Plain-language privacy boundary
Your PDF is not our data.
pdfmend reads, renders, edits, and exports document content inside your browser. The editor has no document upload operation.
What stays on your device
PDF bytes, filenames, rendered pages, extracted form values, signatures, images, ink, text edits, and edit history are processed in your browser. Closing the tab ends the active edit session. Opened PDFs stay in the browser session by default. If you enable “Remember draft on this device,” pdfmend may store the source PDF and edit snapshot in this browser's IndexedDB so the draft can be restored later (never uploaded). A separate optional “Remember PDFs on this device” library for recent files is off unless you turn it on. If a Pro user explicitly saves a reusable signature or form-value preset, that item is stored locally for up to 30 days. Draft recovery and library remember are off by default. The account page lists local items and “Clear all local data” removes them immediately without a network request.
Installable app shell (optional)
When you install pdfmend or leave the service worker enabled, this browser may cache pdfmend-owned app shell assets only—HTML shells for the marketing and editor routes, hashed static scripts/styles, icons, and the manifest. Cache names start with pdfmend-shell-. That shell cache never stores PDF bytes, document filenames, canvas pixels, signatures, form values, or API responses. Authenticated account pages are not shell-cached. “Clear all local data” on the account page also unregisters the service worker and deletes pdfmend shell caches in this browser. You can disable the service worker with the product kill switch when operators need to recover from a bad deploy.
Content-free product measurement
Free and Pro sessions send coarse usage counts so we can measure whether the editor works. These records use a random browser-session ID, closed event names, and broad page-count, file-size, edit-count, and duration buckets. They never include PDF bytes, filenames, document-derived identifiers, text, images, form values, signatures, edit payloads, or arbitrary client strings. The anonymous ID lives in session storage and is discarded when the browser session ends. Measurement failure never blocks editing or export.
Website traffic analytics (optional)
When configured, a cookieless traffic script from Plausible may load on public pages and on the editor shell so we can understand visit volume, referrers, and which editor tools people click (for example “highlight”, “box”, or “text”). That path may process the page URL, referrer, user-agent, IP address (aggregated location only), and closed tool labels. It does not set analytics cookies and never receives PDF bytes, filenames, document text, signatures, form values, or edit content. You can block the third-party host in your browser if you prefer.
What an account may store
An account stores identity and personal-workspace records. If you start a paid plan, pdfmend also stores billing-customer, entitlement, and signature-verified checkout records. Authenticated coarse product events may be associated with that account and workspace; they remain content-free under the boundary above.
Payments and email
Stripe hosts payment entry and the customer billing portal. Resend may deliver verification email. Neither provider receives your document.
Visible signatures
A signature image placed with pdfmend is a visible mark. It is not a certificate-backed digital signature and should not be represented as one.