How we prove your files are never uploaded

Every NoUploadPDF tool works on your file inside your own browser, on your phone or computer, and never uploads it. You don't have to take our word for it: here are two checks you can do yourself in a minute, what our own test sees, what our pages are allowed to contact, and what we can't prove.

Check 1: watch the network panel

Your browser can list every request a page makes: each file it downloads and everything it sends. This list is the network panel, part of the browser's developer tools, and it is easiest to use on a computer, in Chrome or Edge:

  1. Open a tool, for example the PDF compressor, and wait until it says Ready.
  2. Press F12 (on a Mac, Cmd + Option + I) and choose the Network tab.
  3. Press the clear button, a circle with a line through it, so the list starts empty.
  4. Add your PDF and let the tool finish.
  5. Look at the list. Type method:POST in the filter box to see only requests that send a body, the way a file would be sent.

None of the requests carries your file. Some tools download a part they need the first time a file needs it, such as a font for Word to PDF: those come from this site and carry nothing of yours. Google's ad code, which pays for the site, makes requests of its own to Google's ad service, with addresses such as googlesyndication.com and doubleclick.net, as on any site with Google ads. Our code never gives your files to the ad code. To see what a request sent, click it and open its Payload tab.

Check 2: turn off the internet

  1. Open a tool and wait until it says Ready.
  2. Turn off Wi-Fi and mobile data, or switch on airplane mode.
  3. Add a file and let the tool work. It still finishes and saves the result, because the work happens on your device.

In our test on 9 October 2026, every tool but one finished its built-in sample with the test browser's network switched off. The one is Word to PDF: it downloads its converter and fonts from this site the first time a document needs them, so it needs the internet for that. PDF to JPG, PDF to PNG, PDF to Word, the PDF Viewer and Compare PDF read pages with pdf.js, which downloads a font or a decoder from this site the first time some PDFs need one, so a few PDFs need the internet once. The page tools draw their page previews the same way; saving the file doesn't need it. Try it with a file of your own: the compressor's sample is itself a part the page downloads when you press its button.

The PDF compressor after compressing the built-in sample scan from 10.1 MB to 621 KB with the test browser's network switched off, with a Download button, Ready, and the label our test added under it
Our test: the compressor finishing the sample scan with the network switched off.
Merge PDF at a phone's size after joining the three sample PDFs into one 6-page PDF with the test browser's network switched off, with a Download button and the label our test added under it
Our test: Merge PDF on a phone-sized screen, offline.

What our own test sees

We run both checks automatically, with Playwright, a program that drives a browser and records every request it makes. For each tool, our test opens the page, waits until it is ready, loads the sample's own script if the page fetches it only when asked, switches the network off, runs the tool on its built-in sample and lists every request the page and its background workers made. It fails if any request sent data, or if the tool needed the network while it worked.

Our test's request log for the compressor: 15 requests for the site's own files while the page loaded, 1 by our test for the sample's script, 2 while it compressed offline, both answered by the browser's cache, and 0 that sent any data
Our test's request log, set out as a page by the test itself. Open it at full size

In these runs Google's ad loader is answered by an empty stand-in, so our automated visits never load Google's ads. A separate test loads Google's real ad code, with a stand-in publisher ID so no ad views are counted, and fails if any request made while a tool works on a file carries 4 KB or more.

What our pages are allowed to contact

Every page carries a Content Security Policy: a list, sent with the page, of the places it may load things from and send data to. Your browser enforces it and blocks everything else. Ours lets the pages contact this site and Google's ad and font services:

WhatAllowed
Anything not named below default-srcThis site
Programs (scripts) the page may run script-srcThis site, WebAssembly (our engines), the one line that starts an ad, https://*.googlesyndication.com, https://*.doubleclick.net, https://*.adtrafficquality.google, https://*.google.com, https://*.gstatic.com
Styles style-srcThis site, styles written into the page, https://fonts.googleapis.com
Pictures img-srcThis site, pictures written into the page, files the page makes itself, in memory, https://*.googlesyndication.com, https://*.doubleclick.net, https://*.adtrafficquality.google, https://*.google.com, https://*.gstatic.com
Fonts font-srcThis site, https://fonts.gstatic.com
Where the page's scripts may send or fetch data connect-srcThis site, https://*.googlesyndication.com, https://*.doubleclick.net, https://*.adtrafficquality.google, https://fundingchoicesmessages.google.com, https://csi.gstatic.com
Frames inside the page (ads show in frames) frame-srcThis site, https://*.googlesyndication.com, https://*.doubleclick.net, https://*.adtrafficquality.google, https://*.google.com, https://*.gstatic.com
Background workers (where the tools do their work) worker-srcThis site, files the page makes itself, in memory
Plug-ins object-srcNothing
The page's base address base-uriThis site
Where a form may send what is typed in it form-actionNothing
Other sites that may show this page inside theirs frame-ancestorsNothing

This is the policy as the site sends it. The copy inside each page leaves out the last rule, which only works when it comes with the page: default-src 'self'; script-src 'self' 'wasm-unsafe-eval' 'sha256-L9NtTqBLxf1z3sIza7z/JTtm01m91a8xVl07p4WTMYw=' https://*.googlesyndication.com https://*.doubleclick.net https://*.adtrafficquality.google https://*.google.com https://*.gstatic.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; img-src 'self' data: blob: https://*.googlesyndication.com https://*.doubleclick.net https://*.adtrafficquality.google https://*.google.com https://*.gstatic.com; font-src 'self' https://fonts.gstatic.com; connect-src 'self' https://*.googlesyndication.com https://*.doubleclick.net https://*.adtrafficquality.google https://fundingchoicesmessages.google.com https://csi.gstatic.com; frame-src 'self' https://*.googlesyndication.com https://*.doubleclick.net https://*.adtrafficquality.google https://*.google.com https://*.gstatic.com; worker-src 'self' blob:; object-src 'none'; base-uri 'self'; form-action 'none'; frame-ancestors 'none'

The privacy policy page loads no ad code at all.

What our code does with your file

What we can't prove

Questions

If a check shows something you don't expect, please tell us on our contact page.

Compress a PDF