How PrivDF Works
What happens on your device, and the one thing that does not
Open Your PDF
Drag and drop a PDF from your device. It loads straight into your browser's memory — there is no upload path, so it is never sent to a server.
Set a Passphrase
Only needed if you want annotations to persist between sessions. It encrypts them on your device and never leaves it — which also means we cannot reset it.
Highlight & Annotate
Select text to create highlights or add notes. Everything is encrypted with AES-GCM before storing locally.
Analyze with AI
Optional. Click "AI Tools" to summarize or ask questions. Only the extracted text relevant to your request goes to Venice AI — never the PDF file. 5 operations a day are free.
Export or Delete
Export your annotations as an encrypted ZIP file, or delete everything with one click.
Import Anywhere
Import your exported ZIP file on any device to restore your annotations and continue working.
Everything Else
Merge, split, reorder, rotate, redact, fill forms, sign, watermark, compress and OCR scanned pages — all on your device. See the full toolkit →
Privacy-First Architecture
PrivDF uses modern browser APIs (Web Crypto, IndexedDB, PDF.js) to do the document work on your device: rendering, editing, redaction, signing, OCR of scans and every page operation run locally. AI is the exception — summaries, Q&A and table or chart extraction reach the network, sending the text relevant to your request to Venice AI, which operates a zero-retention policy. You can also choose to re-read a single scanned page with AI, which sends that page's image. Your PDF file is never part of any request. Don't take that on faith: open the Privacy Inspector in the app to see every outbound request measured live, or flip on Strict Offline Mode and keep editing, redacting, signing and OCR'ing with the network switched off.