Privacy policy
This page states what stupidPDF collects, what stays on your device, and which actions send data to someone else. It matches the tools that are on the site.
Short version
stupidPDF is a free PDF toolkit that runs in the browser at https://www.stupidpdf.com. There is no account and no paid plan.
PDFs and other files you drop into a tool are processed on your device. stupidPDF does not upload those files to its own server and does not keep a copy of them.
A few actions do send something off the device. Those cases are named below: hosting the website, optional page-view analytics, the AI tool, the Share tool, OCR language data, and the Suggest a feature form. Nothing else in the toolkit is a file upload.
Who this policy covers
This policy describes the public website and the tools on it. It is written so a client can see what the site does with information.
The site is published as stupidPDF. Opening https://www.stupidpdf.com, or any tool path on that host, is covered. Native shells of the same app follow the same file rules: processing stays on the device, and the web ad slot is not shown there.
Hosting
The website is served by Vercel. When your browser requests a page, Vercel receives ordinary request data: IP address, user agent, and the URL. That request carries the site itself (HTML, scripts, and images). It does not carry the PDF you later open in a tool.
Vercel acts as the host. Their handling of request logs is covered by Vercel. stupidPDF does not add your document to that request.
Documents you open in a tool
Drop a file, or type text, and the work happens in the page you already loaded. PDF work runs in the browser, including in a web worker, using libraries that ship with the site. The finished file is held in memory so you can download it. Closing the tab drops that memory.
stupidPDF has no document database, no project history on a server, and no inbox of customer files.
If a PDF is encrypted, the page asks for the password in a dialog on your device. That password is used to open the file locally. It is not written to the server and it is not saved in browser storage.
Passwords you set in Encrypt, Unlock, or a Workflow encrypt step stay in the page for that run. They are applied in the browser. They are not sent to stupidPDF.
Information that stays on the device
Resume text is saved in this browser under the key stupidpdf-resume after you download a resume PDF. The saved fields are layout, name, contact, summary, experience, and education. The next visit to /resume on that browser can refill the form. Another device does not receive it.
The AI tool can store a Gemini API key in this browser under the key stupidpdf-gemini-key, and only if you check “Save key in this browser”. Unchecking that box removes the key from local storage on the next run.
If you dismiss the install prompt, the browser stores stupidpdf-install-dismissed so the prompt stays closed. That value is only a flag.
A service worker may cache the site’s own files (the app shell, scripts, and icons) so a later visit can load. That cache is the website, not your PDFs.
You can remove all of the above by clearing site data for stupidpdf.com in the browser.
When information leaves the device
AI (/ai). This tool is the one that sends document text to a third party. You type your own Gemini API key. The page extracts text from the PDF on the device, then sends that text and your prompt to Google at generativelanguage.googleapis.com, model gemini-2.0-flash. The text included is capped at 20,000 characters. The PDF file is not the body of that request. Google receives the prompt, the extracted text, and the API key. Google’s terms and privacy policy cover that call. If you do not run AI, this request does not happen.
Share (/share). Two browsers connect with WebRTC. You copy a connection code from one browser and paste it into the other. stupidPDF does not receive the code or the file. The file moves on a direct data channel between the browsers. The page uses Google’s STUN server at stun.l.google.com:19302 so the browsers can find a network path. That STUN lookup can reveal a public IP address to Google. It does not upload the file to Google or to stupidPDF.
OCR (/ocr). Text that is already in the PDF is copied on the device. A scan with no real text layer is read by Tesseract.js in the browser. The first time a language is needed, Tesseract.js downloads that language data into the browser. The page image is recognized locally after the download. stupidPDF does not receive the scan. Languages in the tool are English, Spanish, French, and German.
Suggest a feature. The link opens https://forms.gle/CeczpBUdm5VTUcv57 in a new tab. That form is a Google Form. Text you submit there is sent to Google, not into the PDF tools, and stupidPDF does not store the form on its own server.
Analytics
The site loads Vercel Web Analytics. It records that a page was opened, such as the path, so we can see which parts of the site are used. It does not receive your PDF, the text inside it, or a password.
Analytics is about the website, not about the document you edit. You can block it with a browser or extension that blocks that script. The tools still run without it.
Advertising
An ad slot can appear under a tool when ads are turned on for the web build and the app is not running as a native shell. The slot is labeled as an advertisement. It does not receive your files.
The current slot is a placeholder. It does not load an ad network and it does not build an advertising profile from your documents. If that changes, this page will name the network and what it receives.
stupidPDF does not sell personal information and does not share document contents for advertising.
No account and no sale
You do not create an account. The site does not ask for a name, email, or payment card to use a tool.
We do not sell personal information. We do not have a file store to rent or share with data brokers. The third parties named in this policy receive only what their section describes, and only when that feature runs.
Children
stupidPDF is a general document tool. It is not directed at children under 16, and it does not knowingly collect personal information from them. A child who uses a tool still processes files on the device. Do not type a child’s private details into the AI tool or the Suggest a feature form.
How long information is kept
Document bytes exist in the browser tab until you close it or replace them. stupidPDF does not set a server retention period for files, because it does not store the files.
Resume text, a saved Gemini key, and the install-prompt flag stay in that browser until you clear site data or, for the key, you run AI with saving turned off.
Host and analytics logs are kept by Vercel under Vercel’s retention, not in a stupidPDF document archive.
A Gemini request is kept by Google under Google’s retention for that API. A Google Form submission is kept by Google.
Security
The site is served over HTTPS. Keeping the file on the device is the main protection: a server breach of stupidPDF would not yield a library of customer PDFs, because that library is not collected.
You should still treat the AI key as a secret. Leave “Save key in this browser” off on a shared computer. A saved key sits in local storage and can be read by anyone who can use that browser profile.
Encrypt protects a PDF with the password you choose. Unlock removes a password you already know and saves a copy. Neither tool sends the password to stupidPDF. Share sends the file to the other browser you connect. Only connect with someone who should have the file.
Redact deletes selected text strings from the first page’s content. It is not a guarantee that every copy of a secret is gone. Text that exists only in a photo is not found by that scan, because the scan is not OCR. Check the downloaded file before you send it.
Your choices
Skip /ai and no document text is sent to Gemini. Skip /share and no peer connection is opened. Skip /ocr on a pure scan and no language data is downloaded for that job.
Clear site data for this host to delete the resume draft, a saved API key, and the install flag.
There is no account to delete and no server file to request, because those records are not created. A privacy question can be sent through the public Suggest a feature form. That form is operated by Google. It is not a private inbox stored by stupidPDF.
Visitors in other countries
People open the site from many countries. The file work they do stays on their device, so stupidPDF is not the recipient of the document.
Where a feature does send data, the recipient is the one named above: Vercel for hosting and page-view analytics, Google for an AI call you start, for STUN during Share, and for the Suggest a feature form, and the Tesseract.js language-data host when OCR downloads a language. Those parties may process that data in the United States or other countries where they operate.
This page is the notice of those purposes. We do not use document contents to make automated decisions about you. The site does not ask you to create a profile.
Changes
This policy was published on 25 September 2026. If a tool starts sending data somewhere new, this page will be updated in the same change and the date will move. The home page and the tool screens are separate from this policy.