🌹 LovelyPDF
Privacy-first — your files are never stored
Ease-first — no sign-up, ever

Security

Last updated: 2026

This page lists the actual technical protections built into LovelyPDF -- not general claims, but what the code does.

Upload validation

  • File signature checking: uploaded files are validated against their real binary header, not just their filename extension or the browser-supplied file type -- a text file renamed to ".pdf" is detected and rejected.
  • Size limits: a maximum upload size is enforced, checked while the file streams in rather than after it's fully received.
  • Page-count limits: operations that process every page of a document (compression, OCR, image rendering) reject documents beyond a sane page count, protecting against a small file engineered to expand into an enormous processing load.
  • File-count limits: requests that accept multiple files (like Merge) cap how many can be submitted at once.

Abuse protection

  • Rate limiting: requests from a single address are capped within a rolling time window.
  • Concurrency limits: only a fixed number of processing jobs run at once, so heavy traffic queues cleanly instead of overwhelming the server.
  • Processing timeouts: any single job that runs unexpectedly long is stopped automatically, freeing its resources for other requests rather than hanging indefinitely.

File handling

  • Each request gets its own isolated, randomly-named temporary folder, restricted to the server process itself.
  • Uploaded filenames are sanitized to prevent directory traversal (a filename can't be used to write outside its intended folder).
  • Temporary files are deleted immediately after each request, with an automatic background sweep as a backup in case a crash or unexpected error skips normal cleanup.

Logging

A filtering system strips file-path-like text (which includes original filenames) from every log line before it's written, so operational logs never end up containing a document's identity.

Transport security

The production deployment of LovelyPDF is served over HTTPS, encrypting data in transit between your browser and the server.

Reporting a security issue

If you believe you've found a genuine security vulnerability in LovelyPDF, please report it via the Contact page rather than disclosing it publicly, so it can be addressed first.