Some files should not go onto a stranger’s server just so you can remove four names. A client file. An HR investigation. A document covered by a confidentiality agreement.
Dragging a PDF onto a web page feels like a small action. If that tool processes files on a server, it is a transfer of the whole document, before any redaction happens.
Deletion promises are still promises
An uploaded file may pass through memory, temporary storage and backups. The exact path depends on the service. A vendor saying “deleted after one hour” may be telling the truth, but you cannot confirm its internal cleanup jobs from your browser.
That does not make every server-side tool unsafe. It means choosing one involves trusting the operator and checking whether that processing is appropriate for your document.
A web tool can work locally
There are two very different kinds of PDF website. One uploads your file, processes it elsewhere and returns a download. The other runs PDF code inside your browser and reads the file on your device.
The interface can look identical. “Private” and “secure” do not tell you which model you are using.
Desktop software is another local option. It may be the right answer if you already have a suitable application installed. You still need its actual redaction feature, not a drawing tool.
Test with a harmless file
Make a test PDF with no private information. Use that for the checks, not a patient record or client contract.
Open the browser’s developer tools and select Network. Enable Preserve log. Load the test PDF and complete the workflow, including export.
Look at outgoing requests and their payloads. A POST or PUT carrying the file is a clear upload signal. Do not rely on matching file size alone: uploads can be split, compressed or encoded. A large incoming response is not evidence of an outgoing document transfer.
Then test without a network connection. Let the application and any required assets load, disconnect, open the harmless file, redact it and export.
If the complete job works while disconnected, that processing happened locally. It does not prove the application will never send anything later, which is why the network check matters too.
Local does not mean no downloads
The page itself has to load. OCR tools may fetch recognition models on first use and cache them afterwards. Those downloads are different from sending your PDF to a server.
A failed first offline attempt may mean an asset was not downloaded yet. It is not, by itself, proof of server-side processing.
I build hddn. Its document processing runs in the browser; OCR and detection assets may download when first needed. Detection produces candidates for you to review, not a promise that every sensitive detail was found.
Run the checks on the version you are using. Tools change, and the interface does not have to change with them.
Originally published in hddn’s guides.
Top comments (0)