How PrivDF Works

What happens on your device, and the one thing that does not

1️⃣

Open Your PDF

Drag and drop a PDF from your device. It loads straight into your browser's memory — there is no upload path, so it is never sent to a server.

2️⃣

Set a Passphrase

Only needed if you want annotations to persist between sessions. It encrypts them on your device and never leaves it — which also means we cannot reset it.

3️⃣

Highlight & Annotate

Select text to create highlights or add notes. Everything is encrypted with AES-GCM before storing locally.

4️⃣

Analyze with AI

Optional. Click "AI Tools" to summarize or ask questions. Only the extracted text relevant to your request goes to Venice AI — never the PDF file. 5 operations a day are free.

5️⃣

Export or Delete

Export your annotations as an encrypted ZIP file, or delete everything with one click.

🔄

Import Anywhere

Import your exported ZIP file on any device to restore your annotations and continue working.

🧰

Everything Else

Merge, split, reorder, rotate, redact, fill forms, sign, watermark, compress and OCR scanned pages — all on your device. See the full toolkit →

Privacy-First Architecture

PrivDF uses modern browser APIs (Web Crypto, IndexedDB, PDF.js) to do the document work on your device: rendering, editing, redaction, signing, OCR of scans and every page operation run locally. AI is the exception — summaries, Q&A and table or chart extraction reach the network, sending the text relevant to your request to Venice AI, which operates a zero-retention policy. You can also choose to re-read a single scanned page with AI, which sends that page's image. Your PDF file is never part of any request. Don't take that on faith: open the Privacy Inspector in the app to see every outbound request measured live, or flip on Strict Offline Mode and keep editing, redacting, signing and OCR'ing with the network switched off.