Tools.4PDF.Net
Privacy policy
How Tools.4PDF.Net receives, processes, protects, and deletes files during an online PDF tool session.
Last updated: September 8, 2026Scope of this information
This page explains what data Tools.4PDF.Net receives to provide its PDF tools, how that data is linked to an anonymous session, and when access expires. It describes how the service operates. It is not legal advice and creates no legal guarantees beyond those stated here.
If you process documents for an organization, client, or another person, determine your obligations before uploading a file. A tool's ability to process a file does not confirm that you have the right to provide the data.
Data we receive
When you use a tool, the service receives the files you select, your processing options, and the technical data needed to complete the job. A signed HttpOnly cookie identifies the anonymous session. The service does not currently require your name or a user account.
PDF passwords and phrases used for redaction are encrypted before they are stored with the job. They are decrypted only during processing.
Technical data may include file type, size, job status, processing errors, and information needed to validate the request. Storage object names are not taken directly from user-provided file names. Do not put unnecessary sensitive information in file names.
Purpose and processing
File data is used only to validate the format, perform the requested task, provide status and results, handle errors, and keep the service operating safely. Document contents are not used for advertising.
The server performs PDF conversion, OCR, organization, editing, and protection. Resource-intensive tasks enter a queue. When a task reaches the worker, it reads the file and required options. This lets the browser track status without running the entire process on your device.
- Check size, MIME type, and format signature before processing.
- Perform the exact task with the options you selected.
- Create a result that the current session can download before access expires.
- Record the status or error needed to explain the result in the interface.
Anonymous sessions and cookies
The current tools do not require an account. The session cookie is HttpOnly, SameSite=Lax, and signed so the server can recognize jobs that belong to your browser session. HttpOnly limits access to the cookie from page JavaScript, while the signature helps detect changes to its value. A cookie cannot protect a link that has been shared improperly, so you must still secure your device and active session.
If you block or delete cookies, the session may no longer recognize its jobs. You may then lose the ability to view status, download results, or request deletion through the interface. An anonymous session means the service does not require an account identity. Technical data may still exist while the system operates.
Signed links and access control
The browser uploads and downloads through short-lived signed URLs. Each URL grants access only to the related action and object for a set period. The API also checks the session before showing status, creating a download link, or deleting a job.
Do not post, forward, or save an active link where others can access it. If you believe a link has been exposed, delete the job through the interface while you still have access and stop sharing the link.
Protecting sensitive options
Passwords used to encrypt, decrypt, or sign PDFs, along with related sensitive phrases, are protected with AES-256-GCM before they are written to the database. The worker decrypts them only when performing the job. This reduces the risk of exposing values stored with a task, but it does not remove every risk of processing data online.
Do not upload a private key unless the task requires it. Use a test certificate when you are only testing the digital signing process. After downloading the result, check its protection settings and delete copies you no longer need from your device.
Storage, expiration, and deletion
Input files and results are kept in private storage, not a public web directory. Job access expires after one hour. This period is only for processing and downloading results. It is not a promise to store or back up documents.
Cleanup runs every five minutes. Physical deletion may therefore happen shortly after expiration, especially when the system has a queue. You can also delete a completed job through the interface while the session still recognizes it.
Download any results you need before they expire. Do not use Tools.4PDF.Net to store the only copy of a document. Keep the original and any copies your work requires.
Your choices and responsibilities
You choose which files to upload, which options to apply, and whether to use a result. Before sending data, consider its sensitivity, remove pages the task does not need, and confirm that you have the right to process the contents.
- Do not upload a document unless you own it or have the legal right to process it.
- Do not share session cookies, signed links, passwords, or digital certificates.
- Keep the original and carefully check results before using them for important records.
- Delete the job when finished, or close the session and wait for automatic expiration.
Limitations and data questions
No online system can guarantee the complete prevention of incidents, software errors, or unintended access. These measures reduce risk and limit how long files can be accessed. They are not a compliance certification, security badge, or absolute guarantee.
For data questions or to report a privacy issue, contact support@4pdf.net. Include the tool name, approximate time, and error code if available. Do not attach real documents, passwords, or active download links.
