows are all server-side.

What server-side processing does change is the shape of the question. Once the file has left your machine, you are no longer relying on a fact you can observe — you are relying on a promise you cannot check. Every deletion commitment in this article is unverifiable from the outside. That is not an accusation; it is a structural property of the arrangement. The practical consequence is simple: match the tool to the document. A restaurant menu and a client's medical records do not warrant the same care.

Comparison table

Observed 23 August 2026 on the PDF compression tool of each service. Policies change; re-check before relying on this.

Where each PDF tool processes files, and what its privacy policy says about retention
ToolProcessing observedStated retentionDeletion guarantee verifiable?
Tiny Tiny ToolsIn the browserNo server copy exists to retainPartly
iLovePDFOn their servers2 hours after processingNo
SmallpdfOn their servers1 hour (account users); 14 days for saved filesNo
PDF24On their servers"a short period of time" — no figure givenNo
SejdaOn their serversDeleted after processing; no period stated in that clauseNo
Adobe Acrobat onlineOn their serversDeleted unless you sign in to save it; no period statedNo
PDF2GoOn their serversNot located for the web toolNo
Soda PDFOn their serversNot located for the free online toolsNo
CleverPDFOn their servers30 minutes, with a manual delete-now optionNo
TinyWowOn their servers1 hourNo
Stirling PDF (hosted demo)On their serversNot located for the hosted demoNo
FreeConvertNot established8 hours, with a manual delete optionNo
PDF CandyNot established2 hoursNo

What the pattern actually shows

The result that surprised me least and matters most: browser-based PDF processing is rare. Ten of the 13 tools demonstrably upload, one demonstrably does not, and the two I could not settle both show signs of uploading. If you assumed that a tool advertising itself as "online" and "secure" keeps your file local, that assumption is wrong far more often than it is right.

The second pattern is in the policies rather than the packets. Stated retention windows range from thirty minutes to no stated period at all, and the spread does not track company size. CleverPDF, one of the smaller names here, publishes the tightest window and the only user-triggered immediate deletion. Two well-known services state no duration for the free web tool that I could find. Brand recognition is not a proxy for a good retention clause.

Third: read retention clauses for what they exclude. Sejda is the only policy here that says anything about backups, which matters because a backup is precisely the thing that outlives a deletion. Smallpdf's one-hour window is written as conditional on having an account. PDF2Go's strongest privacy language describes its desktop app, not the web tool. None of these are gotchas — they are just what the sentences say when you read them closely.

Per-tool notes

Tiny Tiny ToolsIn the browser

Tool tested
tinytinytools.com/pdf-compressor
What I observed
No request carrying a body left the browser after the file was selected. The tab downloaded pdf.js and pdf-lib and then produced the output. With the network disabled after the page had loaded, the compression still completed.
Retention

No clause covering files processed by this tool was found on the page linked below.

Tiny Tiny Tools privacy policy, retrieved 23 August 2026

Can you verify deletion?
Partly. There is no deletion promise to verify, but the absence of an upload is directly observable in your own network panel.
Worth knowing
This is my site, so treat the row with the scepticism that deserves and run the test yourself. Two things belong here for balance. The page still loads Google Analytics, so the tab is not silent — it is the file that stays put, not the browser. And the background remover, which is not the tool tested here, downloads a machine-learning model from Hugging Face the first time it runs; the image is not sent anywhere, but that download is a real third-party request.

iLovePDFOn their servers

Tool tested
www.ilovepdf.com/compress_pdf
What I observed
A POST to api53.ilovepdf.com/v1/process carried a request body containing the test file’s name. The page then advanced to a download screen.
Retention
ILOVEPDF will delete the files of your Content (as defined in the Specific Terms of Service) within TWO (2) HOURS of being processed on ILOVEPDF’s servers.

iLovePDF privacy policy, retrieved 23 August 2026

Can you verify deletion?
No. The commitment is specific and time-bounded, but it cannot be checked from outside.
Worth knowing
One of the clearest retention clauses in this group: a named period, in the privacy policy rather than only in marketing copy, with the scope of the exception (their e-signature product) spelled out.

SmallpdfOn their servers

Tool tested
smallpdf.com/compress-pdf
What I observed
A PUT with Content-Type: application/pdf went to smallpdf-production-files.<hash>.r2.cloudflarestorage.com, a Cloudflare R2 object-storage bucket. The interface then showed a compressed size.
Retention
If you access our services via a User Account, we delete User Files within one hour unless you save them to your file storage. When you choose to delete saved User Files, we generally delete them within 14 days.

Smallpdf privacy notice, retrieved 23 August 2026

Can you verify deletion?
No. Policy statement only.
Worth knowing
The one-hour clause is written as conditional on using the service "via a User Account", and I did not find an equally explicit period for signed-out use. That may simply be drafting, but the plain text is narrower than a general one-hour promise, so I am reporting it as written rather than rounding it up. The page also loaded Microsoft Clarity session-recording, which posted its own payloads; those relate to your browsing of the site, not to the file.

PDF24On their servers

Tool tested
tools.pdf24.org/en/compress-pdf
What I observed
A POST to filetools7.pdf24.org/client.php carried a body containing the test file’s name, and the tool returned a compressed result.
Retention
The compression tool does not keep your files longer than necessary on our server. Your files and results will be deleted from our server after a short period of time.

PDF24 compress tool page, retrieved 23 August 2026

Can you verify deletion?
No, and the period is not stated, so there is no specific claim to hold them to.
Worth knowing
I searched the PDF24 privacy policy for a file-retention period and did not find one; the quote above is from the tool page itself. "A short period of time" is not a commitment you can plan around. That is a gap in the wording, and I am not treating it as evidence of anything worse.

SejdaOn their servers

Tool tested
www.sejda.com/compress-pdf
What I observed
Decisive: with the page loaded and the network then disabled, submitting the file produced Sejda’s own error — "observation-test.pdf: Upload failed. There is no internet connection." Online, the page moved to a server-generated task ID.
Retention
All user-uploaded files as well as the processed output files will be permanently deleted after upload or processing respectively. We store the files for the sole purpose of giving you enough time to process and download them. No backups are made of these files.

Sejda privacy policy, retrieved 23 August 2026

Can you verify deletion?
No. Policy statement only.
Worth knowing
"No backups are made of these files" is a specific and unusually useful commitment — most policies here are silent on backups, and a backup is exactly what makes a deletion promise leak. Against that, the deletion clause states no duration, so "permanently deleted after processing" is weaker than it first reads.

Adobe Acrobat onlineOn their servers

Tool tested
www.adobe.com/acrobat/online/compress-pdf.html
What I observed
Two POSTs carried the file name: one to unity-an1.adobe.io/api/v1/asset/connector, one to pdfnow-jpn3.adobe.io. The browser tab title then became "observation-test.pdf - Adobe cloud storage".
Retention
Your file will be securely handled by Adobe servers and deleted unless you sign in to save it.

Adobe Acrobat compress page, retrieved 23 August 2026

Can you verify deletion?
No. Policy statement only, and no period is given on the tool page.
Worth knowing
The tab title naming Adobe cloud storage is worth knowing: the file is not passed through a stateless converter, it lands in the same storage layer the signed-in product uses. Adobe is also the only vendor here whose enterprise compliance programme is a matter of public record — I did not audit any of it, and mention it only so the row is not read as a criticism of their security posture.

PDF2GoOn their servers

Tool tested
www.pdf2go.com/compress-pdf
What I observed
A multipart/form-data POST went to www37.pdf2go.com, followed by calls to dragon.pdf2go.com carrying the file name. The result panel reported "Compressed by 48.05%".
Retention
Your files stay on your device. Conversion in the desktop application is performed entirely locally on your computer. The files you convert, and their contents, are not transmitted to us and not transmitted to any third party.

PDF2Go privacy policy, retrieved 23 August 2026

Can you verify deletion?
No, and I could not locate a retention period for the web tool at all.
Worth knowing
A trap worth flagging for anyone repeating this research: the PDF2Go policy contains the sentence "The data is stored on our side for 7 days", and it is tempting to quote it as a file-retention period. Read in context it is about IP addresses in server logs, not uploaded files. The quote above is theirs too, and it is a genuine point in their favour — but it describes their desktop application, not the web tool tested here.

Soda PDFOn their servers

Tool tested
www.sodapdf.com/compress-pdf/
What I observed
A multipart/form-data POST went to api-gw.sodapdf.com, followed by a JSON call carrying the file name.
Retention

No clause covering files processed by this tool was found on the page linked below.

Soda PDF privacy policy, retrieved 23 August 2026

Can you verify deletion?
No, and I did not find a clause covering files processed by the free online tools.
Worth knowing
Their privacy policy is long and unusually specific about retention in other areas — ten years for signed e-signature documents, ninety days for unsigned ones, five years for account data. I could not find the equivalent sentence for a PDF dropped into the free compressor. It may exist somewhere I did not reach; I am recording that I looked and did not find it.

CleverPDFOn their servers

Tool tested
www.cleverpdf.com/compress-pdf
What I observed
Two multipart/form-data POSTs went to www.cleverpdf.com, the second carrying the file name, and a download link appeared.
Retention
Both input and output files are permanently deleted from our servers 30 minutes after processing. If user request to remove the uploaded and output files instantly (By clicking on the delete file links after processing), the files will be permanently removed from server instantly as requested.

CleverPDF privacy policy, retrieved 23 August 2026

Can you verify deletion?
No, but it is the shortest stated window here and the only one with a user-triggered immediate delete.
Worth knowing
On the retention wording alone this is the strongest policy of any server-side tool tested: the shortest window, an explicit manual deletion control, and both input and output covered. Worth saying plainly, since it is a smaller name than most of the others on this list.

TinyWowOn their servers

Tool tested
tinywow.com/pdf/compress
What I observed
A multipart/form-data POST went to tinywow.com after choosing a compression level.
Retention
All files both processed and unprocessed are deleted after 1 hour

TinyWow privacy policy, retrieved 23 August 2026

Can you verify deletion?
No. Policy statement only.
Worth knowing
The interface repeats the same promise where you can actually see it — "Your files will be deleted in 1 hour or less" appears in the file list, not only in the policy. Covering unprocessed files explicitly is a detail several longer policies omit.

Stirling PDF (hosted demo)On their servers

Tool tested
stirlingpdf.io/compress-pdf
What I observed
A multipart/form-data POST went to api.stirling.com.
Retention

No clause covering files processed by this tool was found on the page linked below.

Stirling PDF, retrieved 23 August 2026

Can you verify deletion?
Not for the hosted demo. Uniquely on this list, it becomes fully verifiable if you self-host, because the server is then yours.
Worth knowing
The hosted demo behaves like every other server-side tool here. The difference is structural rather than contractual: Stirling PDF is open source and designed to be self-hosted, so an organisation that cannot accept a third party holding its documents can run the same tool on its own infrastructure and answer the retention question itself. That is a genuinely different answer to the problem than anything else in this table.

FreeConvertNot established

Tool tested
www.freeconvert.com/compress-pdf
What I observed
Not established. Across two attempts the automated harness could not attach a file to the page, so no processing was ever triggered and there was nothing to observe. This is a limitation of my test, not a finding about FreeConvert.
Retention
Files uploaded to FreeConvert are automatically and permanently deleted after 8 hours. You also have the option of permanently deleting the files manually before they are automatically deleted.

FreeConvert privacy policy, retrieved 23 August 2026

Can you verify deletion?
No. Policy statement only.
Worth knowing
Their own policy says "Files uploaded to FreeConvert", which reads as a description of server-side processing, but I am not going to record an observation I did not make. If you repeat this test by hand rather than with automation, this one should be straightforward to settle.

PDF CandyNot established

Tool tested
pdfcandy.com/compress-pdf.html
What I observed
Partial. The page accepted the file and correctly reported "60 pages", which means it parsed the PDF in the browser. No upload had occurred at that point. I could not get the automated harness to activate the Compress control, so what happens at the moment of compression was never observed.
Retention
Within 2 hours of the files being kept on our server, they will be permanently deleted.

PDF Candy privacy policy, retrieved 23 August 2026

Can you verify deletion?
No. Policy statement only.
Worth knowing
Reading the page count locally proves the browser can open the file; it does not prove the compression happens there. Their policy refers to files "being kept on our server", which suggests uploads occur for at least some tools. Unresolved either way, and I would rather leave it that way than guess.

Methodology, so you can repeat it

Everything above came from two activities: watching a browser, and reading policies. Neither requires special tooling.

The network test

  1. Make a test file you will recognise. I generated a 60-page, 57 KB PDF named observation-test.pdf containing nothing but synthetic filler text. A distinctive name matters: it shows up inside multipart upload bodies and makes an upload unambiguous. Never use a real document for this.
  2. Open the tool in a fresh browser profile. A clean profile keeps old cookies and cached state from changing the tool's behaviour.
  3. Open DevTools → Network, tick "Preserve log", and clear it immediately before you choose the file, so what you see afterwards is only what the file triggered.
  4. Select the file, then run the tool. Some services upload the moment you choose a file; others wait until you press the action button. You have to do both before you can conclude anything.
  5. Look for a request that carries the file. Filter to Fetch/XHR and look for a POST or PUT whose request payload is multipart/form-data,application/pdf, or roughly the size of your file. That is the file leaving.

The trap I fell into, and how to avoid it

My first pass reported that Smallpdf and Sejda did not upload. Both conclusions were wrong. Large uploads are frequently streamed, and a streamed request body does not always expose aContent-Length header or a readable payload to automated tooling — so a naive "look for a big request body" check misses them. Smallpdf's upload turned out to be aPUT with Content-Type: application/pdf to a Cloudflare R2 bucket, invisible to my original filter.

If you are checking by hand, the fix is to sort the Network panel and read the entries rather than relying on a size threshold. If you want certainty, use the second test.

The decisive test: pull the plug

  1. Load the tool page completely and let it finish downloading its scripts.
  2. In DevTools → Network, switch the throttling dropdown to Offline.
  3. Now select your file and run the tool.

A tool that processes in your browser will finish the job with the network switched off. A tool that uploads cannot, and will usually tell you so. Sejda's own interface answered the question for me in plain English: "observation-test.pdf: Upload failed. There is no internet connection." This test has no false positives — a completed conversion with the network disabled cannot have involved a server.

One caveat. A browser-based tool may still fail offline the very first time, because the library that does the work may not have downloaded yet. Load the page, use the tool once online, reload, and only then go offline. That is how I tested my own site, and it is the only fair way to run it.

Reading the policies

For each service I searched its privacy policy for sentences containing both a retention verb (delete, retain, remove, store, purge) and a time expression, then read the surrounding paragraph to confirm what the sentence was actually about. That last step is not optional. PDF2Go's policy contains "The data is stored on our side for 7 days", which looks exactly like a file-retention period and is in fact about IP addresses in server logs. Quoting it as a file policy would have been a straightforward factual error.

Where I could not find a clause, the table says so rather than inferring one. "Not located" in this article means I looked and did not find it — it does not mean no such clause exists anywhere, and it is not a finding about how a company behaves.

Limits of this research

What I would actually do

For an ordinary document — a flyer, a form you are about to print, a scan of something already public — any tool in this table is a reasonable choice, and the well-resourced server-side services will handle more formats and bigger files than a browser can.

For anything you would not email to a stranger — contracts, medical records, identity documents, unreleased financials, anything covered by an obligation to someone else — the calculus changes, because the risk is no longer yours alone to accept. There, in rough order of how much certainty each gives you: use desktop software that never touches a network; or self-host something like Stirling PDF so the server is yours; or use a browser-based tool and confirm with the offline test that nothing left; or, if you must use a hosted service, pick one with a short, specific, written retention period and delete the file manually afterwards if it offers that control.

And whichever you choose, the useful habit is the one this whole article is built on: open the network panel and look. It takes a minute, it works on any tool including mine, and it replaces a marketing claim with something you have seen for yourself.