Privacy and security

What a PDF tool can see in your Google Drive

If I let a PDF site open a file from my Google Drive, what else can it see?

Short answer

It depends entirely on which permission it asked for, and Google offers three very different ones. The narrow one, drive.file, covers only the files you hand over through Google's own file picker plus the files the site creates — it carries no ability to list, search or browse anything else, so the rest of your Drive is not visible to ask about. The broad ones cover your whole Drive and are what Google calls restricted: a site using one must pass an annual third-party security assessment. The permission screen tells you which you are being asked for, and the wording is worth reading before you press Continue.

Three levels, and they are not close to each other

When a site wants to work with your Drive it has to name a scope — the permission it is asking for. Google sorts these into tiers by how much damage the wrong app could do with one.

123

The three levels of Drive access

  1. The narrow permission: only the files you hand over through Google's picker, plus files the site creates. The rest of the Drive cannot be listed, searched or opened.
  2. Read-only access to the whole Drive: every file and every folder name. Google classes this as restricted and requires an annual independent security assessment.
  3. Full access: read, change and delete anything in the Drive. Also restricted, also assessed every year.

drive.file is the narrow one. The site may open the files you explicitly hand it through Google's own picker, and the files it creates itself. Everything else in your Drive is not merely off limits — it is invisible. There is no request the site can make that returns a file you did not choose. Google classes this as non-sensitive.

drive.readonly and drive.metadata.readonly cover the whole Drive, to read. Every document, every folder, every name. Google classes these as restricted, and a site that uses one must pass an independent security assessment every year to keep it.

drive is full access: read, change and delete anything. Also restricted, also assessed annually.

The gap between the first and the rest is not a matter of degree. One is "this file I just picked"; the others are "all of it". A utility that converts a document needs the first, and an application that needs to open your documents the way a desktop app does — a backup tool, a document manager — has a real case for the others. The question worth asking of any site is not whether it asks for Drive access but which it asks for.

Why the file picker is the important part

With the narrow permission, the site cannot show you a list of your files, because it cannot obtain one. So the file chooser you see is not the site's. It is Google's own picker, running Google's code, showing you your Drive.

That arrangement is what makes the permission meaningful. You browse inside Google's interface; the site is not watching. When you choose a file, Google hands the site access to that file and to nothing else. Choose nothing and the site learns nothing — not that you looked, not what was there.

It also has a consequence that is easy to read as a missing feature. A site holding only this permission cannot populate a "save to folder" menu from your Drive, because listing folders is exactly what the broad permissions are for. Any site that does show you your folder tree has asked for considerably more than this. On iBuildPDF, destination folders are chosen through Google's folder picker and the ones you have picked are remembered in your own browser, so the menu fills up with use. That list is folders you chose, not an inventory of your Drive.

The same mechanism is why a Drive button on a site cannot do anything until you press it. Until then there is no permission, no token, and nothing of Google's running on the page.

What this site asked for

iBuildPDF uses drive.file, and only that. In practice:

  • It is not part of signing in. Continuing with Google to create an account does not grant it. It is requested the first time you press a Drive button on a tool page, and never otherwise.
  • It is optional. Every tool on the site works with files from your device, with no account and no Drive permission at all.
  • The access token stays in the browser tab. It is created by Google's script inside the tab, held in a variable there, and discarded when you close the tab. It is not sent to this site's server, not written to a cookie, and not written to browser storage. The server is not given the file id or the folder name either.
  • We cannot list your Drive, and this is a property of the permission rather than a promise about our conduct — which is the kind of assurance worth having, because it does not depend on us.

What this does not tell you is anything about other sites. The permission screen is the thing to read, every time: it names what is being requested in Google's words, not the site's. Are free online PDF tools safe? covers the wider question of what to check before handing a document to any of them.

Where the file actually goes

Opening from Drive changes where a file comes from. It does not change what the tool then does with it, and those are two different questions.

Drive123

Where the bytes travel when you open a file from Drive

  1. The browser tab. The access token is created here by Google's script, stays here, and is discarded when the tab closes.
  2. For a tool that runs in the browser, the file goes from Drive to the tab and back again. This site's server is not in that path.
  3. For a tool that needs a server — OCR, the Office conversions, passwords — the file is sent on, exactly as it would be if you had chosen it from your disk.

For a tool that runs in your browser — merging, splitting, compressing, rotating, reordering, adding page numbers, converting images — the bytes go from Google to your browser tab, the work happens there, and the result goes back to Drive from the same tab. This site's server is not in that path at any point. How browser PDF tools work explains how that is possible.

For a tool that runs on a server — OCR, the Office conversions, adding or removing a password — the browser sends the file to the processing server, exactly as it would if you had chosen that file from your disk. Drive changed where the file came from and nothing else. Each of those tools states on its own page what happens to the file and how long it is kept, and that notice does not change when the file arrives from Drive.

The practical reading: if a tool would not have sent your file to a server before, opening it from Drive does not start it; and if it would have, Drive does not stop it. Judge the tool, not the button.

Checking and withdrawing access

Everything you have granted is listed in one place, and it is worth a look once in a while regardless of this site.

  • See the list. In your Google Account, under Security, open the third-party access section. Every app you have granted anything is there, with what it was granted.
  • Read what each one says. "See and download all your Google Drive files" and "See, edit, create and delete only the specific Google Drive files you use with this app" are the two wordings to tell apart. The second is the narrow permission.
  • Remove what you no longer use. Removing access is immediate and does not touch your files. A site that held the narrow permission simply stops being able to open the files you gave it.
  • Removing access here costs you nothing. Withdraw the Drive permission and the Drive buttons stop working; every tool still works with files from your device. Nothing you converted or saved is affected.

Two habits worth more than any of this. Check the permission screen before pressing Continue rather than afterwards — it is the only moment the exact request is put in front of you. And be more careful about scope than about brand: a well-known site asking for your whole Drive is asking for more than an unknown one asking for a single file.

Tools this article covers

Sources

Primary documentation for the claims above.

Last reviewed: October 7, 2026

Published by iBuildPDF.

More from the knowledge base

Browse the knowledge base