PDFEnrich · Trust center
Privacy boundaries you can understand before choosing a file
Supported core tools process document contents in your browser. A private account copy, a share link, analytics, and support each use a separate, clearly stated data path.
Reviewed August 3, 2026 by PDFEnrich Product Engineering.
Browser processing
The editor and supported PDF tools process file contents in the current browser tab. Choosing a file does not send its bytes to PDFEnrich merely to run those tools.
Signed-in private account copies
Firebase Authentication handles sign-in. When the authenticated account-document API is configured, PDFs opened while signed in automatically sync as finished private PDFs with minimal version metadata for cross-device access. Older browser-only documents are not bulk uploaded; one is imported when the user opens it while signed in. Workspace state, extracted OCR text, thumbnails, undo history, and the signature library are not uploaded as separate cloud data.
Sharing is a separate choice
Creating a sharing or signing link uploads the exported PDF separately from private account storage. Anyone with the unrevoked bearer link can open or download that PDF until the link expires.
Local storage
Guest and signed-in work may be saved in browser storage when space allows. You, the browser, private-browsing rules, or device cleanup can remove it.
Product analytics
After a user allows optional analytics, bounded events may be processed by Google Firebase and Google Analytics. They can include route, broad traffic and device categories, tool, broad file-size and page-count buckets, outcome, and duration, but exclude search terms, full referring URLs, filenames, file contents, extracted text, document URLs, signatures, form values, and user-entered document data.
Support and service providers
Support requests store the reply email, category, message, account ID when signed in, and submission time in the owner-only inbox. Vercel hosts the public application; Google Firebase provides authentication, sharing, analytics, App Check, reCAPTCHA Enterprise, and Google Sign-In; Supabase Edge Functions, Postgres, and private Storage provide signed-in account PDF synchronization.
Deletion
Clear site data to remove guest browser records. Signed-in users can delete saved documents or permanently delete their account and associated document records, cloud payloads, sign-in directory profile, linked analytics events, and account-linked support requests from Settings. Anonymous events cannot always be linked back to a person.