Last updated
pdf.xyz (“we”, “us”) operates the website at pdf.xyz and the tools on it. For anything in this policy, including requests about your data, write to legal@pdf.xyz.
Where this policy uses terms from the UK and EU General Data Protection Regulation, we are the controller for the limited personal data described below.
This is the part most people are asking about, so it comes first.
Tools that run in your browser (29 of 50). The file is opened and processed by code running on your own device. It is not sent to us, and we could not read it if we wanted to. Closing the tab discards it. Nothing about the file's contents, name, or size reaches our servers.
Tools that use a processing worker (21 of 50). Some work cannot be done in a browser — optical character recognition, office-format conversion, and anything using an AI model. For these, your file is uploaded over an encrypted connection to storage we control, scanned for malware, processed, and then removed on this timetable:
We do not read your documents, and no person at pdf.xyz opens them in the ordinary course of running the service.
One case worth naming. If you use the tools that add or remove a PDF password, the password you type is part of the instruction sent to the worker, and it sits in that job record for the same ~24 hours. It is never written to a log, an error message, a filename, or a result. Still: if a password is one you use elsewhere, change it, or use it only for the document.
Every tool page states which of these two applies before you choose a file, and the status page lists them all.
Our AI tools — summarising, translating, answering questions about a document, and structured extraction — work from the text of your PDF. The worker extracts that text and sends it to a third-party AI provider to produce the answer. The PDF file itself is not sent to the provider.
Two details we would rather state than have you discover. Only text the PDF already contains as text is sent — we do not run character recognition to manufacture text from a scan, and a scanned document is refused rather than silently half-processed. And for Chat with PDF, the document's text is held briefly in the provider's cache between your questions, so a follow-up does not resend the whole document; that cache lasts minutes, not days.
We use providers under agreements that prohibit training on data sent through the API. We cannot control what a provider does beyond those terms, so if a document is sensitive enough that this matters, use one of the in-browser tools instead, or do not use the AI tools for it.
Beyond file processing, the data we handle is deliberately small.
There are no accounts. We do not ask for a name, an email address, or a password to use the tools, so we hold no profile of you to lose.
Under UK and EU data protection law we rely on two lawful bases:
Our providers operate internationally, so your data may be processed outside your country, including in the United States. Where personal data is transferred out of the UK or EEA, we rely on the safeguards those providers offer — typically the UK International Data Transfer Agreement or the EU Standard Contractual Clauses.
Traffic to and from this site is encrypted in transit. Uploaded files are stored on infrastructure we control and are scanned for malware before any processor touches them. The site sets a strict Content Security Policy and related protections against common web attacks. We remove uploads and results on the timetable in section 2 rather than keeping them.
No service can promise perfect security, and we do not. What we can say is that the largest single reduction in risk is the design itself: for the majority of our tools there is nothing on our servers to breach, because the file never left your device.
Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal data, to object to or restrict processing, and — in California — to know what is collected and to opt out of sale or sharing. We do not sell or share personal information, so there is nothing to opt out of.
To exercise any right, email legal@pdf.xyz. We will not treat you differently for asking.
Please be aware of a practical limit: because we hold no accounts and delete files within an hour, a request about a document you processed is usually a request about data that no longer exists. We are also often unable to connect a request to a specific past request without information that would identify you more than we currently do — we will not create a record of you in order to answer.
If you are in the UK or EEA and you think we have handled your data badly, you may complain to your national supervisory authority. In the UK that is the Information Commissioner's Office.
This service is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child has provided us with personal information, contact us and we will delete it.
If we change how we handle data, we will update this page and the “last updated” date above. Where a change materially reduces the protections described here, we will say so prominently rather than quietly editing the text.