# Are Online PDF Converters Safe? What Happens to Your File, and How to Check in 60 Seconds

It depends on whether your file leaves your device, who holds it, for how long, and what it contains. How uploads work, the real risks, and a 60-second check.

---

- **Canonical URL:** https://dothecalculation.com/blog/files/are-online-pdf-converters-safe
- **Category:** Files & PDFs
- **Author:** Do The Calculation Team
- **Published:** 2026-09-29
- **Reading time:** 16 min read
- **Publisher:** Do The Calculation (https://dothecalculation.com)
- **Methodology:** https://dothecalculation.com/methodology

---

## Are online PDF converters safe? The short answer

It depends on four things: whether your file actually leaves your device, who receives it if it does, how long they keep it, and what is in it. A reputable converter that uploads your file over an encrypted connection, processes it and deletes it within an hour or two is a reasonable choice for a restaurant menu or a school worksheet. It is a weaker choice for a bank statement, a medical letter, a passport scan or an employee’s payslip, because for that window a copy of your document sits on a computer you do not control. And a fake converter site can be actively dangerous: in March 2025 the FBI warned that criminals were using free converter tools to steal information and spread malware.

The safest converter is one that never receives your file at all: a tool that runs inside your browser, or the conversion built into your computer or phone. This guide explains what happens when you upload a document, what the real risks are, when they matter most, and a check you can run in about a minute to see whether any site sends your file anywhere.

Tool: [Convert images to PDF without uploading them](https://dothecalculation.com/tools/jpg-to-pdf) — The JPG to PDF converter runs in your browser tab. Your photos and scans never leave your device, and you can check that yourself.

## What happens to a file you upload

Most online converters are server-based. When you drop a file on the page, five things happen:

- Transfer: your browser sends the whole file over the internet to the service’s servers, normally over an encrypted HTTPS connection.
- Storage: the file is written to the service’s storage, often a cloud provider’s data centre in a country you did not choose, while it waits to be processed.
- Processing: conversion software on the server opens the file and reads its contents in order to convert it. A PDF converter has to read your document to do its job.
- Retention: the converted file, and usually the original, are kept for a period so you can download the result, and sometimes longer if you have an account.
- Deletion: after the retention period, the service deletes the files, according to its own policy. You cannot see this happen; you rely on the service to do it.

Large converters publish how long they keep files. We read three of them on 29 September 2026. iLovePDF’s security page says files are automatically and permanently deleted within two hours of being processed (https://www.ilovepdf.com/help/security), and its privacy policy says that, as a general rule, personal data is processed within the European Economic Area (https://www.ilovepdf.com/help/privacy). Smallpdf says files are permanently removed from its servers after one hour of processing and are protected with 256-bit TLS encryption in transfer (https://smallpdf.com/blog/is-smallpdf-safe). Adobe’s FAQ for its free Acrobat online tools says files are protected with AES-256 encryption and TLS 1.2, and that if you do not sign in to save your file, Adobe deletes it from the server within a short time period (https://helpx.adobe.com/document-cloud/faq/try-acrobat-online-services.html).

Those are clear, published commitments, and they describe a careful process. They also confirm the basic fact: for that window, a copy of your document exists on someone else’s computer. For most documents that is fine. For some, it is a risk you do not need to take.

## The real risks

### Retention and breaches

A file that is stored can be exposed: through a misconfigured storage bucket, a compromised account, or a breach of the service. Document services are attractive targets because of what people upload to them. In 2020, BleepingComputer reported that a database from Nitro, a PDF software and e-signature company, was being sold with about 70 million user records, and that the seller also claimed to hold stolen documents, a claim the publication did not confirm (https://www.bleepingcomputer.com/news/security/massive-nitro-data-breach-impacts-microsoft-google-apple-more/). Nitro is a document platform rather than a free one-off converter, but the lesson carries over: anything stored can in principle be stolen, and a short retention period narrows that window without closing it.

### Third parties and jurisdictions

A converter may run on a cloud provider, use a separate company for conversion or storage, and operate from a country with different data-protection law from yours. Reputable services list their processors and where data is handled in their privacy policies. Free sites with no named company, no address and no privacy policy tell you nothing about where your file goes.

### Accounts and history

Signing in usually changes the rules: files may be kept in your cloud storage until you delete them, and a history of what you converted builds up in your account. That is convenient, and it is also a record. If you only need a one-off conversion, check whether the service keeps files for signed-in users before logging in.

### Malicious converter sites

The most serious risk is not a legitimate service being careless but a fake one. On 7 March 2025 the FBI Denver Field Office warned that its agents were increasingly seeing criminals use free online document converter tools to load malware onto victims’ computers, leading to incidents such as ransomware (https://www.fbi.gov/contact-us/field-offices/denver/news/fbi-denver-warns-of-online-file-converter-scam). The FBI said these tools do the task advertised, but the resulting file can contain hidden malware, and that the tools can also scrape submitted files for personal information such as Social Security numbers and dates of birth, banking and cryptocurrency information, email addresses and passwords. Its advice was to slow down, keep antivirus software up to date, scan any file you receive before opening it, and report incidents at ic3.gov.

These sites often appear as search advertisements or lookalike domains, with names one letter away from a well-known service. A converter that makes you download a program to finish the job, asks you to enable macros, or returns an .exe, .zip or .js file when you asked for a PDF is a warning sign. So is a site that asks for an email address or phone number before it will give you the result.

## When it matters most

For a flyer or a recipe, the risk of uploading is small. It matters a great deal for documents that could be used to steal your identity or money, or that you have a duty to protect:

- Identity documents: passports, driving licences, national ID cards, birth certificates, visa papers. A clear scan is exactly what identity fraud needs.
- Financial documents: bank and card statements, payslips, tax returns, loan applications. They carry account numbers, income, addresses and spending history.
- Medical records: test results, letters, prescriptions, insurance forms.
- Legal documents: contracts, court papers, wills, anything under a confidentiality agreement.
- Other people’s data: employee records, customer lists, patients’ or clients’ files. Here it is not only your risk to take.

If you handle other people’s personal data for work, law may decide the question for you. Under the EU and UK GDPR, a service that processes personal data on your behalf is a processor, and Article 28 requires that you use only processors providing sufficient guarantees and that the processing be governed by a contract (https://gdpr-info.eu/art-28-gdpr/). Article 5(1)(f) requires personal data to be processed with appropriate security (https://gdpr-info.eu/art-5-gdpr/). In US healthcare, HIPAA rules require a written contract with a business associate that handles protected health information, including a commitment to use appropriate safeguards (https://www.law.cornell.edu/cfr/text/45/164.504). A free converter you found through a search, with no agreement in place, rarely meets those requirements, which is why many employers block such sites or provide an approved tool. When in doubt, ask your organisation’s data protection or IT team.

## The 60-second check: does this site upload my file?

You do not have to trust a site’s description of itself. Your browser can show you every request a page makes, and how big it is. This works in Chrome, Edge, Firefox and Safari on a computer:

- Open the converter’s page, then open the developer tools: press F12, or Ctrl+Shift+I on Windows and Linux, or Cmd+Option+I on a Mac. In Safari, first turn on Show features for web developers in Settings, Advanced.
- Choose the Network tab. Chrome’s documentation notes that DevTools only logs network activity while it is open (https://developer.chrome.com/docs/devtools/network), so open it before you add the file. Firefox calls the same panel the Network Monitor (https://firefox-source-docs.mozilla.org/devtools-user/network_monitor/index.html).
- Add a test file of a known size, a PDF of a few megabytes for instance, and run the conversion.
- Watch the list. Look for a request with the method POST or PUT, and at the size column. A server-based converter shows a request roughly the size of your file going out, often to an address with upload in its name, followed later by a download of the result.
- A browser-based tool shows only small requests for its own code and images, and nothing the size of your file, however large the file is.

### What the check looked like on our own converter

We ran this test on our JPG to PDF converter in Chrome, adding four photos of about 22 KB each and converting them. The Network panel recorded 14 requests between adding the files and downloading the PDF, and every one was a GET with no body. Five fetched the converter’s own code from the site, including the background worker that decodes images. Four were blob: addresses, which is how a page shows a picture that already sits in the browser’s memory; they never leave the device. Two were the consent and analytics scripts that every page of the site loads a few seconds after opening. Three more fetched the site’s own code. There was no upload, and nothing the size of a photo; on other runs the analytics script also sent its usual page-view record, a request with the page address in it and no body. Adding an iPhone HEIC photo added five more GETs, all for the HEIC decoder and its worker, which download only when a HEIC file is added.

On a server-based converter the same panel looks different: after you add the file there is a POST or PUT whose size is close to the file’s own, followed by requests that check whether the conversion has finished and then a download. That is not a sign of wrongdoing; it is simply how a server-based converter works. The test tells you which kind of tool you are using, so you can decide what to put through it.

The airplane-mode test is even simpler and works on phones too: load the converter page, switch on airplane mode or unplug the network cable, and then convert. A tool that works offline cannot be sending your file anywhere. One that fails with a network error needs the connection to do the conversion.

> **What “encrypted in transit” does and does not mean** — HTTPS, shown by the padlock, uses TLS to encrypt data while it travels, so it cannot be read by anyone on the network between you and the server (https://developer.mozilla.org/en-US/docs/Web/Security/Transport_Layer_Security). It says nothing about what happens once the file arrives: the server decrypts it in order to convert it, and the service’s own storage, staff access and deletion policy decide the rest. Encryption in transit is necessary, but it is not the same as the service never seeing your document.

## What a converter’s privacy page should tell you

A privacy or security page is where a converter makes its commitments, and a good one answers a short list of questions in plain words. If you cannot find answers, treat that as the answer.

- Who runs it: a named company with an address and a contact for data-protection questions, not just a brand name.
- How long files are kept: a specific period, such as one or two hours, and whether that changes if you have an account.
- Where files are processed and stored: a region or country, and whether other companies (hosting, conversion engines, analytics) handle them.
- Who can see them: whether staff can access files, and under what circumstances.
- How to delete: whether you can remove a file immediately after downloading the result, rather than waiting for the automatic deletion.
- What is done with the content: a clear statement that uploaded files are not used for advertising, profiling or training models.

Certifications such as ISO/IEC 27001, which covers how an organisation manages information security, are a good sign when a service states them, but they describe processes, not a promise about your particular file. The retention period and whether the file is uploaded at all are still what decide your exposure.

## The three ways to convert, side by side

**Server-based, in-browser and built-in conversion compared**
|  | Server-based online converter | In-browser converter | Built into your device |
| --- | --- | --- | --- |
| Where the file goes | Uploaded to the service’s servers | Stays in the browser tab on your device | Stays on your device |
| Who could see it | The service and its processors, under its policy | No one else | No one else, unless the app syncs to the cloud |
| How long a copy exists elsewhere | Until the service deletes it | Never | Never, unless synced |
| Works offline | No | Yes, once the page has loaded | Yes |
| Best for | Formats that need server software, very large jobs | Private documents, everyday conversions | Private documents, simple jobs |
| How to check | Network tab shows an upload | Network tab shows no upload; airplane mode test passes | Nothing to check |

## If you have already uploaded something sensitive

Most of the time nothing bad follows from having converted a document on a legitimate service. Still, a few steps are worth taking, in proportion to what the file contained:

- If the service lets you delete the file, do it now rather than waiting for automatic deletion, and sign out.
- If the site now looks suspicious, for example it gave you a program to run or a file type you did not ask for, do not open that file. Run an up-to-date antivirus scan, and change important passwords from a different, clean device, which is what the FBI advises victims of fake converters to do.
- If the document carried bank or card details, tell your bank and watch your statements. If it carried identity details, consider the fraud-protection options your country offers, such as a credit freeze or fraud alert in the United States.
- Report a malicious converter site. In the United States that is the FBI’s Internet Crime Complaint Center at ic3.gov, as the FBI’s warning recommends.
- If the file held other people’s personal data and you uploaded it for work, tell your organisation’s data protection officer promptly: data-protection law can require a breach to be assessed and, in some cases, reported within a short deadline.

## Server-based and in-browser converters

A server-based converter sends your file to its computers and sends a result back. It can use powerful software, handle formats a browser cannot, such as Word to PDF with perfect layout, and process very large files on fast machines. The cost is the upload: your document leaves your control for as long as the service keeps it.

An in-browser converter downloads the conversion code to your browser when you open the page, then does the work on your own device. The file is read from your disk into the tab’s memory, converted there and handed back as a download. Nothing is uploaded, so nothing needs to be deleted afterwards, and the service could not see your document even if it wanted to. The trade-offs are that your device does the work, so very large jobs are slower on an old phone, and some conversions that need server software are not possible yet.

Every tool on [our tools page](/tools) that carries the Runs in your browser label works this way, including the [JPG to PDF converter](/tools/jpg-to-pdf), the [PDF to JPG converter](/tools/pdf-to-jpg), the [resume builder](/tools/resume-builder) and the [invoice generator](/tools/invoice-generator). The PDF page tools, [Merge PDF](/tools/merge-pdf), [Split PDF](/tools/split-pdf), [Compress PDF](/tools/compress-pdf) and [Rotate PDF](/tools/rotate-pdf), work the same way, and when a file needs a password to open, you type it into the page, where it is held in the tab’s memory and never stored. The document tools keep your drafts in your browser’s own storage; the converters keep nothing but your settings. You can check any of them with exactly the test above: open the Network tab, convert a file, and look for a request the size of your file. There isn’t one. Apart from the site’s own code, you will see the consent and analytics scripts every page loads and the analytics page-view record, which notes the page you opened, never your file, its name or its contents, and no request carries a body. Or load the page, switch on airplane mode and convert; it still works.

## Zero-upload options already on your devices

Your computer and phone can already do many common conversions without any website:

- Mac: Preview opens images and PDFs, exports to PDF, and combines PDFs by dragging page thumbnails from one document’s sidebar to another’s (https://support.apple.com/guide/preview/combine-pdfs-prvw43696/mac).
- Windows: any program that can print can save a PDF by choosing Microsoft Print to PDF as the printer, which is built into Windows 10 and 11.
- iPhone and iPad: the Notes and Files apps can scan paper documents with the camera and save them as PDFs on the device (https://support.apple.com/en-us/108963).
- Android: Google Drive’s scan button turns camera shots of documents into a file, and you can choose to save the scan as PDF or JPG (https://support.google.com/drive/answer/3145835). Drive then stores the file in your Google account, so treat it like any cloud storage.

For choosing the right format in the first place, and what resolution to scan at, see [PDF vs JPG vs PNG](/blog/files/pdf-vs-jpg-vs-png).

## A checklist before you convert a sensitive document

- Is the document sensitive: identity, money, health, legal, or someone else’s data? If not, a reputable online converter is fine.
- Can it be done without uploading: a built-in option on your device, or a tool that passes the 60-second check?
- Are you on the real site? Type the address yourself or use a bookmark rather than clicking a search advertisement.
- Does the site name the company behind it, and does its privacy or security page say how long files are kept and where?
- Does it return the file type you asked for? Never open an .exe, .js, .zip or macro-enabled document that arrives in place of a PDF.
- If it is work data, is the service approved by your organisation, with a data-processing agreement where the law requires one?
- After converting, delete the file from the service if it offers that, sign out, and scan anything you downloaded if in doubt.

More guides on scanning, converting and sending documents are collected in [Files and PDFs](/blog/files).

Tool: [Convert PDF pages to images without uploading](https://dothecalculation.com/tools/pdf-to-jpg) — The PDF to JPG converter opens PDFs, including password-protected ones, inside your browser and never sends them anywhere.

## Frequently asked questions

**Do online converters keep my files?**

Server-based converters keep them for a while so you can download the result. Published retention periods vary: iLovePDF says within two hours of processing, Smallpdf says one hour, and Adobe says it deletes files from its free online tools within a short time if you do not sign in. Signed-in accounts often keep files until you delete them. In-browser converters never receive the file, so there is nothing to keep.

**Can a converted file contain malware?**

Yes, if the converter is malicious. The FBI Denver Field Office warned in March 2025 that criminals were using free converter sites that do the conversion but return a file containing hidden malware. Use converters you know, check that the result is the file type you asked for, keep antivirus software up to date, and scan downloads before opening them.

**Is it safe to convert bank statements or ID documents online?**

It is safest not to upload them at all. A statement or ID scan is exactly what identity fraud needs, so use a converter that runs in your browser, or the tools built into your device, such as Preview on a Mac or Microsoft Print to PDF on Windows. If you must use an upload service, choose a well-known one with a published deletion policy, and delete the file there when you are done.

**How do I know if a tool uploads my file?**

Open your browser’s developer tools, choose the Network tab, then convert a test file of a few megabytes. An upload shows as a request, usually a POST, about the size of your file. A browser-based tool shows only small requests for its own code. Or load the page, turn on airplane mode, and try converting: if it still works, nothing is being sent.

**What is the safest way to convert a PDF?**

On your own device: an in-browser converter that passes the network check, or a built-in feature such as Preview on a Mac, Microsoft Print to PDF on Windows, or the scanning features of the Notes, Files or Google Drive apps. Either way the document never leaves your control. For work documents, use whatever tool your organisation provides.

**Do converters see the contents of my document?**

A server-based converter’s software has to read the document to convert it, so the contents are processed on the service’s computers. Reputable services say their staff do not look at files and that access is restricted, but the data is there for as long as the file is kept. HTTPS protects it only on the way. An in-browser converter processes the document on your device and the service never receives it.

**Is a converter that says it deletes files after an hour safe enough?**

For everyday documents, usually yes: a short, published deletion period from a named company with a clear privacy policy is a sensible standard. For identity, financial, medical or legal documents, and for other people’s data, the question is whether you need to upload at all, because even an hour on a server you do not control is exposure you can avoid with an in-browser tool.

**Does GDPR allow me to use a free online converter for work files?**

If the files contain personal data, the converter becomes a processor under GDPR, and Article 28 requires a contract and sufficient guarantees of security. Many free converters offer terms of service rather than a data-processing agreement, so they may not be appropriate for employee, customer or patient data. Check with your data protection officer, or use a tool that keeps the data on your own device.

---

_Source: [Do The Calculation](https://dothecalculation.com/blog/files/are-online-pdf-converters-safe). Quote freely with attribution and a link to this page._
