PDFArrow · Trust center
Privacy boundaries you can understand before choosing a file
Supported core tools process document contents in your browser. Optional account, cloud-history, analytics, and support features have separate, clearly stated data paths.
Reviewed July 21, 2026 by PDFArrow Product Engineering.
Browser processing
The editor and supported PDF tools process file contents in the current browser tab. Choosing a file does not send its bytes to PDFArrow merely to run those tools.
Optional account and cloud features
Firebase Authentication handles sign-in. When Firebase Storage and Firestore are configured, signed-in users may save document history and workspace data for cross-device access. Guest processing does not require cloud history.
Local storage
Guest and signed-in work may be saved in browser storage when space allows. You, the browser, private-browsing rules, or device cleanup can remove it.
Product analytics
Privacy-safe events can include route, traffic-source category, referring hostname, tool, broad file-size and page-count buckets, validation category, duration, browser family, device class, and success or failure. They exclude search terms, full referring URLs, filenames, file contents, extracted text, document URLs, signatures, form values, and user-entered document data.
Support and service providers
Support requests store the reply email, category, message, account ID when signed in, and submission time in the owner-only inbox. Vercel currently hosts the public application and Google Firebase provides optional authentication, Firestore, and Storage.
Deletion
Clear site data to remove guest browser records. Signed-in users can delete saved documents or permanently delete their account and associated document records, cloud payloads, linked analytics events, and account-linked support requests from Settings. Anonymous events cannot always be linked back to a person.