Papaya PDFOpen a PDF Privacy
Papaya PDF is built to keep your documents yours. The short version: your PDF file is never uploaded, we don’t track you, and the one place page content can reach our servers — AI-assisted features — is something you control and can turn off.
Your PDF file stays on your device
Opening, viewing, editing, and exporting a PDF all happen locally in your browser using our PDF engine. The file itself is never uploaded — not to us, not to anyone else. There is no server round-trip to open a document, and simply opening and reading one sends nothing anywhere.
AI-assisted features
Some features use machine-learning models that we run on our own servers: detecting the layout of a page so text and tables can be made editable, recognizing table structure, and OCR for scanned pages. When one of these runs on our servers, we receive an image of the page being analyzed — not your PDF file, and not your document as a whole.
This is triggered by what you do, not by opening a document. Entering Edit mode runs layout analysis on the pages you work with; OCR and table refinement run when you invoke them. Page images are used to compute the result for that request and are not stored afterward. We don’t use your document content to train models.
On supported iPhones, you can instead ask an Apple Vision App Clip to analyze the current page without installing the full app. Papaya’s server temporarily relays an end-to-end encrypted page request and result. The decryption key is established between Safari and the App Clip and is never sent to Papaya’s server, so the server cannot view the page image or resulting layout. The server can see session metadata and encrypted payload sizes. The private relay link expires after five minutes. Request ciphertext is removed when Apple Vision returns a terminal result, completed sessions are removed as soon as Safari receives that result, and abandoned sessions expire automatically from the relay’s short-lived cache.
You choose how this works under AI Settings → Processing profile. Recommended uses our hosted models for the best accuracy. Privacy sensitive scrambles the text in page images before they are sent, so the models see layout and geometry instead of your literal words, and runs OCR on your device. Local only keeps layout and OCR entirely on your device. The setting applies to every document in that browser.
Worth being straightforward about the trade-off: the models that run on your device are smaller and less accurate than the ones we run on our servers. A browser tab has a fraction of the memory and compute of a large GPU server, so the on-device models are chosen to load quickly and finish in reasonable time on an ordinary laptop rather than to be the most capable available. In practice, expect Local only to miss more than Recommended does — less reliable layout and table structure on dense or complicated pages, and weaker OCR on low-quality scans, unusual fonts, and handwriting. That is the cost of the page image never leaving your device, and it is why Recommended is the default rather than the most private option.
Accounts
If you create an account, we store your email address and your authentication credentials — a password hash, or a passkey’s public key. We use them to sign you in, to confirm which features your account has access to, and to send you transactional email such as address verification, password resets, and notices when a passkey is added or removed. We don’t send marketing email.
Your account is not linked to your documents, because your documents never reach us. You can use Papaya PDF without an account for everything that doesn’t require one. To delete your account, write to us at the address below.
Desktop licenses
If we issue you a desktop license, we keep the license’s ownership record, licensee email, issue and update-coverage dates, signing-key ID, a hash of the signed license, and any revocation record. We use this information to let you download the license from your account, provide support, and administer the license program.
The macOS app currently verifies a signed desktop license locally. Using a license does not send us your PDFs, their contents, or a device inventory, and it does not require an online activation check. If we later add device-based activation or seat management, we will update this policy before collecting information for that purpose.
Preferences are stored locally
Settings like your theme and saved signatures are kept in your browser’s local storage on this device so the app remembers them between visits. They stay on your device and are not sent anywhere. Clearing your browser’s site data removes them.
Cloud storage connections
If you choose to connect Google Drive, Dropbox, or another storage provider in a Papaya PDF app, the connection is authorized by that provider. We use the permission you approve to show folders and download the PDFs you choose to open. Connection credentials are kept on your device and are not sent to Papaya PDF servers.
Analytics
We use analytics services to understand aggregate site traffic, performance, and how people use Papaya PDF. These services may collect usage events and technical information such as pages or features used, browser and device details, traffic sources, and performance data.
Product usage data may include actions such as opening, editing, saving, exporting, or sharing, along with limited details such as file size or page-count ranges, export format, and account type. We do not send PDF contents or filenames through product analytics. Analytics identifiers may be stored in your browser and used to associate activity with a browser or account.
Contact
Questions about privacy? Reach us at support@papayapdf.com.
Papaya PDF is early, in-progress software and this notice may evolve as the app grows. If we ever add features that change how data is handled, we’ll update this page.