PDF Kami EU-Hosted

Blog

Is Smallpdf safe?

A Swiss company, servers in Europe, deletion "after one hour": Smallpdf sounds reassuring. We read its privacy policy, its terms and its security pages. Retention, American subcontractors, trackers, AI: here's what you agree to when you drop in a file.

Smallpdf is one of the most widely used online PDF tools in the world: the company claims more than 40 million monthly users (Smallpdf). It's Swiss, it displays a security certification and it promises to delete your files quickly. Before you drop a document on it, one simple question: what exactly are you agreeing to? Not what the home page says — what the privacy policy, the terms of use and the security pages say. We read them on 27 September 2026. Everything below links back to their pages: check for yourself.

Who's behind Smallpdf?

Smallpdf AG is a company incorporated under Swiss law, based in Zurich and founded in 2013 (privacy policy, Smallpdf). Its terms are governed by Swiss law. In 2022 it bought PDF Tools AG, a developer of PDF technology, for $30 million (PR Newswire), then sold it on to the American company Apryse in July 2026, while remaining independent itself (Startupticker).

Switzerland isn't a member of the European Union, but the European Commission recognises its level of data protection as adequate. As far as the law governing the company is concerned, that's a point in its favour.

Promise versus reality

What Smallpdf advertises What its other pages say Source
Files "permanently removed from our servers after one hour" The privacy policy only gives that one-hour deadline to users with an account. Without one, Smallpdf merely says it aims to delete files "within a reasonable period of time" after they were last opened. Blog, Privacy
Servers "located in Ireland" The privacy policy refers to servers managed by Hetzner in the European Union, and to possible temporary storage with Cloudflare, "in the United States or in Europe", during processing. Blog, Privacy
ISO 27001 certification, GDPR compliance Displayed on the trust centre, where the certificate itself isn't published. Trust Center
"We do not use these files to train models" The terms specific to the AI features mention OpenAI as a provider — a name that doesn't appear in the privacy policy itself, which refers readers to those terms. Usage data from the AI features is kept for 90 days. Privacy, AI terms

None of these differences is a lie. They're pages written at different times, for different audiences. But that's precisely the problem: someone searching "is Smallpdf safe?" reads the blog, not the privacy policy. And it's the privacy policy that counts: the GDPR requires it to state, among other things, how long data is kept, the categories of recipients and the safeguards covering transfers outside the European Union (LegalPlace).

Where does your file go, and who can ask for it?

The file you drop in leaves your computer. According to Smallpdf's policy, it's processed on servers run by the German company Hetzner in the European Union — a fairly reassuring choice. But that isn't the whole story.

There are American intermediaries along the way. The privacy policy states that data may be stored temporarily, for the duration of processing, on servers run by Cloudflare, a San Francisco company. Other providers it names are also American, or subsidiaries of American groups: Amazon Web Services, Google, Stripe, PayPal. And the CLOUD Act, a 2018 US law, lets the US authorities demand that an American company hand over the data it holds, including on servers located in Europe. Smallpdf covers its transfers with standard contractual clauses; those clauses bind Smallpdf and its providers, not the US government.

Retention is vague for users without an account. Paradoxically, it's by creating an account that you get the most precise commitment: deletion within one hour, unless you save the file. Without an account, "a reasonable period of time" commits Smallpdf to nothing you can measure. And files you save and then delete are "generally" erased within 14 days.

No data breach at Smallpdf has been documented to date, and the company takes part in a public vulnerability disclosure programme. That's to its credit.

The journey of a file dropped on Smallpdf: sent over the internet, possibly via Cloudflare (United States or Europe), processed on Hetzner servers in the European Union, kept for one hour with an account or for a "reasonable" period without one, advertising trackers on the page

What the page collects before you've even dropped a file

The privacy policy lists analytics tools (Google Analytics, Hotjar, HubSpot) and advertising tools (Google Ads, the Meta pixel, LinkedIn Insight Tag), subject to your consent through the cookie banner. To be valid, that consent has to come from a positive action: no pre-ticked boxes, and simply carrying on browsing doesn't count (LegalPlace).

Independent measurements go further. WhoTracks.me, Ghostery's tracker observatory, recorded 11 trackers on smallpdf.com that appear on at least 5% of the pages observed (22 counting the rarer ones), with an average of 4.4 trackers per page. Among the most common are Google Tag, Datadog and Microsoft Advertising, present on 63% of the pages observed (WhoTracks.me). Microsoft Advertising, Datadog and TrackJS are not named in the privacy policy we consulted, which only mentions general categories of provider (error logging, marketing).

How free is it?

Smallpdf runs on a freemium model: a few free operations, then a subscription. The site doesn't put a figure on the free plan's limit ("limited document downloads") and displays its prices dynamically; on 27 September 2026, its pricing page, viewed from France, showed the Pro plan at €7.50 a month on annual billing (€90 a year) and €10 on monthly billing (Smallpdf). Beyond the first few operations, the service prompts you to create an account — and from then on, every file is tied to an identity.

So, is it safe or not?

Safe from what? From interception in transit: yes, the connection is encrypted. From a fly-by-night outfit: yes, Smallpdf is an established, certified company with no known incidents. From your file sitting on third-party servers for a while: no, that's how the service works. From a request by a US authority to one of its subcontractors: no, nothing legally prevents it. From advertising trackers on the page: no, unless you refuse them.

So the honest question isn't "is Smallpdf safe?" but: does this document have any reason to leave your computer?

The same job, without uploading the file

Merging, compressing, splitting, turning images into a PDF, watermarking: a modern browser can do all of it on your own machine. That's what PDFKami does. The page reads the file, transforms it in memory and hands it back to you as a download. It isn't uploaded: no subcontractor, no retention period, no CLOUD Act. No account, no cookies, no trackers, no adverts. And you don't have to take our word for it: try it once, switch off the Wi-Fi, and the tool still works — here's how to check, on our site and on theirs.

What PDFKami doesn't do: OCR, PDF-to-Word conversion, electronic signatures. For those, you still need a server — and you now know which pages to read before you choose one.

FAQ

Does Smallpdf keep my files?

With an account, it deletes them within an hour unless you save them. Without one, its privacy policy gives no precise timeframe ("a reasonable period of time"), even though its blog says one hour.

Where are files uploaded to Smallpdf stored?

On Hetzner servers in the European Union, according to its policy, with a possible stop at Cloudflare, in the United States or Europe, during processing.

Is Smallpdf subject to the CLOUD Act?

Smallpdf is Swiss, but several of its subcontractors are American, including Cloudflare. They can be targeted by a request from the US authorities.

Does Smallpdf use my files to train AI?

It says not. According to its AI-specific terms, its AI features rely on OpenAI; those terms state that data isn't shared for training and that usage data is kept for 90 days.

Does Smallpdf have advertising trackers?

Yes. Its policy cites Google Ads, the Meta pixel and LinkedIn; WhoTracks.me observed 11 trackers on at least 5% of pages (22 in total), including Microsoft Advertising.

Has Smallpdf had a data breach?

None has been documented as of 27 September 2026.

Read next

← All articles