Skip to main content

Guides

How to check that a PDF tool does not upload your file

· 6 min read

Open your browser's developer tools, switch to the Network tab, run the PDF tool on a file, and look for a large request sent out while it works. A tool that uploads your file shows a POST or PUT request about as big as the file itself. A tool that works locally shows none. For a stronger test, load the page, set the Network tab to Offline, and run the tool again: if it still produces a file, the file never needed a server.

TL;DR: two tests. One, watch outgoing request sizes while the tool runs. Two, go offline after the page loads and run it anyway. On AstralPDF the tools pass both; you will still see small analytics and ad requests, which is expected and explained below. The test is not specific to us: use it on any PDF site.

How do I watch the Network tab while a tool runs?

  • Open the tool page, then open developer tools (F12, or Cmd+Option+I on a Mac) and choose the Network tab.
  • Click the clear button so the list is empty, and keep the tab open.
  • Add a test PDF and run the tool, for example Split PDF with a page range.
  • Look at the list. Sort by the Size or Transferred column, largest first, and check the Method column for POST or PUT.
  • A PDF upload shows up as a request of roughly the file's size going to the tool's own domain or a storage service. Nothing like that should appear for a local tool.

Use a file big enough to be obvious. A 5 MB PDF cannot hide inside a request of a few hundred bytes. Chrome's own documentation of the Network panel covers the columns and the clear and filter controls.

How do I run the offline test?

Load the tool page completely first, so its code is already in your browser. Then, in the Network tab, change the throttling menu from No throttling to Offline. Add a PDF and run the tool. A tool that processes files locally downloads its result as usual, because the work happens in the page you already have. A tool that depends on a server shows an error, a spinner that never ends, or a failed request in red.

You can also simply turn off Wi-Fi after the page has loaded. The result is the same, and it needs no developer tools.

Try it on the Split PDF tool: load the page, go offline, split a file and watch it still work.

What will I still see in the Network tab on AstralPDF?

The page itself loads Google Analytics through Firebase and a Google AdSense script, so requests to Google domains appear when the page opens and as you scroll. They are small, and they do not contain your PDF. Some tools also send one small usage event when a file is processed: the tool's name, and for some of them the file size, the page rotation, or a count of images. File names and file contents are not part of those events.

What you seeWhat it isShould it worry you?
Requests to Google analytics or ad domains at page loadVisit statistics and adsNo file data; this is the normal cost of a free site
A small request right after you run a toolA usage event: tool name, sometimes file size or a countNo file name or contents
A large POST or PUT that matches your file's sizeAn uploadYes. Stop using that tool for private files
The tool fails when you are offlineIt needs a serverYes, for confidential files

The download itself is not a network request either: the finished file is built in memory and saved straight from the tab, which is why you see no file transfer at all.

Is the AstralPDF developer API the same thing?

No, and it is worth knowing the difference. The browser tools on this site process your file locally. The separate developer API is built for scripts and servers, so a call sends the file to the server in the request and gets the result back. If you test the API from a script, you will see the upload, because that is what it is for.

What is the safe checklist for a confidential PDF?

  • Run the offline test once on the tool, using a harmless file, before using it on a private one.
  • Keep the Network tab open for the real file and confirm no request is close to the file's size.
  • Remove or protect sensitive pages before sharing the result, and keep the original private.

See also: password-protecting a PDF properly: set a password on the result before you send it anywhere.

See also: how to merge PDFs without uploading them: how merging stays in the browser, and when uploading is the better choice.

Frequently asked questions

How can I tell if a PDF tool uploads my file?

Open the Network tab in your browser's developer tools, run the tool, and look for a large POST or PUT request about the size of your file. A tool that processes files locally shows none.

Does AstralPDF upload my PDF?

No. The tools run in your browser tab. You can load a tool, go offline and still get a result. The page does make small analytics and ad requests that contain no file contents.

Why do I see requests to Google when I use AstralPDF?

The page loads Google Analytics through Firebase and a Google AdSense script. Those requests are small and unrelated to your file.

Does the offline test work for every PDF tool?

It works for any tool whose processing runs in the page. If a tool fails offline after the page has loaded, it depends on a server.

Is the AstralPDF developer API also private in the browser?

It is a different service. API calls send the file to the server in the request, by design, and return the result. Only the browser tools keep the file on your device.