Check What Your PDF May Reveal

Inspect supported metadata, comments and document characteristics before you share a PDF. The check runs directly in your browser, so your file stays on your device.

Your PDF stays on your device. Nothing is uploaded.

Why your file stays private

PDFSanitize runs this check inside your browser. The PDF is read and inspected on your device instead of being uploaded for server-side processing.

  • Your browser reads the file you choose directly from your device.
  • The inspection runs in this browser tab. The file isn't stored or modified.
  • As an extra safeguard, this page's security policy tells your browser to block it from making network requests.

What this checker currently inspects

Checked now

  • Standard PDF metadata (title, author, subject, keywords, creator, producer, dates)
  • XMP metadata
  • Custom document properties
  • Supported comments (sticky notes and text-box comments, with their replies and pop-ups)
  • Other annotations, counted by group: highlights & markup, drawings & shapes, stamps & carets, links and form controls
  • Supported form fields and whether they hold entered or default values (values themselves aren't shown)
  • Embedded file attachments (name, type, size and where they're referenced — never opened)
  • JavaScript and document actions (type, where they're attached and script length — never run)
  • Signature structure (presence only, not validity)
  • PDF/A identification

Not checked yet

  • Text attached to highlights, stamps and drawings (the annotations are counted, their notes aren't reviewed)
  • Page content, including text hidden on the page
  • Whether redactions truly removed the underlying content

A result with nothing to review means none of the checked items were found. It doesn't mean the PDF contains no other information.

What can a PDF reveal?

A PDF is more than the pages you see. Alongside the text and images, the file can carry information about itself: who made it, with what software, and when. Most of it is added automatically, which is why it's easy to share without noticing. Checking a PDF before it leaves your hands takes a few seconds.

PDF metadata

Every PDF can store a small set of document properties, usually visible in a viewer's “Document properties” panel:

Author
Often copied from the computer account or app profile that created the file, so it can contain your name, a colleague's, or the name of whoever made the original template.
Creator
The application the document was first made in, such as a word processor or design tool.
Producer
The software that generated the PDF itself, frequently with a version number.
Title and Subject
Free text that can differ from the file name and sometimes keeps an internal or earlier name for the document.
Keywords
Search terms or tags, occasionally left over from a template.
Dates
When the file was created and last modified, usually with a time zone.

None of these fields is a problem in itself. They're worth reviewing when a document is going to a client, an employer, a publisher or the public. If you'd rather not share them, the PDF Metadata Remover can remove them and create a cleaned copy in your browser. To see every stored value, use the PDF Metadata Viewer; to change values instead, use the PDF Metadata Editor.

XMP metadata

Many PDFs keep a second metadata record in a format called XMP, written as XML inside the file. It often repeats the author, title and dates, and it can add unique document IDs and details about the software used. Removing only the standard fields can leave this copy behind, which is why the checker reports it separately.

Comments

Review comments are stored as annotations attached to a page. Sticky notes can show only as a small icon, and many viewers hide comments unless a comments panel is open, so they're easy to send without noticing. The checker counts supported comments (sticky notes and text-box comments, including replies), shows which pages they're on, and lets you view each comment's author and text. If you'd rather not share them, the Remove Comments From PDF tool removes them and re-checks the copy. Other annotations are counted by group: highlights and text markup, drawings and shapes, stamps, links and form controls. When review markup is found, the Remove Annotations From PDF tool can remove it while keeping links and form fields.

Form fields

Fillable PDFs keep the values typed or selected in each form field, and fields can also store a default value. The checker lists the supported form fields and says which ones hold a stored value, without showing the values themselves. When values are found, the Clear PDF Form Fields tool can clear them while keeping the form. To keep the answers visible but stop them being edited, Flatten PDF turns them into page content (flattened values are still readable in the file).

Embedded attachments

A PDF can carry complete files inside it, such as spreadsheets, images or other documents. The checker lists each embedded file's name, type, size and where it's referenced, without opening or extracting it. The Remove PDF Attachments tool can remove the ones you choose.

JavaScript & actions

PDFs can carry actions that run when the file or a page opens, when a form is used or when a link is clicked, including JavaScript. The checker reports scripts and other executable actions separately from ordinary web links and internal navigation, without running anything. The Remove JavaScript From PDF tool can remove them.

Digital signatures

Some PDFs contain a digital signature. The checker tells you when it finds a signature structure, because changing or rebuilding a signed PDF, including cleaning its metadata, can invalidate the existing signature. It doesn't check whether a signature is valid or who signed it.

PDF/A identification

PDF/A is a version of PDF intended for long-term archiving, and a PDF/A file declares this in its XMP metadata. The checker reports that declaration so you know that removing metadata may affect how the file identifies itself. It reads the identification only; it doesn't validate whether the file actually meets the PDF/A standard.

How to check a PDF before sharing it

  1. Drop the PDF into the checker above. It's read in your browser and never uploaded.
  2. Look at the highlighted items, especially the author, title and any custom properties.
  3. If there's something you don't want to share, use the PDF Metadata Remover to create a cleaned copy.
  4. Read through the pages themselves: names and notes can also appear in the visible content.

What the checker does not inspect yet

This version focuses on document metadata, supported comments and annotations, supported form fields, embedded attachments, JavaScript and document actions, and a few document characteristics. A PDF can contain other things that aren't checked yet, including:

  • note text attached to highlights, stamps and drawings (these annotations are counted, not read),
  • hidden or covered page content, including text under a black box that was never truly redacted.

Redaction safety isn't automatically determined for existing third-party PDFs. To redact content yourself, use Redact PDF, which verifies its own output.

So a report with nothing to review is useful, but it isn't a guarantee. Read through the document itself before sharing anything sensitive.

FAQ

PDF privacy checker FAQ

What the checker does today, and what it doesn't do yet.

Does PDFSanitize upload my PDF?

No. The privacy check runs locally in your browser. Your PDF is read and inspected on your device and is not uploaded to our servers. The page and the code that runs the checker still load over the internet, like any website.

What does the PDF Privacy Checker inspect?

It currently checks the standard document metadata fields (title, author, subject, keywords, creator, producer, and the creation and modification dates), custom document properties, XMP metadata, supported comments (sticky notes and text-box comments, including replies), other annotations counted by group (highlights and markup, drawings and shapes, stamps, links and form controls), supported form fields and whether they hold entered or default values, embedded file attachments (name, type and size), JavaScript and other document actions (never run), whether a digital signature structure is present, and whether the file identifies itself as PDF/A.

Can a PDF contain my name?

Yes, it can. The Author field is often filled in automatically from the computer account or app profile that created the document, and XMP metadata may repeat it. Supported comments also show their author. Supported form fields that hold values are reported too, without showing the values. Names can also appear in the visible text or in notes on highlights, which this checker doesn't inspect yet.

What is XMP metadata?

XMP is a second way of storing metadata inside a PDF, written as XML. It often repeats the author, title and dates from the standard fields and can add details such as unique document IDs and the software used.

Does a clean result mean my PDF contains no hidden information?

No. A result with nothing to review means none of the items this checker inspects were found. PDFs can also contain note text on highlights and page content, including text that looks redacted but isn't, which this version doesn't check yet.

Can the checker inspect password-protected PDFs?

Not yet. If a PDF is encrypted or password-protected, the checker tells you it can't inspect it. It doesn't try to get around the protection.

Does this verify digital signatures?

No. It detects whether a signature structure is present. It does not perform cryptographic signature validation, so it can't tell you whether a signature is valid or who signed the document.

Can I remove the metadata it finds?

Yes. The free PDF Metadata Remover removes the standard metadata fields, custom document properties and XMP metadata, creates a cleaned copy in your browser and re-checks the result.