File privacy
Three tools, three clear processing models.
FileCarpenter does not describe every tool as “local” when that would be inaccurate. Check the section that matches the tool you are using.
Focused PDF tools
Most tools under /pdf/ process the selected PDF entirely in your browser. Their application server serves static code and has no PDF upload endpoint. Sign PDF and Fill PDF Form are the explicit exceptions: after a same-origin, one-time browser handoff, they open the full FileCarpenter PDF Editor and send the PDF to a temporary editor session so the signature can be placed with the editor’s signing engine, or existing AcroForm fields can be updated, and the result preservation-validated. The handoff copy stored in IndexedDB is deleted before the editor uses it.
Full PDF editor
The PDF editor sends the selected document to the FileCarpenter application server for the active editing session. Server-side processing is used for structural checks, supported edits and validated export. In the supplied deployment, the editor keeps the active document in a bounded temporary application session and does not intentionally write a persistent application-level copy to disk. The default inactivity limit is 30 minutes.
While a PDF is open, the editor shows a live Server copy status. It reports whether the application session still exists, how long remains before inactivity deletion, and whether the editor service reports a persistent application copy. Checking that status does not refresh the inactivity timer. The user can also choose Delete server copy now, which destroys the active editing session immediately and makes that tab view-only until another PDF is opened.
For a short period after deletion, the service may keep a metadata-only deletion receipt containing the random session identifier, deletion time and reason so the browser can confirm that the document session was destroyed. That receipt does not contain the filename, PDF bytes, password, previews or edit history. The in-editor status describes the FileCarpenter application session; it is not an independent audit of hosting-provider backups, operating-system swap, reverse-proxy infrastructure or other systems outside the application process.
Session data otherwise expires after inactivity. Do not process a document you do not have permission to handle.
Peer-to-peer file transfer and Smart Send
The file-transfer tool uses WebRTC to move file bytes between paired browsers. The signaling service introduces the devices and relays connection information. When direct connectivity is unavailable, a TURN relay may carry encrypted WebRTC traffic, but FileCarpenter does not persist the transferred file as an uploaded object.
Smart Send inspects selected media on the sender device and receives a small, temporary capability profile from the receiving browser over the WebRTC DataChannel. The profile uses broad categories such as platform/browser family, screen class, codec/image support, save APIs and coarse browser-storage/network classes. It does not transmit exact CPU count, exact screen dimensions, devicePixelRatio, a full hardware fingerprint, or exact free-disk bytes. Generated image copies are created on the sender device. Capability profiles are not persisted by the supplied server.
Accounts, advertising and analytics
The supplied deployment does not require user accounts and does not include advertising or third-party analytics scripts. If the site operator later adds analytics, advertising, logging or another external service, this notice must be updated before that change is deployed.
Operational logs
Web servers and reverse proxies may keep short operational logs containing request time, requested URL, browser information and network address. Configure log retention on the VPS to match the operator’s policy, and never place room passwords or PDF contents in access logs.
This page describes the behavior of the supplied FileCarpenter deployment package. It is not a substitute for a jurisdiction-specific privacy policy if additional data collection is introduced.