🌹 LovelyPDF
Privacy-first — your files are never stored
Ease-first — no sign-up, ever

Privacy Policy

Last updated: September 2026

LovelyPDF is built around one rule: Upload → Process → Return the result → Destroy the temporary data. This page describes exactly what that means in practice -- not marketing language, but what the actual system does.

No accounts, ever

LovelyPDF does not have user accounts, logins, email collection, or sign-up of any kind. You can open the site, use any tool, and download your result without providing any personal information. The only time an email address is ever asked for is optional: if you send a problem report and want a reply (see "Problem reports" below).

Tools that never leave your device

Merge PDF, Split PDF, Rotate PDF, Reorder PDF Pages, Remove PDF Pages, Crop PDF, Sign PDF, and JPG/PNG to PDF all run entirely inside your browser. The file you're working with is never uploaded anywhere for these tools -- it's opened, processed, and saved back to your device using in-browser PDF processing (pdf-lib), and LovelyPDF's servers never see it.

Tools that require temporary server processing

Compress, Protect (encrypt), Unlock (decrypt), Watermark, Add Page Numbers, PDF to JPG/PNG, OCR, Redact, PDF to Markdown, PDF to Word, PDF to Excel, PDF to PowerPoint, and Word/Excel/PowerPoint to PDF need real server-side processing power that a browser can't reliably provide. For these:

  • Your file is uploaded only for the single operation you requested.
  • It's stored in an isolated, randomly-named temporary folder -- never a shared or permanent location.
  • The result is sent back to you, and the temporary folder (both your original file and the result) is deleted immediately afterward. This also happens when a conversion fails -- for example, if the file is locked or damaged.
  • As a safety net against crashes or unexpected failures, a background process automatically deletes any leftover temporary folder within 10 minutes at the absolute most -- normal use never comes close to that limit, since cleanup happens within seconds of your request finishing.

Problem reports

Every tool has a "Report a problem" button. Sending a report is always your choice. A report never includes your file, its name, or anything written in it. It contains only:

  • which tool you used, what went wrong (your choice from a list), and any description you type;
  • technical details shown to you before sending: the error message (with file names removed), file type and size, number of pages, time taken, browser name (for example "Chrome on Windows"), device type (computer, phone or tablet), and whether your internet connection and our server were reachable;
  • your email address, only if you choose to enter one so we can reply.

Reports do not include your IP address. They are used only to find and fix problems, and are deleted once the problem is resolved.

What we do NOT do

  • We do not keep a database of your documents.
  • We do not keep a history of what you've processed.
  • We do not create permanent backups of uploaded or converted files.
  • We do not analyze, scan, or profile the contents of your documents.
  • We do not send your document content to any third-party service. Tools like OCR and Office-format conversion run on software we operate ourselves (Tesseract and LibreOffice); nothing is sent to an external company.

What our logs actually contain

Operational logs may record which tool was used, how long it took, whether it succeeded, and file size -- never the file's name or its content. Like any web server, our server also briefly records technical connection details (such as IP addresses) to protect the service against abuse; these are not linked to your files. A filtering system automatically strips any file-path-like text (which would include original filenames) from every log line before it's written, as a structural safeguard rather than something that depends on remembering to do it correctly every time.

Analytics and cookies

LovelyPDF does not run advertising or third-party analytics, and sets no cookies for visitors. To know how much the site is used, it keeps only anonymous daily totals on its own server: how many people visited, which tool was opened, and how many conversions finished or failed. These totals never include document content, extracted text, filenames, IP addresses or any identifier. To tell a new visitor from a returning one on the same day, the server briefly holds a one-way code made from the connection and a secret that is replaced every day and never stored, so it cannot be traced back to anyone. If your browser sends a Do Not Track or Global Privacy Control signal, your visit is not counted; a finished conversion is still added to the daily total, as a number only. The site owner's own administration login uses one private cookie, which is never set for visitors.

Accuracy of this policy

We only describe what LovelyPDF's code actually does. If a specific tool doesn't process entirely in your browser, this page says so plainly rather than implying otherwise.

Contact

Questions about this policy can be sent via the Contact page.