Is PDFCheetah safe?
PDFCheetah does not upload your PDF: every tool runs in your browser, so the file is read, changed and saved on your own device, and there is no copy of it on our side to lose, read or hand over. The site does send itself a short usage record — which tool was used, whether the job succeeded and roughly how long it took — but never your file, its name or its size, and you can watch every request it makes in your browser's network panel.
Updated
Where your file is processed
Opening, previewing, editing and saving a PDF all happen locally in your browser. The file is read from your device, worked on there, and written back there. It is not sent to us, and there is no copy of it on our side to lose, read, or hand over.
Your working copy stays on your device. Every tool page carries a Delete local files control, and anything more than fifteen minutes old is cleared the next time the site starts.
What the site sends over the network
Six files do the PDF reading and writing. Three of them may open no connections at all. The other three may fetch exactly one kind of thing, from this site's own address: replacement fonts and character maps, for a document that did not bring its own. Nothing else is reachable from any of the six, and your document is never part of what is fetched.
PDFCheetah is not silent. It sends its own server a short usage record: which tool was used, whether the job succeeded, and roughly how long it took. File names and sizes are never included, and the value tying one visit together is random and gone when the tab closes.
Each kind of usage record, and the fields each one carries beside the visit value above:
- A page opens: which kind of page it was: a tool, the tool list, a marketing page, a legal page, an account page, or anything else. Not its address.
- You arrive from one of our own adverts: which advertising service the advert ran on. Not the advert, the keyword or the click.
- A tool opens: which tool, and roughly how you got there: from the home page, from the tool list, from another tool, or none of those.
- You choose files: which tool, and how many files as a range: 1, 2 to 3, 4 to 10, or more than 10.
- A job starts: which tool, and a broad class of how capable your device is.
- A job succeeds: which tool, and how long it took as a range: under a second, 1 to 5 seconds, 5 to 30 seconds, or longer.
- A job fails: which tool, how long it ran as a range, and an error code from a fixed list.
- You leave the page while a job is still running: which tool, and how long the job had run as a range.
- A document will not open: which tool, and an error code from a fixed list.
- You download a result: which tool, and that the result went to a download.
What is never sent
Nothing from inside the documents you open: not their contents, names, sizes, page counts, or anything read out of them. We do record which tool ran, whether it worked, and how many files you chose as a range rather than an exact number — facts about the job you started rather than about the files themselves.
No document contents, filenames, passwords or document metadata in any diagnostic or error report.
No advertising networks, social media pixels, or third-party tracking scripts.
If your browser sends Global Privacy Control — a setting you turn on once, in the browser or an extension, rather than one we ask you for — we take it as an objection to the usage record and collect none of it. Nothing is counted, nothing is held on your device waiting to be sent, and nothing is sent. You do not have to ask us, and there is nothing here for you to click.
What our server records, and for how long
Serving the site. Like any website, our host records the request: your IP address, browser user-agent, the page requested, and the time. This is needed to deliver the site and to protect it from abuse.
Visiting a page. We record which kind of page you viewed — a tool, the tool list, a marketing page, a legal page, an account page, or anything else — and, if you arrived by clicking one of our own adverts, which advertising service it ran on, such as Microsoft Advertising. If you arrived from an AI assistant — ChatGPT, Claude, Perplexity, Microsoft Copilot or Gemini — our server adds one to that day's count for that assistant, and the count holds only the day and the assistant's name. Nothing else about the visit: not the address of the page, not what you typed into a search engine to find it, not which advert you clicked, and not the click identifier those services add to links. It carries no cookie, writes nothing to your device, and uses no identifier that outlives the tab you are in or that can be linked to another visit.
Using the contact form. We receive the name, email address, subject and message you type into it, and, if you choose one, your answer to how you heard about us, picked from a short fixed list.
Asking to hear about Pro. If you give us your email address on the pricing page, we store that address so we can tell you once when Pro is ready. The only other thing stored with it is your answer to how you heard about us, if you choose one from the short fixed list beside it.
Server request records: kept by our host for a short period, for delivery and security. We take no copy of our own. Where a request is rate-limited — the two forms and the usage record's own beacon, which means every visit rather than only the visits that submit something — your address itself is still never written down: it is turned into a scrambled fingerprint that cannot be turned back, and only that is stored, next to a count of how many requests of that kind have arrived from it. The scrambling key changes every hour, and each old key is deleted together with the counts it was used for: usually within minutes, and at the latest by the following night, when a scheduled clear-out runs. Once a key is gone the link cannot be rebuilt, even by us. Two honest limits: while an hour is running, someone holding both the key and the counts could work out which addresses they came from — so treat this as a short-lived stand-in for your address rather than as anonymous — and on a quiet night an old key can sit unused until that clear-out reaches it.
Tool usage records: 28 days, after which they are deleted automatically. The same applies to the page-view records described above, which are kept in the same place and expire on the same schedule. What remains is daily totals — how many times a tool ran and how many succeeded — which are not about any one visit and cannot be traced back to one. The count of arrivals from AI assistants is a daily total from the start, and is kept the same way.
Contact form messages: for as long as needed to deal with what you wrote about.
An email address you gave us for Pro: until Pro launches and we have written to you, or until you ask us to remove it.
Who runs PDFCheetah
PDFCheetah is operated by an individual rather than a company, trading as PDFCheetah.
Questions about any of this can go to privacy@pdfcheetah.com or through the contact page. Both reach the same person.
We keep this list short deliberately, and it is complete:
- Cloudflare, which hosts and delivers the site, and stores the tool usage records described above, the daily counts of arrivals from AI assistants, your contact form messages, and any email address given for Pro, each with your answer to how you heard about us if you gave one.
- Hostinger, which handles email for pdfcheetah.com, so anything you send to the address above passes through them on the way to us.
What happens to a password you type
No. The document is encrypted in your browser and saved on this device. Neither the file nor the password is ever sent anywhere, which is also why nobody here can recover the password for you.
No. The document is decrypted in your browser and the unlocked copy is saved on this device. Neither the file nor the password is ever sent anywhere, because there is no server involved in the work.
How large a file you can use
No size limits tied to a plan. What you can process depends on your device, and the tool shows the ceiling before you choose a file.
How to check this yourself
Watch the network while the tool runs. Open your browser's developer tools, go to the Network panel and turn on Preserve log. Load the tool page, choose your PDF, and run the job. A tool that uploads shows a request going out roughly the size of your document. A tool that does not shows nothing of the kind.
Turn the network off and run the job again. With the page already open, tick Offline in the same panel, then choose a file and run the tool. If it finishes and hands you a result, the work happened on your device.
One trap: do not reload after going offline. Some tools that do all their work on your device still fetch their code fresh each time, so the reload fails even though nothing was uploaded.
Works offline once you have opened a tool. Measured end to end on Rotate in Chrome; Safari and iPhone are unverified.
An automated check drives all twenty tools in a real browser, records every request, and fails if your document's bytes or a phrase from inside it turn up in one. Merging, splitting, compressing, organizing, rotating, deleting PDF pages, turning JPGs into a PDF, turning PNGs into a PDF, saving pages as JPGs, saving pages as PNGs, extracting pages, cropping, removing blank pages, reversing page order, adding page numbers, watermarking, editing, signing, password-protecting and unlocking: every tool on this site, with none left out. One more cannot be published without one — our build fails if any published tool is missing this check.
What this does not cover
- The claim covers this application, not your computer. A browser extension that reads pages, other software on the machine, or another person using it, sit outside what a website controls.
- Our server sees what any server sees when you load a page: the request, and the address it came from.
- No outside firm has audited this.
For how online PDF tools in general are built, and how to tell which kind any site is, read Are online PDF tools safe?