GhostXStudio tools

Are online PDF tools safe? How to tell if a tool uploads your file

Updated

Short answer

Open your browser’s developer tools, switch to the Network tab, and use the tool. An upload appears as a request, usually POST or PUT, whose size roughly matches your file. A client-side tool processes the file inside the page with JavaScript or WebAssembly and sends no such request.

Server-side versus client-side

Most online file tools are server-side: your file is uploaded, processed on the company’s computers, and the result is sent back. That can be perfectly legitimate, but it means a copy of your document exists on someone else’s infrastructure, subject to their retention policies, their security, and their staff.

A client-side tool does the work in your browser. The page reads your file with the browser’s File API, processes it with JavaScript or WebAssembly (sometimes in a background worker or on the GPU), and hands you the result as a download. The file’s contents never need to leave your device. Browsers have become fast enough to handle PDF editing, image conversion, audio and video processing, and even machine-learning models this way.

Check with the Network tab

  1. Open the tool’s page, then open developer tools: F12 or Ctrl+Shift+I on Windows and Linux, Cmd+Option+I on a Mac. Choose the Network tab.
  2. Turn on ‘Preserve log’ so requests aren’t cleared if the page navigates, and clear the existing list.
  3. Add your file and run the operation, then download the result.
  4. Look at the requests that appeared. Sort by size, and check the method column: an upload is typically a POST or PUT with a request body close to your file’s size, often of type multipart/form-data.
  5. Click any suspicious request and look at its payload or request body, and note which domain it went to.

Normal requests on a client-side tool look different: downloads of scripts, WebAssembly modules, fonts, or model files (large responses, tiny requests), and small analytics pings. The direction matters — a large download of the tool’s engine is not an upload of your file.

The offline test

Load the tool, run it once on a harmless file so any engines or models are downloaded, then disconnect from the network (airplane mode, or DevTools’ ‘Offline’ throttling option) and run it again on your real file. If it works offline, the processing is happening on your device. The limits: some pages cache themselves so they can load offline, which is fine, and a tool that works offline could in principle still queue data to send when you reconnect. Combine the offline test with the Network tab check rather than relying on either alone.

What these checks can’t tell you

  • Network traffic is often compressed or encrypted inside the request, so compare sizes rather than expecting to read your text in the payload.
  • A tool could send a small derivative — extracted text, a thumbnail, a hash — instead of the whole file. Look at every request made while processing, not only large ones.
  • WebSocket and WebRTC traffic appears differently; check the WS tab and the messages inside a connection.
  • A clean check covers the version of the page you tested. Sites change, so re-check tools you rely on.

‘No upload’ also isn’t the whole privacy picture. Third-party analytics and ad scripts can record which pages you visit, and file names sometimes end up in analytics events. The site’s privacy policy should say what is collected.

What you’ll see on GhostX

GhostX’s file tools — PDF, image, audio, video, and the X-ray scanner — process files in your browser. If you watch the Network tab, you’ll see the page, scripts, fonts, WebAssembly, and machine-learning models downloaded from ghostx.tools; the OCR engine from cdn.jsdelivr.net and the document-scan edge detector from docs.opencv.org when those features are first used; and Google Analytics on every page. You shouldn’t see a request carrying your file.

Some features contact servers by design, and GhostX says so: one-time encrypted sends store ciphertext the server can’t decrypt; peer-to-peer transfers use a server to connect the two browsers; multi-signer documents are end-to-end encrypted and coordinated by a server; GhostSign’s seal sends a hash of the finished file, not the file; and proof timestamps submit a blinded hash. The security page lists these exceptions and what each one sends.

Frequently asked questions

  • Are online PDF tools safe to use?

    It depends on where the processing happens and what the service does with your file. Server-side tools keep a copy at least temporarily; client-side tools don’t need to. Check with the Network tab and read the privacy policy before using any tool with confidential files.

  • Does HTTPS mean my file is private?

    No. HTTPS encrypts the connection so others on the network can’t read it, but the server at the other end still receives the file in full.

  • Can a website upload my file without it showing in DevTools?

    Requests made by the page, including from its background workers, appear in that page’s Network tab. Browser extensions can make their own requests, so test in a clean profile or a private window with extensions disabled.

  • Is a tool that works offline guaranteed not to upload?

    It proves the processing is local, but not that nothing is sent later. Pair the offline test with a Network tab check while online.