What actually happens when you upload a PDF?
The file is copied to a server, usually in another country, written to disk or object storage, processed, and offered back as a download. Along the way it may pass through a load balancer, a queue and a cache, and be logged by each of them.
Deletion policies describe the intent, not the mechanism. Backups, crash dumps, CDN caches and support copies all sit outside the "delete after one hour" path, and none of it is visible to you.
Which documents make this worth caring about?
The everyday list is not exotic: bank statements, payslips, tax returns, passports and IDs, medical letters, custody and divorce papers, signed contracts, NDAs, tender documents and anything covered by a client confidentiality clause.
For a business, an upload can be a reportable data transfer under GDPR or an NDA breach, whatever the site does with the file afterwards.
How do you check what a page sends?
Open the browser’s developer tools, choose the Network tab, then add a file and run the tool. Watch the request list. An uploading site shows a POST or PUT the size of your document. A local tool shows only its own scripts and, for some jobs, a one-time engine download.
A second test: switch off the network after the page has loaded and run the tool again. If it still works, nothing was being sent.
This site is built so those two tests pass. There is no upload endpoint in it at all — the tools have nowhere to send a file even if they tried.
What should you check about the file itself?
Before sending a PDF to anyone, look at what is inside it beyond the page: author and software fields, hidden text under images, attachments, JavaScript, and personal numbers in the body text. The privacy scanner reports all of those in one pass.
Then clear what should not travel. Metadata is the usual culprit, and it is one click.