ZeroPDF
Security Page
Your documents stay with you. This page explains, in plain language, how ZeroPDF processes PDFs locally, which data may exist separately for account, billing, and operation of the service, and which security limits users should keep in mind.
- Last updated
- July 22, 2026
- Operator
- Luís Cardoso, independent developer in Portugal
- Contact
- support@zeropdf.app
1. Core principle
Your documents stay with you. ZeroPDF's main tools are designed to process PDFs locally in the browser or device, reducing the need to send file contents to ZeroPDF servers.
Local processing improves privacy and control, but it does not eliminate all risk. Final security also depends on the browser, device, network, installed extensions, and how the user handles their files.
2. How it works
- You select the PDF on your device.
- The browser reads the file to prepare the chosen operation.
- The tool processes the document locally.
- The output is created on the device itself.
- The user downloads the exported file without ZeroPDF keeping a server copy of the PDF for that local operation.
3. What ZeroPDF can and cannot see
During normal local processing, the PDF contents and exported output should not be sent to ZeroPDF servers merely to run the tool.
ZeroPDF does not receive for local processing
- PDF contents.
- Individual document pages.
- Text extracted or handled locally from the PDF.
- Images embedded in the PDF.
- Visual signature representation placed locally.
- PDF password applied locally during export.
- The exported output downloaded to the device.
ZeroPDF or providers may process separately
- Account and identity data when authentication is used.
- Session and sign-in state.
- Pro status and its validation.
- Elements needed for checkout, billing, and the billing portal.
- Technical logs, errors, and operational events.
- Analytics subject to configuration and applicable consent preferences.
- Information the user sends to support.
4. Local processing and network access
Local does not mean total absence of network use. The app may use network connections to load assets, authenticate users, manage subscriptions, process payments, update Pro status, and run authorized analytics.
Those requests should not include PDF contents merely to perform normal local document operations.
5. Offline and PWA behavior
Some features may remain available after the necessary assets have been loaded or cached. Offline behavior varies depending on the browser, cache state, device, and which chunks or models are already available.
OCR may depend on models already cached. Offline Pro access lasts for no more than seven days after eligible online validation. Not every tool or service state is guaranteed to work offline in all circumstances.
6. Authentication and Offline Pro
Clerk manages session, identity, and authenticated user state.
Separately, ZeroPDF may use its own signed token to confirm temporary Offline Pro status on the device for the maximum allowed period. This mechanism does not replace periodic online validation.
7. Payments
Checkout, card handling, and subscription management are processed by Stripe. PDF documents processed locally are not part of the normal payment flow.
8. Providers
ZeroPDF uses confirmed providers only for their known roles:
- Clerk, for authentication, session, identity, and access-related account metadata.
- Stripe, for checkout, billing, and subscription management.
- Cloudflare, for infrastructure, delivery, and runtime technical components.
- Google Tag Manager and Google Analytics 4, for loading and measuring the technologies currently configured on the site.
9. Confirmed technical measures
- The public service is intended to be accessed over HTTPS on the production domain.
- Local PDF processing for the main document operations.
- Signing of the Offline Pro access token.
- Separation between document processing and account or subscription data.
- Subscription-state validation for Pro access.
- Reliance on the browser, device, and required libraries as part of the security model.
Additional safeguards will be documented publicly when they are implemented and confirmed.
10. Limitations
- Malware, malicious extensions, or spyware on the device can compromise security and privacy.
- Compromised or shared devices increase the risk of improper exposure.
- Outdated or incompatible browsers can fail or reduce expected protections.
- Vulnerabilities in dependencies, the browser, or the operating system can affect the service.
- Low memory or hardware limitations can interrupt local processing.
- Malformed, corrupted, or very complex documents may fail or produce imperfect results.
- No technical solution eliminates all risk.
11. Recommended user practices
- Keep the browser and operating system updated.
- Use a protected and trusted device.
- Limit extensions to trusted sources.
- Choose strong passwords for accounts and protected PDFs.
- Keep backups of important originals.
- Review exports before distribution or professional use.
- Close documents and sign out on shared devices.
12. Responsible disclosure
Researchers and users may report potential vulnerabilities to support@zeropdf.app.
Where possible, include a description of the issue, reproduction steps, impact, browser or version used, and enough technical detail to investigate. Do not send real personal documents or unnecessary sensitive data.
A reasonable period should be allowed before public disclosure so the issue can be assessed and addressed proportionately.
13. Security status
14. Contact and updates
For security questions, responsible disclosure, or clarifications about this page, you can contact:
The date on this page will be updated when there are material changes to the information published here.