Security

Last updated: August 3, 2026

Lazy PDF is built around a simple idea: your documents are yours, and they should never have to leave your device to be edited.

Local-first processing

Every core PDF tool — merge, split, compress, rotate, convert, sign, and more — runs entirely in your browser using client-side code. When you drop a file into Lazy PDF, it is read and processed on your own device, not transmitted to our servers to perform the tool's function.

What this means in practice

  • No upload queue. Files aren't sent to a remote server for standard processing.
  • No document storage. We don't retain copies of the PDFs or files you work with.
  • No silent retention. Files imported via a shared Google Drive or Dropbox link are used only to complete your action and are not kept afterward.

Account data

If you choose to create an optional account for synced activity and favorites, we store metadata about your usage, such as tool names and timestamps — not the contents of your documents.

Transport security

Our website and application are served over HTTPS/TLS, so any data that does travel between your browser and our infrastructure, such as account information, is encrypted in transit.

Responsible disclosure

If you believe you've found a security vulnerability in Lazy PDF, please report it to [email protected]. Include steps to reproduce, the affected URL, and your browser or operating system so we can investigate quickly. Please give us a reasonable window to address the issue before public disclosure.

Questions

For anything else related to security, reach out via our Contact Us page or email [email protected].