Why this exists
The usual way to get a PDF job done online is to hand the file to somebody else's computer. For a conference flyer that's fine. For a bank statement, a settlement agreement, a patient's scan, or a contract with someone else's salary figures in it, it's a decision you were rarely asked to make. Once uploaded, the file sits where you can't reach it: in their storage, in their backups, under whatever their retention policy says this month.
There's no technical reason for most of that. Merging, splitting, redacting, compressing, and extracting metadata are all things a computer can do without shipping the bytes anywhere. Doing them in the browser costs you nothing except giving up the file-somewhere-else architecture, which is why sites that depend on it rarely offer an alternative.
So this is that alternative: 20 tools, each one finished rather than labeled "coming soon", running in a tab you close when you're done.
What "local processing" gets you, and what it doesn't
It removes one specific risk: the document being transmitted to and stored by a third party. That's a real and materially large risk, and getting rid of it is worth something. It's also the whole claim. It doesn't make a process compliant, because compliance is a property of a process, not a tool. It depends on who may open the file, who may keep it, how long it's retained, and what happens on the machine it was already on.
No tool can certify any of that. Any site that calls its PDF converter "HIPAA compliant" or "GDPR compliant" on its own is selling you a phrase, not a guarantee. What this site offers instead is something more useful: a claim you can check yourself. Open the network panel, or unplug the network, and the difference between "runs locally" and "uploads" stops being a matter of policy wording.
The mechanism, including the libraries involved and what they cost you, is on the how it works page. There's also a page that lists exactly what your own browser keeps. It's short, because there are three items.
What it deliberately doesn't do
Each of these is either something a local-first tool can't honestly offer, or something that would need the kind of server whose absence is the point:
- No accounts, no quotas. There's nobody to meter you, so nothing needs to be metered.
- No waitlist, no "pro" tier, no daily limits. The only cost of another document is the electricity your machine was already using.
- No watermark stamped across your output. It's your document.
- No analytics, no advertising, no tag managers. Nothing here has a reason to know who you are.
- No email capture to read the answer later. Results are yours immediately.
- No password recovery. Cracking one is a job for a dedicated service, not a tab pretending to be one.
One entry that used to be on that list has moved. The text extractor can now read a scan rather than only the text layer already inside it, using an OCR engine of about 7 MB that downloads the first time you switch the option on. It reads printed English; handwriting and poor scans come back wrong, and the tool says so before it runs. It's the only tool here that does any of this, and getting that engine to your machine doesn't change the rule the rest of the page is about.
What is here
20 tools, grouped the way the work actually shows up:
Security & privacy — Redact, Strip Metadata, Remove Password, Encrypt PDF, Sanitize PDF.
Pages & structure — Merge PDFs, Organize Pages, Compress, Rebuild & Diagnose, Crop PDF, Compare, Impose & Insert.
Edit & convert — PDF ↔ Images, Watermark & page numbers, Sign & Stamp, Light Edit, Extract Text, Fill Forms, Extract Images, Batch.
Each one is described, with every option, on the home page.
Getting in touch
PDF Sanctum is an independent project, not a company with departments, so there's one email address and no ticketing system: hello@pdfsanctum.com. Bug reports are welcome, especially the ones that say something confusing happened, because that usually means a page failed to explain itself.
