Security & File Privacy

How your files are actually handled — including what browser-based processing does not protect you from.

How to tell what a tool does

Every tool page carries a badge directly under its workspace:

That badge is generated from the tool's processing mode in our tool registry, not typed into each page by hand. A tool that uploads your file therefore cannot display the browser-only badge, even by mistake.

At the time of writing, every published tool on iBuildPDF is browser-based.

What browser processing does and does not protect

It protects you from your document being transmitted, stored, logged or read by us or by anyone intercepting the connection, because none of that happens.

It does not protect you from a compromised device, a malicious browser extension with permission to read page content, or someone with physical access to your computer. If a document is sensitive enough that those are real concerns, do the work on an offline machine with desktop software.

Transport and site security

The site is served over HTTPS, and requests to the plain-HTTP or www address are redirected to the canonical secure address. The administration area is excluded from search indexing and requires a login. Forms are protected against cross-site request forgery.

The PDF engines (pdf-lib and PDF.js) are loaded from a public CDN at pinned version numbers rather than floating "latest" URLs, so the code your browser runs does not change without a deliberate release on our side.

Limits worth knowing

Browser tabs have a memory ceiling, and a very large or image-dense PDF can exceed it. When that happens the tool tells you the file was too large to process safely rather than failing silently.

Compression works on the images inside the file. The Smart and Strong levels decode each embedded photograph, downsample it and write it back, leaving the page content — your text, vector graphics, links and form fields — exactly as it was. Only the Maximum level re-renders whole pages as pictures, and because that discards the real text it is labelled as destructive before you run it. We show the before and after sizes so the trade-off is visible, and we never claim compression is lossless.

If a tool ever returns a file that is broken, blank or larger than the original, that is a bug and we would like to hear about it through the contact page.

The three ways a file can be handled

Any PDF service handles a document in one of three ways. They differ in what actually leaves your device, and the difference is the whole of the privacy question. Here is what each means, and which ones iBuildPDF uses today.

ModelWhat leaves your deviceRetentionDeletionUsed by iBuildPDF
Local processing
The page reads the file in your browser and does the work there.
Nothing. The document is never transmitted. The page fetches its code from a CDN when it loads, before you have chosen a file, and that request carries no file data.Nothing is retained, because nothing is received. The file exists in the tab's memory while you work and is gone when you close it.Nothing to delete. Your original on disk is never modified; the result is a new file you download.All 31 live tools.
Server processing
The file is uploaded, processed on a server, and the result sent back.
The complete document, over an encrypted connection.The upload and the result exist on the server for as long as the job takes plus a retention window.Files are removed by a scheduled cleanup after the retention window; the job record does not keep the document.None. The tools that would need it are switched off, not quietly uploading.
Third-party processing
The file is passed to an external provider that does the conversion.
The complete document, to a company that is not us, under their terms rather than ours.Whatever the provider's policy says. We would not control it and could not promise on their behalf.The provider's process, not ours.None. No external conversion provider is configured.

This is why the format converters — PDF to Word, Word to PDF, PDF to Excel and the rest — are marked as coming soon rather than being made to work. Making them work means choosing one of the two models above, and that is a decision about where your documents go, not a feature to be shipped quietly.

What this page is for

It is the reference version of the claim every tool page makes in one line. If something here contradicts a tool page, this page is the one that has been checked, and the contradiction is a bug worth telling us about.

Two things it deliberately does not say. It does not say your files are safe from everything — a compromised device, a malicious browser extension or a shared computer are all outside what any web page can protect against. And it does not give a blanket "nothing is ever uploaded", because that would stop being true the day a server-side converter is switched on. What each tool does is stated on that tool, generated from the tool's own configuration, so the two cannot drift apart.

Last reviewed: September 17, 2026