PDF tools that never
upload your files
For documents that can't leave the building — finance, legal, and healthcare at work; a tax return, a medical letter, or a bank statement at home. Parsing, rendering, and rewriting all happen in your browser. There's no upload endpoint because there's no backend. You don't have to take that on faith. This page counts its own outbound requests.
Drop a PDF here
or choose a file · pasting with Ctrl+V works too
20 tools, all of them finished
Every tool here is finished. No daily limits, and no ads stamped across your pages.
Join several files into one, drag to reorder, and pull just the pages you want from each.
A thumbnail grid you can reorder, rotate, delete and duplicate, then export as a new file.
Lossless restructuring and image re-encoding, run separately. You keep whichever came out smaller.
A qpdf check first, then the internals get rewritten: cross-reference table rebuilt, unreferenced objects dropped, streams recompressed, and one last check. If a file is beyond saving, it tells you straight.
Box off account numbers, ID numbers, figures. The text underneath is destroyed, not covered up.
Export pages as high-resolution PNG or JPG in a ZIP, or combine a stack of scans into a PDF.
Tile a watermark or place it in one spot, Chinese included. Add page numbers in your own format.
See which author name, which machine, which software version a file is carrying. Then wipe it.
Trim the white border off a scan, or let it snap to the content edges. Writes the page boundary, not the content.
Use the password you already have and get back a file you can print and merge. RC4 and AES-128/256. No cracking.
Put a lock on the file: AES-256 encryption, separate passwords for opening and for permissions, and restrictions on printing, copying, form filling, and changes.
Draw a signature, upload a stamp, or just type a name. Drag it where it goes and pull the corners.
Two versions, page by page. A pixel diff shows what moved; a line-level text diff says what the change was.
Cover a stale line, retype the right one, drop in an image. And an honest note about what that does and doesn't hide.
Pull the text layer out page by page into TXT or Markdown. Chinese included. Scanned pages can go through OCR — English only, and it tells you what it could not read.
Read the fillable fields a PDF already has, fill them in, and export — either kept editable or flattened in place.
Clean out the parts of a PDF that can run or reach out: JavaScript, launch actions, embedded files, external links, and attachments.
Export the images stored in a PDF rather than a rendering of the page. JPEG comes out byte-for-byte; other formats are re-encoded as PNG, all in a ZIP.
Drop in a whole folder, pick one action, strip metadata, sanitize, compress, repair, encrypt, unlock, or export text, embedded images, or page images, and get everything back in a ZIP.
Fit several pages onto one sheet (2-up / 4-up), arrange a booklet, or insert pages from another PDF — all aimed at printing and binding.
How this differs from the usual online PDF site
| What matters | A typical cloud PDF site | PDF Sanctum |
|---|---|---|
| Where your file goes | Uploaded to their servers, usually kept for hours or days | Never leaves your machine. It's processed in your browser, never uploaded |
| Who can see it | Interception in transit, server caches, anyone with server access | None of those exist here |
| Speed | Limited by your upload bandwidth, so large files stall at 90% | Limited by your own CPU, with no network wait |
| Offline | ❌ Doesn't work at all | ✅ Works once the page has loaded |
| Limits | Free quotas, membership walls, and a watermark forced onto the output | None, other than the memory you have |
| Can you check? | You have to take their word for it | Open DevTools, or unplug the cable and see |
Don't believe it? Three ways to check
Pull the plug
Load the page, then turn off Wi-Fi or unplug the network cable. Open any tool and run a file through it. It should all work.
Watch the network panel
Press F12, open the Network tab, tick "Preserve log", and drop a file in. Nothing new should appear except your own file.
Read the source
There's no backend. The whole site is a handful of HTML and JavaScript files, and the libraries travel with it instead of loading from a CDN.
Common questions
Will a large file freeze my browser?
Work happens in chunks, and the main thread is handed back every couple of pages, so the interface keeps responding. The real ceiling is how much memory your browser gives a tab; a few hundred megabytes is normally fine. If a document runs into the thousands of pages, split it first.
After redacting, can someone still extract the text?
No. A lot of tools just draw a black rectangle on top of the page. The original text is still underneath, selectable and copyable, which makes the redaction fake. Here the page is rendered to a bitmap and the covered area is burned into the pixels, so the text layer is gone and there's nothing left to extract. The trade-off is that those pages stop being searchable and selectable.
Why does compression sometimes make a file bigger?
A text-heavy PDF is already packed tightly, so re-encoding its pages as images takes up far more room. The compressor runs both routes and gives you the smaller result, and it shows you both numbers instead of quietly hiding the worse one.
Can it handle encrypted PDFs?
Anything with an open password has to be unprotected first. The metadata tool can read an encrypted file's info in read-only mode, but operations that rewrite the document can't run without the password. That's a limit of the PDF format, not a shortcut taken here.
