Documents tower · floor

Is iLovePDF safe, and Smallpdf? What they publish

Is ilovepdf safe? Is Smallpdf? Almost every floor in this tower says, at some point, that a job can be done without uploading the file at all. This is the floor that explains why — and it does it by reading what the upload sites themselves publish rather than by assuming the worst.

What two of the largest actually publish

Read from their own pages on 21 August 2026. Both are more reassuring than the rumours, and both contain something the rumours miss.

iLovePDF

“All files processed within our platform are automatically and permanently deleted within two hours of being processed.”

And plainly: “iLovePDF does not retain user documents.”

Smallpdf

“If you access our services via a User Account, we delete User Files within one hour unless you save them to your file storage.”

On training: “We do not use these files to train models, and no persistent storage of User Files occurs unless you save the results.”

So the folklore that these sites quietly keep everything is not what either of them says. The published position is hours, not forever — and a page that told you otherwise would be doing the same thing it accuses them of: asserting without checking.

Two details the summaries leave out

The clock can restart. Smallpdf: “this retention period is extended every time you reopen the respective User File.” An hour from processing is not an hour from upload if you go back to the download page.

And signing is different from converting. iLovePDF: “We retain signed documents for a maximum of 5 years in compliance with legal requirements.” That is not a loophole — a signature service has to be able to evidence what was signed — but it is a very long way from two hours, and it applies to precisely the documents people care most about.

Those two details are the reason this page exists rather than a blanket warning. The risk is not that these companies are lying. It is that the summary in your head — “it gets deleted straight away” — is a simplification of a policy with conditions in it, and the conditions attach to exactly the documents that matter.

A rule that does not require reading a policy every time

The question is not whether a site is trustworthy. It is what the document is.

Fine to uploadA leaflet, a public report, a manual, a recipe, an article — anything that is already public or that you would not mind a stranger reading.
Do it offline insteadAnything with your full name and address together; a payslip; a bank statement; a contract; an identity document; medical or legal papers; anything about somebody who did not choose this.
The deciding questionWould you be comfortable if this file were readable by someone you have never met, for the time it sits on their server? If yes, upload it. If you hesitate, the offline route exists and takes the same two minutes.

There is also a category the policies cannot cover, and it is worth naming. A published retention policy describes the intended behaviour of a well-run service. It does not describe what happens if that service is breached, sold, or replaced by a lookalike with a similar name — and the search results for these jobs contain plenty of sites nobody has heard of. The policy you read belongs to the site you meant to visit.

None of which is an argument for never using them. For a public document, an upload site is convenient, free and quick, and the two policies above are more careful than most people assume. It is an argument for spending ten seconds on the question before the file leaves the machine, because that is the only moment at which the decision is still yours.

And for the documents where the answer is no, this tower has the offline route for nearly every job: converting, merging, splitting, compressing, signing, filling in a form, turning pictures into a PDF and a PDF into pictures. Each of those floors starts with what is already installed, and none of them asks you to weigh a privacy policy against a deadline.

The neighbouring searches are all the same worry with a different brand attached: is smallpdf safe, is simplepdf safe, secure pdf editor. The answer has the same shape every time — read what the company publishes, note the exceptions, and then ask what the document is. Pdf security as a phrase covers both halves, and only one of them is about the website.

Where to start

Four ways in.

“Is this site safe?”
It is above. Then reading a policy
“It is a private document.”
Go to doing it offline
“I already uploaded it.”
Read after the fact
“Which sites are which?”
That is telling them apart

Doing it offline

The floors that need no upload at all. Between them they cover almost everything anybody does to a PDF.

Reading a policy

What to look for, and the three phrases that carry all the meaning. Five minutes once, rather than trust forever.

The three questionsHow long, who can see it, and what happens to the copy after processing.Being built
Where the exceptions liveSigning, accounts and saved files — the clauses that change the answer.Being built
Free versus paid tiersThe same service can treat an account holder’s files differently.Being built

Telling them apart

The search results for these jobs are crowded, and not every result is the site whose policy you read.

Lookalike sitesSimilar names, similar layouts, no published policy at all.Being built
What an advert looks likeThe first results on these searches are frequently paid placements.Being built
When there is no policyThe absence of a statement is itself the statement.Being built

After the fact

For the file that has already been sent. Some of it can be undone, and knowing which part is worth ten minutes.

Deleting from the serviceSeveral sites offer manual deletion from the download screen. Use it.Being built
What was in the file anywayAuthor names, edit history and hidden data you did not mean to send.Being built
If it contained your identityWhat to do first, in order, when documents about you are exposed.Open this floor →

What this tower will not do

It will not claim these sites secretly keep your files. Two of the largest publish deletion within one and two hours, and this floor quotes them rather than the rumour.

It will not stop at the reassuring half. The retention clock can restart, and signed documents are kept for up to five years — both stated by the companies themselves.

And it will not tell you never to upload anything. It will tell you to spend ten seconds deciding, because after the upload the decision is no longer yours to make. What holds instead is simple: every retention figure on this page is quoted from the services’ own published pages.

Where this page got its facts

  1. iLovePDF — Security, on deletion within two hours and the five-year retention of signed documents — www.ilovepdf.com, read 21 August 2026.
  2. Smallpdf — Privacy Notice, on deleting user files within one hour, the extension of the retention period, and model training — smallpdf.com, read 21 August 2026.

Written by Alberto Gulotta

Founder and editor of AI Tools Primer, writing from Palermo, Italy. Thirty-five years of taking computers apart, starting with a Commodore 64 — the long version is on the about page.

Something wrong on this page? Write to aitoolsprimer@gmail.com and it gets fixed.

Written on 21 August 2026.

Independence and limits

No affiliate links and no paid placements anywhere on this site. Nobody pays to appear here, and no company has seen this page before you did.

This is general information, not professional advice. Where a page touches money, health, safety or the law, it names its source and the date it was read — and your situation may still differ. See the privacy page and the cookie policy.