Is NoUploadPDF safe?

Last updated: 10 October 2026

Security and privacy in one line: the safest file is one that never leaves your device, so no NoUploadPDF tool has an upload step. This page says what protects you, what your browser enforces, what we do not control (Google's ad code is one of those things) and how to tell us about a problem.

Your files stay on your device

Every tool on this site is a small program that runs inside your own browser, on your phone or computer. When you add a PDF, the browser hands it to the page, the tool works on it in your device's memory, and your browser saves the new file like any other download. There is no upload step anywhere, so a copy of your file never reaches our server. That is the heart of our security, and it is a simple idea: we can't leak, sell or forget to delete a file we never received.

You don't have to take our word for it. The two checks take about a minute: watch your browser's network panel while a tool works, or switch the internet off and see the tool finish anyway. Our own test does the same for every tool and keeps a request log. How our tools work explains each step, with a picture, and the engine each tool uses. Everything below is about the parts around that idea: the rules your browser follows, what our code does, and the things no website can promise.

What your browser enforces

Every page we send comes with a few short instructions called response headers. Your browser reads them before it shows the page, and then follows them itself, whatever any script on the page tries to do. They are rules for the browser, so they keep working even if a script on the page misbehaves. This table lists each security header the site sends and what it tells your browser:

HeaderWhat it tells your browser
Content-Security-PolicyThe places our pages may load anything from or send anything to: this site and Google's ad and font services. Your browser blocks every other site. The same policy says no other site may show our pages inside its own, and no form on our pages may send what is typed in it anywhere.
Strict-Transport-SecurityAlways use the secure https:// address for this site, for a year after each visit, so no one on your network can swap in a fake copy over plain http.
X-Content-Type-OptionsTreat each file only as the kind of file the site says it is, so a file can't be run as a script by mistake.
Referrer-PolicyWhen you follow a link to another site, tell it only our site's address, not the page you were on.
Permissions-PolicyNo part of our pages, ads included, may use your camera, microphone or location.
Cross-Origin-Opener-PolicyAnother site that opens one of our pages in a new window can't reach into it.

The most important one is the Content Security Policy, a list of the places a page may load things from and send data to. Think of it as a second lock. The first lock is that no tool has an upload step. The second makes your browser refuse requests to any site that is not on the list, which is meant to catch a mistake in our own code, or a script that has no business being on the page. Every site the policy allows is listed on the proof page, made from the policy itself, so the list can't fall behind what the site sends.

You can read these headers yourself:

  1. On a computer, open any page of this site in Chrome or Edge and press F12.
  2. Choose the Network tab and reload the page.
  3. Click the first request in the list, the page's own address, and look under Response Headers.

If you are comfortable with a terminal, curl -I https://nouploadpdf.online/ prints the same headers.

What our code does and doesn't do

Google's ad code: what we don't control

NoUploadPDF is free because Google's ads pay for it. To show them, our pages load Google AdSense's ad code. It is Google's code, not ours, and it is the one part of a page we don't write and can't fully see into, so here it is in plain words.

Our server

The site is a set of ready-made files, sent out by an ordinary web server. We have no program on the server that accepts a file, because no tool needs one. The server's job is to send you the page and the tool.

Every page travels over an encrypted https connection. If someone types an old http:// address, the server sends them on to the https one, and the Strict-Transport-Security header in the table above asks your browser to keep using https for this site for a year after each visit.

Like most web servers, ours may keep short technical records of page requests, such as IP address, date and time, the page requested and browser type. They are used only to keep the site secure and working, and they never include your files. Pages are checked with the server on every visit, so when we fix something you get the fixed page the next time you open it. Your browser keeps the engines and scripts for next time, and they get a new name whenever they change.

What is outside our control

Some things are outside what any website controls. We would rather tell you than leave you to find out:

How to report a security problem

If you think you have found a security problem, please email info@nouploadpdf.online. You don't need to be an expert. It helps if you tell us:

Please don't attach a file with private details. NoUploadPDF never needs your files to work, and a description is almost always enough. If you think we need a file to see the problem, say so in your first message and leave it out until we reply.

The same address is in our security.txt file, the standard place (RFC 9116) where people who look for security problems check first. It is renewed each time we publish the site.

We reply to a security report within 7 days. We don't run a bounty programme. NoUploadPDF is run by one person, and a clear report is the best help in getting a problem fixed. For a question about a tool that is not about security, our contact page is the place.

Keep reading

Compress a PDF