Privacy

Why you should stop trusting your confidential documents to cloud-based online converters

Written and maintained by the KitYards team Published: 9 min read

Almost everybody has done it: a contract needs to be smaller, a scan needs to become a JPG, three PDFs need to become one, and the fastest route is the first result on Google. You drag the file in, wait for the progress bar, download the result and close the tab. The job took ninety seconds. What most people never think about is that the file did not stay on their computer — and that the ninety seconds were only the part they could see.

What actually happens when you press “upload”

A cloud-based converter is, by definition, somebody else's computer. When you drop a file into one, your browser opens an HTTP connection and streams the entire document to a server you have never seen, in a data centre whose location is rarely stated. There it is written to disk, placed in a job queue, picked up by a worker process, transformed, written to disk again as an output file, and exposed through a temporary download link. Depending on the platform, that link may sit behind a CDN which caches it at the edge.

None of that is sinister on its own — it is simply how server-side processing works. The problem is the number of copies it creates. A single conversion routinely produces the uploaded original, the worker's temporary file, the generated output, whatever the CDN cached, and one or more lines in an access log. Add automated backups and you have a document that now exists in five or six places, none of which you control, and none of which you can audit.

The file is not the only thing you send

Alongside the bytes go the filename — which is often more revealing than the content, think “Redundancy_letter_Maria_final.pdf” — the file size, your IP address, your user agent, and frequently the referring page. Office documents and PDFs also carry internal metadata: the author's name, the organisation that owns the licence, the software used, and creation and modification timestamps. Photographs carry EXIF data, which can include the exact GPS coordinates where the picture was taken.

“Files are deleted after one hour” is a policy, not a mechanism

Reputable services do publish retention promises, and many honour them. But a promise is a statement of intent enforced by the service's own code and staff discipline. You cannot verify it, you are not notified if it changes, and it says nothing about the backup snapshot taken twenty minutes after your upload, or about the logs, which are usually governed by a different retention period entirely. A guarantee you cannot inspect is a matter of trust, not of security.

The four risks, in order of how likely they are

  1. 1 Retention beyond what you expected. The output link is often valid for hours, sometimes days, and is frequently a long random URL rather than an authenticated resource. Anyone who obtains that URL — from a browser history, a chat message, a proxy log — can download your document.
  2. 2 Subprocessors you never agreed to. Most small conversion sites do not run their own infrastructure. Your file passes through a cloud provider, possibly an object-storage bucket, sometimes a third-party conversion API. Each hop is another organisation with technical access to the content.
  3. 3 Breach. Storage buckets left publicly readable are one of the most common causes of data exposure on the internet. You are not only trusting the operator's intentions; you are trusting their configuration, on a day you know nothing about.
  4. 4 Jurisdiction and lawful access. A file stored in another country is subject to that country's disclosure regime. For a holiday photo this is irrelevant. For a client's medical report or an unfiled patent application it is not.

Why this matters more than it did five years ago

Under the GDPR — and equivalent regimes elsewhere — the person who decides why and how personal data is processed is the data controller. If you are a lawyer, an accountant, a recruiter, a doctor or an HR manager, and you upload a document containing somebody else's personal data to a free converter, you have engaged a data processor. Doing that lawfully requires a processing agreement, a lawful basis, an assessment of transfers outside your jurisdiction, and an entry in your records of processing. Practically nobody who uses a free converter in a hurry has done any of that.

The professional exposure is real

Legal professional privilege, medical confidentiality, banking secrecy and standard commercial NDAs all impose duties that do not pause because a deadline is tight. In most of these regimes, disclosing a document to an unnecessary third party is a breach whether or not anything bad subsequently happens to the file. The exposure is created at the moment of upload, not at the moment of misuse.

What your browser can already do without a server

The habit of uploading is a hangover from an era when browsers genuinely could not do this work. That era ended some time ago. A modern browser can read a file from disk with the File API, hold it in memory as an ArrayBuffer, decode and re-encode images through the Canvas API, run heavy libraries compiled to WebAssembly, rebuild a PDF's object graph in JavaScript, compute cryptographic digests with Web Crypto, do all of it on a background thread with Web Workers, and hand the result back through a temporary local blob URL that never leaves the machine.

That is exactly how every tool on this site is built. There is no application server behind KitYards to receive a file, because the site is a static build: HTML, CSS and JavaScript on a CDN. When you drop a PDF into one of the tools, the bytes are read into your own tab's memory, transformed there, and offered back to you as a download. Nothing is transmitted, which is a stronger guarantee than any retention policy can offer, because it does not depend on anyone keeping their word.

The performance objection is out of date

The old argument for server-side processing was raw power. On a document-sized workload that argument has collapsed: the round trip of uploading twenty megabytes and downloading the result is usually slower than doing the work on a five-year-old laptop, and it fails completely on a poor connection. Local processing also scales perfectly — every visitor brings their own CPU — which is why it can be free without limits, watermarks or a queue.

Reorder or delete pages without the document leaving your device

Drop in a PDF, drag the page thumbnails into the right order, remove what should not be there, and download the rebuilt file. The pages are rendered and rewritten inside your browser.

Organize pages

How to check whether a tool is genuinely local

You do not have to take anyone's marketing copy at face value, including ours. Five minutes of checking settles the question, and the tests work on any site.

  1. 1 Watch the network. Open your browser's developer tools, switch to the Network tab, clear it, then use the tool. A local tool shows the page's own assets and then nothing more — no POST request carrying your file, no multi-megabyte upload.
  2. 2 Pull the plug. Load the page once, then disconnect from the internet or switch on airplane mode and use the tool. Genuinely local processing keeps working. A cloud converter fails immediately.
  3. 3 Look at the response time. If a 40 MB file is “processed” in a fraction of the time it would take to upload it on your connection, the work happened locally. If the wait scales with your upload speed, it did not.
  4. 4 Check what the site asks for. An account, an email address for the download link, or a file-size cap that unlocks with a subscription all imply a server doing the work and a business model built on it.
  5. 5 Read the policy for the word “retention”. A site with nothing to retain says so plainly and briefly. A long, hedged section about how long files are kept tells you they are kept.

Turn PDF pages into JPG or PNG, locally

Each page is rasterised in your browser at the resolution you choose and downloaded as an image or a ZIP. Useful when you need to send one page without releasing the whole document.

Convert PDF pages

A practical policy for a small team

Blanket bans on online tools do not survive contact with a deadline; people simply stop mentioning what they use. A workable rule is narrower and easier to follow.

  • Classify by content, not by file type. Anything containing personal data, financial details, credentials or unpublished commercial information is never uploaded to a third party.
  • Prefer tools that run in the browser for routine document work — compressing, splitting, reordering, converting. These are precisely the operations that no longer need a server.
  • Where a server genuinely is required, use a service your organisation has assessed and has an agreement with, not the first search result.
  • Strip metadata before sharing files externally, and check the filename. “Offer_Letter_v3_reject_backup.pdf” has told the recipient something you may not have intended.
  • Write the rule down in one paragraph. A policy nobody can recite is not a policy.

The short version

Uploading a document to a free converter is not reckless because the operator is presumed dishonest. It is reckless because it creates copies you cannot count, in places you cannot see, governed by promises you cannot verify — in exchange for a convenience your own browser can now provide. For the everyday jobs of compressing, splitting, merging, reordering and converting, there is simply no longer a reason for the file to travel. Keep it on your device, and the entire class of risk disappears.

Combine documents without handing them over

Merge several PDFs into a single file entirely in your browser — no account, no size limit imposed by a server, and no copy left behind on one.

Merge PDFs

The tools used in this guide

Free, no sign-up, and everything runs on your own device.

Keep reading