File handling & privacy
Last updated: September 9, 2026
Companion to the Privacy Policy. This page explains what happens to an uploaded PDF on PDF123 in plain language, so you can decide whether a hosted tool fits your document policy.
Lifecycle (high level)
- Upload — Your browser sends the file over HTTPS to our web/API layer.
- Process — The selected tool runs on the server (memory and/or a short-lived temp directory).
- Respond — You download (or receive) the result for that request.
- Delete — Working copies are removed when the job finishes; they are not kept as a personal document library.
We do not use uploads to train models or to build advertising profiles. Operational logs (time, IP, URL, status) may exist for reliability and abuse prevention — details are in the Privacy Policy.
What we promise vs what you should still do
- Prefer not uploading data your organization forbids sending to a hosted service.
- Keep your own original; treat our output as a derivative.
- Security tools (Unlock, Sanitize, Remove Certificate Signature, Protect, and similar) are only for documents you are authorized to modify. See each tool page for the lawful-use notice.
Third parties and optional connectors
Core PDF tools run on our infrastructure. If you explicitly configure a third-party connector (for example a webhook you choose), that destination's policy applies to whatever you send there. Ads are a separate channel: Google AdSense may load on content pages and may use cookies as described in our Cookie Policy.
Ads and consent (EEA / UK / CH)
Google's EU User Consent Policy requires a Google-certified CMP before personalized ads for those regions. Until an account-level Privacy & messaging (or equivalent) CMP exposes __tcfapi, this site defaults ad requests toward non-personalized ads where we control the request path. See also the Advertising section of the Privacy Policy.
Contact
Questions: [email protected] — also listed on About and Contact.