Plain-language privacy boundary
Your PDF is not our data.
pdfmend reads, renders, edits, and exports document content inside your browser. The editor has no document upload operation.
What stays on your device
PDF bytes, filenames, rendered pages, extracted form values, signatures, images, ink, text edits, and edit history are processed in your browser. Closing the tab ends the active edit session. Opening passwords are held only in memory for the active document; they are never uploaded, logged, or written to browser storage. Opened PDFs are kept by default in this browser's IndexedDB so you can reopen recent files. The on-device library holds at most 25 PDFs and about 200 MiB; older recent files are removed first. You can turn this off at any time in Editor Settings, which immediately clears the local PDF library and preserves that choice. Files are never uploaded. When you open a recent document from a public page, its validated local library ID is staged in this tab's session storage for at most five minutes and deleted as soon as the editor reads it; that handoff never leaves your browser. “Remember editing draft” is a separate setting: if enabled, pdfmend stores the source PDF and edit snapshot in this browser so the draft can be restored later. Files you explicitly save with “Save as” remain pinned in the on-device library until you delete them or turn PDF storage off. If a Pro user explicitly saves a reusable signature or form-value preset, that item is stored locally for up to 30 days. Draft recovery remains off by default. The account page lists local items and “Clear all local data” removes them immediately without a network request.
Installable app shell (optional)
When you install pdfmend or leave the service worker enabled, this browser may cache pdfmend-owned app shell assets only—HTML shells for the marketing and editor routes, hashed static scripts/styles, icons, and the manifest. Cache names start with pdfmend-shell-. That shell cache never stores PDF bytes, document filenames, canvas pixels, signatures, form values, or API responses. Authenticated account pages are not shell-cached. “Clear all local data” on the account page also unregisters the service worker and deletes pdfmend shell caches in this browser. You can disable the service worker with the product kill switch when operators need to recover from a bad deploy.
Plausible analytics (optional)
Plausible is pdfmend's only analytics provider. When configured, its cookieless script may load on public marketing pages and the editor—but never on account, sign-in, or API surfaces. It measures page visits, referrers, editor actions, and a small activation funnel: document opened, edit applied, export succeeded, repeated feature used, and upgrade intent. Product events contain only closed labels and broad page-count, file-size, edit-count, and duration buckets. We do not send Plausible a pdfmend analytics session ID, event ID, account ID, workspace ID, raw count, raw duration, PDF bytes, filename, opening password, document-derived identifier, text, image, form value, signature, edit payload, or arbitrary client string.
Plausible may process the page URL, referrer, user-agent, and IP address to produce aggregate traffic statistics under its service terms. pdfmend disables automatic pageviews and supplies a sanitized analytics URL containing only the approved page path and standard campaign parameters. Automatic file-download, outbound-link, and form-submit tracking is also disabled. Local-document IDs, editor-language state, and other query values are removed. Content-free boolean keys beginning with folio-mend-measurement- record whether this tab has already emitted a milestone or edit-depth bucket; they prevent duplicates and disappear with the browser session. These flags never leave the browser. If Plausible is unconfigured, blocked, or unavailable, analytics becomes a no-op and never blocks editing or export. You can block plausible.io in your browser if you prefer.
What an account may store
An account stores identity and personal-workspace records. If you start a paid plan, pdfmend also stores billing-customer, entitlement, and signature-verified checkout records. Plausible event properties do not include account or workspace identifiers.
Payments and email
Stripe hosts payment entry and the customer billing portal. Resend may deliver verification email. Neither provider receives your document.
Visible signatures
A signature image placed with pdfmend is a visible mark. It is not a certificate-backed digital signature and should not be represented as one.