PDF tools5 min read
Online PDF services: what they say about storage
What well-known online PDF services state about deletion periods, server location and encryption, how to read such statements and what the FADP says.

The secretariat of a school in Kriens puts documents together every semester: timetables, letters to parents, registrations for school camps. Often these are separate PDFs that need to become one file. The quickest way is an online service: upload the files, merge them, download the result. With the registrations, which include allergies and emergency numbers, the school secretary wonders where these files sit in the meantime, and for how long.
The answer is usually given by the provider itself — in an FAQ, on a security page or in the privacy policy. This post sets out what four widely used services state there, without evaluating them, and shows what to look out for when reading such statements.
What happens on upload
An online service that works on a server needs the file on its server. It is uploaded, processed there, and the result is made available for download. For a certain time, then, both the original and the result are with the provider. How long, where, and who can access them is decided by the provider — and, at best, described publicly.
What four providers themselves state
The following statements come from the providers’ own pages, summarised in their own words, as of 25 September 2026:
| Provider | Deletion of uploaded files | Location and other details |
|---|---|---|
| Adobe | Without signing in, Adobe deletes the file within a short time; when signed in, it is stored in the account | AES-256 and TLS 1.2 encryption (FAQ, updated 2 June 2025) |
| iLovePDF | Automatic and permanent deletion within two hours of processing | Company in Barcelona, Europe-based (security page of 19 June 2025) |
| PDF24 | Automatic deletion within one hour of processing | Processing servers in data centres in the EU; desktop program for processing without upload (FAQ) |
| Smallpdf | When using the tools, deletion after one hour; files stored in the account kept until deleted | Company based in Switzerland, server infrastructure in the EU (provider’s blog post) |
The overview is a snapshot. Providers change their statements; what counts is always the provider’s current page.
How to read such statements
A comparison brings out a few points that can also be asked of other services:
- With or without an account. For several providers, the period depends on whether you are signed in. With an account, files are often stored until you delete them yourself.
- “Deleted” from where? A deletion period usually refers to the processing server. Whether and for how long backups or logs exist is not always stated alongside it.
- Registered office and server location are two separate details. A company can be based in one country and run its servers in another. Both matter for the question of which law applies and where data goes.
- Subcontractors. Whether a provider runs its own servers or uses third-party data centres and cloud services is often only stated in the privacy policy.
- The date. Statements on security pages are revised. A date on the page shows how current it is; if there is none, it is worth noting the date you read it.
- Encryption. “Encrypted” usually means encrypted in transit (TLS) and in storage. For processing on the server, the content generally has to be readable there.
Three kinds of documents
To judge whether an online service fits, a simple sorting of your own documents helps:
- Documents without personal data, such as a timetable or an information sheet. Here it is mainly about convenience.
- Documents with ordinary personal data, such as a class list with names and addresses. Here retention, location and contract count.
- Documents with sensitive personal data, such as details about health (Art. 5 let. c no. 2 FADP). Here the bar for data security is higher, and the question of local processing arises in particular.
The sorting does not anticipate a decision, but it shows for which documents a provider’s statements should be read carefully.
What the FADP says
If a business or a school uploads documents containing personal data to a service that processes them on its behalf, that service is generally a processor. The FADP allows such a transfer if the data is processed only in the way the controller itself would be permitted to, and no duty of confidentiality prohibits it; the controller must in particular satisfy itself that the processor can guarantee data security (Art. 9 FADP).
If the servers are outside Switzerland, there is also a disclosure abroad. This is possible without further ado if the Federal Council has determined that the country concerned provides adequate protection (Art. 16 para. 1 FADP). The list of these countries is in Annex 1 DPO; it includes Germany and Austria, among others.
The questions that can be put to a provider on this are described in the post Six questions to ask.
When the file is not uploaded at all
There are alternatives to uploading. Some providers have desktop programs that work locally; PDF24, for example, describes such a program for Windows. And some web apps can process files in the browser itself, without sending them to a server. How to check whether that is really the case is described in the post Processing in the browser.
After downloading
The provider’s deletion period is only one part. Copies also arise on your own computer: in the downloads folder, in an email attachment, on a shared drive. Personal data is destroyed or anonymised as soon as it is no longer needed for the purpose (Art. 6 para. 4 FADP) — this applies to the intermediate files in the downloads folder just as much as to the file at the provider.
For the school secretariat in Kriens
The secretariat sorts its documents into two groups. Timetables and letters to parents without personal data are still merged online, with the provider whose statements it has read. Registrations with health details are processed locally. And the list of programs in use records which service is used for what.
The PDF tools we are building will process files in Switzerland, in memory, without storing them — without advertising and without tracking. In confidential mode, selected tasks will be done entirely in the browser on your own device.
Sources
- 1.Adobe: FAQ — Try Adobe Acrobat online services (zuletzt aktualisiert 2. Juni 2025) (checked on 25 September 2026)
- 2.iLovePDF: Security (datiert 19. Juni 2025) (checked on 25 September 2026)
- 3.PDF24: Questions and answers about the PDF24 Tools (checked on 25 September 2026)
- 4.Smallpdf: Is Smallpdf Safe? (checked on 25 September 2026)
- 5.Bundesgesetz über den Datenschutz (DSG, SR 235.1) (checked on 25 September 2026)
- 6.Datenschutzverordnung (DSV, SR 235.11), Fassung in Kraft seit 15. September 2024 (checked on 25 September 2026)
Be told when it launches
This idea is still being planned. Sign up and we will write to you once, when it becomes an app. Signing up is non-binding – no newsletter, no advertising.
View the idea