Security and data
Last updated: October 5, 2026
What happens to your files, where they are processed and how they are protected: explained simply, for individuals and IT departments alike.
No documents kept
Your files are processed automatically, then deleted as soon as the result is ready or downloaded. There is no copy, no backup and no history. A daily automatic cleanup also erases any temporary file that might remain, by the next day at the latest.
No analysis
Nobody reads your documents. They are not indexed, analyzed, shared or used to train artificial intelligence. pdffusion has no accounts, no ads and no user profiles.
Encryption
Every connection is encrypted (HTTPS) and the site enforces encryption on every visit (HSTS). The Protect tool encrypts your PDFs with AES-256; the password you choose is never stored.
Where your files are processed
Site, PDF and image tools: Vercel, Paris data center (France, European Union). Word, Excel and PowerPoint conversions: Render, in Frankfurt (Germany, European Union). Files over 4 MB: temporary Vercel Blob storage, under a random name, deleted after use.
Technical safeguards
Security headers (HSTS, blocking the site from being embedded in other pages, protection against file-type confusion), temporary file addresses that cannot be guessed, and a conversion service that only accepts requests carrying a secret token. Every code change is checked automatically (tests, type checks) before going live.
Privacy and applicable law
pdffusion is published in New Brunswick and complies with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA). It collects no personal information about its users: no account, no email address, no tracking cookie. It is built on the same principles as the European GDPR and Quebec's Law 25: data minimization, no reuse, deletion after processing.
For organizations with strict rules
If your rules forbid sending documents to an outside service, install pdffusion on your own servers. The complete software is free, open source and works without an Internet connection: no file ever leaves your network. The installation guide is on the project page. INSTALLATION.md
Transparency
The complete source code is public: your security teams can verify every one of these statements. github.com/mikailoucedrictoure/pdff
Report a vulnerability
Think you have found a security flaw? Report it confidentially from the “Security” tab of the project page: github.com/mikailoucedrictoure/pdff/security · contact@pdffusion.app