The short version: your documents never leave your machine, because nothing in the app can send them anywhere.
Last updated 2 October 2026.
Every PDF you open is read, rendered and edited on your own device. No document, and no part of one, is sent anywhere — not its contents, not its name. The browser version does the same work in the page itself, and the Chrome extension declares no permissions and no host permissions at all, so it cannot reach a server even if something in it tried. You can check that: the source is public, and the extension's manifest is two lines.
Nothing about a document is collected, logged or transmitted. Not its contents, not its name, not the fact that you opened one. There is no analytics, no telemetry and no crash reporting, in any build.
All of it stays in your own browser or on your own disk. None of it is sent anywhere, and the whole list is:
No cookies, and nothing that identifies you across sites.
An account, which is optional and only needed for the two Supporter tools (watermark and OCR). If you sign in, an account service at auth.openpdfedit.com handles it, and it sees what any sign-in service must: the identity you sign in with, your credit balance, and the fact that you unlocked something. It never sees a document — the app has no way to send it one.
Signing in is the only network request the app makes on your behalf. Never signing in means it makes none at all.
One exception, and only where it cannot be otherwise: opened inside Telegram as a Mini App, the page loads Telegram's own bridge script from telegram.org — that is what makes it a Mini App rather than a web page in a webview. It is fetched only when the app is actually running inside Telegram, never in an ordinary browser, and it carries no document either. Documents stay on the device there too: the app takes files through the webview's own file picker rather than through the bot, which is the route that would put them on Telegram's servers.
Recognising text in a scan happens on your device too. In the browser, the recogniser and its language data are downloaded once from this site — not from a third-party CDN, which is what the underlying library would do by default — and then cached, so it works offline afterwards. The page being recognised is never sent anywhere.
The two Supporter tools cost 1,000 credits once, for both together. Credits are bought on the account service's own pages, never inside the editor, and payment is handled entirely by its payment processor. OpenPdfEdit never sees or stores a card number, a wallet seed phrase or a private key.
On iPhone, iPad, Mac and Android the credits are bought through the store instead — StoreKit on Apple's platforms, Google Play Billing on Android — because each store requires that for anything unlocked inside its own app. The purchase happens in the store's own sheet. What reaches us is a transaction identifier: we ask Apple or Google whether it is genuine, and add the credits. No card number, billing address or store account identity comes to us, and the store is never told which document you had open.
The Chrome extension requests none. Its manifest declares no permissions and no host permissions at all — not tabs, not storage, not activeTab. Files are opened through the browser's own file picker, which you drive; the extension never gets standing access to your filesystem, your tabs or any website.
The desktop app asks the operating system for nothing beyond the file you point it at.
The Android app declares two permissions and no more: internet access, for the account service and the store and never for a document, and network state, which the billing library asks for. There is no storage permission. Files come in and go out through the system document picker, which you drive, so the app only ever sees the file you chose.
This site counts page views, and which buttons are clicked, with a self-hosted, privacy-preserving analytics service. It sets no cookie, records no personal data, and does not follow you to other sites. It never sees your documents, and the app itself contains no analytics.
Your data is never sold, rented or shared for advertising or any other purpose. The only outside services involved at all are the sign-in provider you choose, if you sign in; the payment processor, if you buy credits; and Telegram, if you deliberately open the app inside Telegram. Each is involved only for the action you took, and none of them receives a document.
Downloads of the desktop app are served by GitHub, which will see your IP address the way any file host does.
Everything stored on your device can be removed from inside the app: clear the recent list, delete a saved signature, sign out. Clearing the site's data in your browser, or uninstalling the extension or desktop app, removes all of it at once. None of it needs asking us, because none of it is ours.
Your account goes from inside the app too: Account, then Delete account. It destroys the sign-in identity we hold for you — the only thing on our side that points at a person — along with any deposit address, and signs you out everywhere. Afterwards there is nothing left to sign back into: signing in again with the same Apple ID, Google account or key starts a new, empty account rather than reopening the old one.
What we keep is the transaction record — what was bought and what credits were spent — because tax and accounting law requires it. It is filed under a random account number with your identity already removed, so it no longer says who you were. Unspent credits are not refunded and cannot be restored. If you would rather we did it for you, write to the address below.
OpenPdfEdit is not directed at children under 13 and does not knowingly collect data from them. It does not knowingly collect data from anyone, which is rather the point.
If this policy changes, the date at the top of the page changes with it, and the change is in the public commit history along with the code it describes.
Questions about this policy, or about your data: openpdfedit@gmail.com.
If something here turns out to be inaccurate, that is a bug and worth reporting as one — open an issue on GitHub.