Nothing is uploaded. Here is how to check.
Every online tool promises confidentiality. Here you can check the promise in thirty seconds, and this page explains how.
Three checks, in thirty seconds
Cut your network connection. Load a tool, then turn off Wi-Fi or unplug the cable. Drop a document in, merge, rotate, number, save, switch tools. Everything keeps working, because everything was already happening on your machine. It also works if you unplug before dropping anything in.
Watch the “Network” tab. Open your browser's developer tools (F12), Network tab, then drop in a hundred-page file, reorder it, watermark it. Nothing goes out while you work: no request, no background upload, no telemetry. Save, and exactly one appears, /compte?p=100&f=pdf: the counter on the home page, which receives a number and the family of tools it came from. It weighs one line, and it is the only one on the whole site. If you would rather not open the developer tools, every tool page carries the same list right at the bottom, “What this tab asked the network”, and it updates while you work. That list is written by the page, so by us; your browser's own table is the one that counts, and we say so there too.
Read the content security policy. It is in the source of every page, and your browser applies it. connect-src 'self' means the page cannot open a connection to any other domain: not a font provider, not a CDN, not an analytics tag.
Unplugged, the site still works
A service worker puts that machinery aside as soon as the page opens, along with the seventy tool pages of your language. You can unplug on arrival, then merge, redact, compress, and move from one tool to the next. The site fits inside your browser.
A service worker is a program that installs itself between the page and the network. Here is what ours does, and what it does not.
- It opens no connection. Its job is to answer with what it already holds, so that nothing has to be asked for. It talks to no other domain, and the content security policy would forbid it anyway.
- No document goes through it. Your files never touch the network; they go from your disk to the memory of the tab. It keeps this site's pages and code, nothing else.
- It does not touch the counter, and it does not replay it. A service worker can hold a send back and repeat it when the network returns. That would mean keeping a timestamped trace of your work in your browser, waiting to be sent to us. Offline, the counter does not count.
- It empties itself completely at every new version of the site, and it never serves yesterday's page while the network answers.
- It can be read. It is the file
/sw.js, at the root of the domain: two hundred commented lines that open in a tab.
The one request, and what it carries
After an export, and only then, the page sends one request to this domain. It carries two things: a number, and the family of tools it came from, pdf, image, video or archive. No byte of your document, no file name, no identifier, no cookie, and not the tool itself: a family holds a dozen of them.
Each family counts in its own unit: pages for PDFs, images, files for video and archives. Never what an archive contains: that would say something about your folders.
The server log for that endpoint writes three things: a date, a family and that number. It says that on a given day somebody worked on an image rather than a PDF, tied to nobody: no address, no session, no chain of actions. The format is in the repository, and a browser that asks not to be tracked sends nothing at all.
What it changes for the GDPR
Your documents are never processed by us, since they never reach us. There is no processor to name, no transfer outside the European Union to declare, no retention period to set, and nothing to ask anyone to delete.
No cookie, no tracker, no third party, so no consent banner. A web server necessarily sees an IP address when you load a page: that is how the web works. The question is what it keeps. Since 2026-08-30 this site has its own access log, and it writes three things into it: a date, the page requested, the response code. No IP address, no referrer, no user agent, which is less than any web server keeps by default. It tells us which pages are read and which links are dead; it cannot tell us who read them, whether someone came back, or in what order. It is kept for fourteen days, then deleted: the server rotates it daily and keeps fourteen. Before 2026-08-30, requests to this site went into the machine's default log, with the address, the referrer and the browser. They no longer do.
What we do not guarantee
This site does not make your computer safe, and it does not claim to.
- A tool is not an audit. Inspecting a PDF says what we were able to read in its bytes, not that the document is harmless.
- A watermark is not protection, and cropping a PDF does not erase what sticks out. Each tool says so on its own page.
- Redaction flattens the page into an image: what is covered is gone, but the page loses its selectable text.
- Everything happens in the memory of the tab. Past a hundred megabytes per file, the tab is what gives way.
- Signing here is not an electronic signature within the meaning of eIDAS: nothing certifies your identity or seals the document.
It works without us
The whole site is a folder of static files. It can be put on an intranet or on any small web server and it works unplugged: that package is what we sell, for organizations that would rather depend on no outside website at all.
It also answers “what if this site disappears?”: nothing you did here depended on it staying up.