All guides
8 min read

When not to use online PDF tools (and when cloud is fine)

Private PDF tools should be the default for sensitive files. Cloud suites still fit some jobs — here is a clear split.

Online PDF tools are not uniformly “bad.” Upload-based suites ship polished UX and heavy server conversion. The mistake is using them by habit for every file, including ones you would never attach to a public ticket. This guide draws a hard line for sensitive work and a fair green light for low-risk jobs.

Do not upload these to random online tools

  • Government IDs, passports, and immigration packets
  • Tax returns, bank statements, and payroll documents
  • Medical records, insurance claims, and prescriptions
  • Employment contracts, offer letters, and performance reviews
  • Customer lists, unpublished financials, and source code printouts
  • Anything covered by NDA, attorney-client privilege, or school privacy rules

For those categories, prefer on-device processing: merge, compress, split, OCR, encrypt, and convert in a browser toolkit that does not take custody of the bytes. Retention policies that promise deletion still require trust and still create a temporary copy outside your control.

When cloud PDF suites are reasonable

  • Public marketing PDFs and already-published brochures
  • Internal flyers with no personal data
  • Bulk jobs you run under a paid vendor contract with BAAs or DPAs your counsel accepted
  • Team workflows that need shared templates, admin audit logs, or integrated e-sign
  • Conversions that truly need server-grade engines you have already approved

If your company already standardized on a suite and trained staff on its retention settings, following that standard can be safer than shadow IT free sites. The dangerous pattern is personal free converters for work documents that never went through security review.

A quick decision tree

  1. Does the file contain personal, financial, medical, or confidential business data? → Local first.
  2. Would you paste the full text into a public chatbot? If no → do not upload to a free PDF site.
  3. Do you need unlimited free tasks without an account? → Private browser toolkit.
  4. Do you need vendor e-sign, SSO, or contractual processing terms? → Approved cloud suite.
  5. Still unsure? → Local for this copy; escalate to IT for a standing exception if cloud is mandatory.

Encrypt PDF locally before sharing

A useful last step even when the channel is email or a portal.

Encrypt PDF locally before sharing

Middle ground mistakes

Compressing “only the images” via a cloud site

Compression tools still read whole pages. Image-heavy tax scans are not anonymous pixels; they are full documents. Use a local compressor.

Unlocking passwords on mystery websites

If you know the password, unlock locally. If you do not, a website that “removes PDF passwords” is either limited to weak protection or doing something you should not trust with corporate files.

Chaining five free tools

Each upload multiplies exposure. One private toolkit for merge → compress → encrypt is fewer trust decisions than three brands with three privacy policies.

How StackPDF fits the “local first” side

StackPDF is built for the local-first branch of this tree: free tools, no account wall for core jobs, processing in the browser. It does not replace enterprise e-sign or a records system of record. It does replace the habit of dropping sensitive PDFs into whichever site ranked first today.

Related guides

Compare private toolkits with big cloud brands in the private-vs-cloud article, and use the end-to-end private workflow for packing a packet you will actually send.

Try these tools

More guides