Privacy Policy
Last updated: September 13, 2026
The short version: your files never leave your device. Every tool on localdobe — merge, split, compress, edit, watermark, protect, unlock, and signature validation — runs entirely in your browser. When you drop a PDF into a tool, it’s read into memory on your machine, processed there, and handed back to you as a download. At no point does your file — or any data derived from its contents — travel over the network to us or anyone else.
The rest of this page describes, completely, the data that does exist when you use this site: standard hosting logs, site analytics (including a single analytics cookie), and a few preferences stored on your own device.
1. Your files
Files you process with localdobe’s tools are opened in your browser’s memory, transformed on your device, and offered back as a download. They are never uploaded, never logged, never cached on a server, and never seen by us. Passwords you enter in the Protect and Unlock tools are used only inside your browser’s memory for the encryption or decryption operation and are likewise never transmitted or stored. After the page has loaded a tool once, most operations work with your network disconnected — the clearest proof that processing is local.
2. Hosting and server logs (Cloudflare)
The static site — HTML, CSS, JavaScript, fonts, and the files the tools use — is served by Cloudflare. Like any content delivery network, Cloudflare’s edge may process and briefly log standard HTTP request metadata: the URL requested, your IP address, user-agent string, referrer, and timestamp. This covers which pages and assets were requested — never the contents of any file you process, because your files are not part of that traffic. Cloudflare processes this data as described in the Cloudflare Privacy Policy.
3. Analytics (Cloudflare Web Analytics — cookieless)
We use Cloudflare Web Analytics to understand aggregate site usage — which pages are visited and how fast they load. We chose it because it is one of the least invasive analytics products available:
- it sets no cookies and uses no localStorage;
- it does not fingerprint your device or track you across sites;
- it collects page-view events only: the page URL, referrer, browser and device type, country-level location, and performance timings;
- it never sees your files or anything you do inside a tool — it has no access to file names, file contents, or tool inputs.
This works via a small script served from cloudflareinsights.com. If you block it with an ad-blocker or a browser like Brave, every tool on this site continues to work exactly the same — we think that’s how it should be. Analytics data is processed by Cloudflare under the Cloudflare Privacy Policy.
4. Product analytics and session replays (PostHog)
We use PostHog for two jobs: product analytics — seeing which tools people use and where they get stuck, for example how many visitors who open Compress PDF actually download a result, and which errors they hit on the way — and session replays, which show how the interface is actually used (where people click, how far they scroll, and where the UI confuses them). Replays are what make it possible to work out why a tool went wrong for someone rather than just counting that it did.
Product events record the tool being used, the step reached, and coarse measurements of the work: the number of files or pages, file sizes in bytes, how long the operation took, and which options (compression preset, page size, split mode) were selected. Replays record interaction data — clicks, scrolls, mouse movement, page URLs, and browser and device type.
- Nothing about your documents is included. Events never carry file names, file contents, page text, or passwords. Error messages are scrubbed of anything resembling a file name before they are sent. Replays follow the same rule: the parts of a tool that show your document — file names, rendered pages and images, document text, signature details — are replaced with masked placeholders before the recording is sent, and form inputs are masked by default. The tool’s own controls and options (buttons, sliders, page counts and sizes) stay visible, because replays help us see how the interface is actually used. A replay never contains file names, document text, rendered pages, or anything you type into a tool (passwords included).
- Cookies identify a session, not a person. PostHog stores a random identifier in a first-party cookie and in
localStorage. That identifier is what lets the events and a replay from one visit be stitched into a single session. It is not a profile: person profiles are disabled, we never callidentify(), and there are no accounts to link it to. It is not used for advertising and is not shared with anyone else. - Blocking it changes nothing. If an ad-blocker stops the PostHog script, every tool keeps working exactly the same.
- It is served from our own subdomain. To keep these measurements from being skewed by ad-blockers, the PostHog script and its events go through
e.localdobe.com, which forwards to PostHog. We mention it because it means the traffic is not obviously PostHog’s if you inspect it yourself — the data collected is exactly what is listed above, and no more.
This data is processed by PostHog under the PostHog Privacy Policy. You can stop it at any time with an ad-blocker, or clear PostHog’s cookie and its localStorage entry from your browser’s site-data settings.
5. Data stored on your device
localdobe stores a small amount of data in your browser, on your device:
- Theme preference — if you toggle dark mode, your choice is kept in
localStorageso the site remembers it. It never leaves your device. - Offline caches — a service worker caches the site’s pages and engines so the tools work offline and load faster. This is standard browser cache storage, and it never leaves your device.
- PostHog’s session identifier — the random id described in section 4, kept in a cookie and
localStorageand sent to PostHog with analytics events and replays so they belong to the same session.
You can remove all of it at any time through your browser’s site-data settings (usually under “Cookies and site data” → localdobe.com → clear), which fully resets the site.
6. What we don’t collect
We have no accounts, no sign-ups, and no way to associate site usage with a real-world identity. We run no advertising and never sell or share data. The only cookie the site sets is the first-party PostHog session identifier described in section 4 — there are no advertising cookies, no cross-site tracking cookies, and no cookies of our own. We verified this in a real browser: loading the site sets no cookies other than PostHog’s.
7. Your rights
Because localdobe itself stores no personal data about you, there is nothing for us to access, correct, export, or delete on request — the data described in sections 2–4 is processed by Cloudflare and PostHog, and requests concerning it can be directed to them under their privacy policies. Data stored on your device (section 5) is under your direct control through your browser and can be cleared at any time.
8. Children
This site provides document utilities and does not target children. We do not knowingly collect personal information from anyone, children included — the site has no mechanism to do so.
9. Changes to this policy
If how the site works ever changes in a way that affects this page — a new analytics tool, a new third party, anything that touches data — we will update this policy and the “last updated” date above. The core promise will not change: your files are processed on your device, full stop.
10. Contact
Questions about this policy, or about anything on this site, can go to [email protected]. In the same spirit as the rest of this page: that is a personal Gmail inbox, so an email you send puts your address and whatever you write in it into Google’s hands under Google’s privacy policy — writing to us is the one part of using localdobe that isn’t local. We don’t add the address to any mailing list, and there is no mailing list to add it to. Please don’t attach the document a tool struggled with; we can’t debug your file and would rather not receive it. A description of what it contains and which step failed is more useful anyway.