PRIVACY GUIDE · REVIEWED AUGUST 25, 2026 · SAKSHI KUMARI
Private online PDF tools: what “browser-based” means
“Private” is not a magic label. The relevant questions are whether a file is uploaded, what scripts run on the page, what your device retains, and how sensitive the document is. This guide describes the current techSA implementation and the limits of what code inspection can establish.
What techSA’s PDF tools do
The PDF merge, split, rotate, organise, extract, watermark, page-number and conversion pages use JavaScript libraries in the browser to read files selected through the file picker and generate a download. The repository contains no request code that sends those selected PDF files to a techSA application server. The browser File API only exposes a file after a person explicitly selects it; it does not give a page arbitrary access to files by pathname.
Several tool pages load PDF, image, OCR, QR or ZIP libraries from cdn.jsdelivr.net. Loading a library is a network request to that CDN. It is distinct from uploading a chosen document, but it means a file tool is not an isolated offline application. The current code does not show file-storage, retention or deletion controls because it does not implement a techSA file-upload service.
What this does not guarantee
- It does not prove that every dependency is harmless, or that a future deployed version will behave the same way.
- It does not protect a compromised, shared or publicly used device.
- It does not remove copies you have already downloaded, cached, backed up or shared.
- It does not make an altered PDF legally valid or suitable for an official process.
Browser-first versus server processing
With browser-first processing, the page reads the file into browser memory and creates an output locally. With server processing, the file is transferred to a remote service for processing; that service’s retention, security and access policies then matter. If a tool asks you to sign in, shows a cloud job queue or describes upload retention, treat it as a different model and read its policy carefully.
Safer handling for sensitive documents
- Use only the pages needed and retain an untouched original.
- Redact information before sharing—not merely by drawing a black box over selectable PDF text.
- Check the downloaded PDF page by page for extra pages, annotations, signatures, metadata or omissions.
- Use a current browser on a device you control; avoid shared computers for identity, financial and signed records.
When to stop
Do not use a browser tool to bypass password protection, change a signed document’s meaning or rescue the only copy of a critical file. Encrypted, corrupt or very large PDFs can fail because of library or device-memory limits. Get the original document or appropriate authorised support instead.
Sources and next steps
The browser permission model is described in MDN’s FileReader documentation. See the site-specific scope in the Privacy Policy, then use the PDF Merger only if this workflow is appropriate.