Privacy and file handling

In short: you edit your document in your own browser. Our server only stores an encrypted copy that nobody can read without the key in your link – not even us – and we delete it one hour after your last edit. No cookies, no ads, no tracking.

Where your PDF is processed

Viewing, every edit and creating the final PDF all happen right in your browser (JavaScript). Our server never processes the contents of your document.

The same goes for photos and images: scanning a document with your camera, converting images to PDF, saving pages as images, splitting and compressing PDFs all run entirely on your device. Photos are never uploaded – only the finished PDF is sent to the server (encrypted), like any other document.

Text recognition in scans (OCR) also runs in your browser. The first time you use it, only the recognition program and language data are downloaded from our server (the same for everyone, with none of your data). The recognized text is stored like any other edit – encrypted, together with the document.

Digital signatures with a certificate

Your certificate file (.p12/.pfx), its password and the private key stay only in your browser’s memory: they are never saved or sent anywhere, and they are discarded after signing. If you leave the timestamp option on, your browser sends – through our server – only a fingerprint (hash) of the signature value and a random number to the DigiCert timestamp authority. Not the document, your name, your certificate or your password. Our server only forwards the request and does not store it. Verifying signatures in a document happens entirely in your browser.

What we store on the server and why

So that you don’t lose your work when you reload the page, close the window or want to continue on another device, we store on the server:

  • an encrypted copy of the original PDF,
  • an encrypted record of your edits (added text, signatures, images…),
  • technical data: data size and the times of creation, last change and deletion.

Your browser encrypts the data with AES-256-GCM before sending it. The key is created on your device and exists only in the part of the link after the # sign. Browsers never send that part to the server. The server therefore only stores unreadable data, and neither we nor anyone who gained access to the server or its backups can find out what the document contains. The file name is encrypted too.

We store the copy because it is part of the service you are using (saving your work in progress), and only for as short a time as necessary.

When data is deleted

  • automatically 60 minutes after your last edit,
  • at the latest 12 hours after upload, even if you keep editing,
  • immediately when you choose Delete copy now in the editor.

Deleted documents cannot be restored. Deletion does not affect files you have downloaded to your device.

The document link

Anyone with the full link can open, edit and delete the document, so only share it with people you trust. If you lose the link, the document can’t be opened again – not even with our help, because we don’t have the key.

Technical logs and abuse prevention

Every request to the website passes through the Cloudflare network and our server. Both necessarily process technical data: IP address, time, page address (without the part after the #, so without the document key) and browser type. The web server keeps these logs for security and troubleshooting for at most 14 days, after which they are deleted. We don’t use them for profiling and don’t combine them with anything.

To prevent overloading the service, we count requests per IP address. We don’t store the IP address in our database for this: we only use a one-way fingerprint (HMAC) whose secret salt changes every day. These records are deleted within 24 hours.

Statistics, cookies and third parties

This website uses no cookies at all. The only cookie in the whole Peekless service is the operator’s login to the admin area on peekless.app – it is never set for visitors. We use no third-party analytics, ads or tracking pixels. All website files (scripts, fonts, icons) are served from our own server.

We only keep anonymous daily totals – for example how many documents were uploaded and downloaded, or how often each tool (Text, Signature, Compress PDF…) or font was used. Your browser sends only the feature name and a usage count per visit – no identifiers, nothing from the document, and page count and file size only rounded into ranges.

When an unexpected error occurs in the editor, your browser sends us its description and location in our code, the website version and the browser and system type (e.g. “Chrome 140, Windows”). Before sending, the report is stripped of document addresses, keys, emails, longer quotes and long numbers – the document’s content is never included. Reports are deleted after 30 days. If your browser has Global Privacy Control or “Do Not Track” turned on, nothing is sent at all, not even the totals.

Who helps us run the website

  • Cloudflare, Inc. – the network the website runs through (speed and protection against attacks). It processes the technical request data described above; it cannot read the encrypted documents. It may process data outside the EU, protected by the EU Standard Contractual Clauses.
  • OVH GmbH – the server that runs the website and holds the encrypted copies (data center in Germany).
  • DigiCert, Inc. – only if you add a timestamp when signing with a certificate (see above).

Stored locally in your browser

If you choose to remember your signature, it is saved only in your browser’s storage on this device. You can delete it in the signature dialog or by clearing the website’s data in your browser. Your browser also remembers the light or dark theme and your last-used settings (such as image format, page size or scan look).

My details for filling in forms (name, address, contacts…) and the name on your comments are also stored only in your browser’s storage – they are never sent to the server. You can keep them only until you close the browser, and delete them at any time with Delete my details. They only get into a document when you fill them in or insert them yourself.

For offline use, your browser stores the editor’s own files (scripts, styles and fonts) – never your documents. A file you share into the app from another app on your phone stays in the browser’s storage only until the editor opens it, and is deleted right after.

So that you can return to a document even after closing the window by accident, your browser remembers the link to its encrypted copy (including the key) and offers it on the home page under Documents in progress. The link stays only on your device, and only until the copy on the server is deleted. You can remove it from the list at any time with the cross button.

Questions and contact

We keep nothing about you as a person – no accounts, names or email addresses. Documents are stored only in encrypted form, they delete themselves, and you can delete the encrypted copy at any time with Delete copy now. The server’s technical logs are deleted after 14 days at the latest. That’s why there’s usually nothing for us to hand over, correct or delete.

Send privacy questions to [email protected]. If you feel we’re not handling data properly, you can lodge a complaint with a data protection authority – for example the one in the country where you live.

Last updated: September 29, 2026. If we change this policy, we will update this page.