Free privacy scanner
What does your PDF reveal about you?
Every PDF you send carries invisible baggage: your name, your company, editing timestamps, reviewer comments, hidden layers — sometimes even embedded files and scripts. Drop a file below to get your privacy score in seconds. The scan runs entirely in your browser; nothing is uploaded.
Privacy policy: This tool scans PDF metadata locally in your browser — no files are uploaded. To keep the site free, we use cookies and advertising (Google AdSense); third-party ad partners — including Google — may use cookies or similar identifiers to serve and measure ads. See our full Privacy Policy for details on data collection, cookies, and your choices.
Detection scope last reviewed: August 2, 2026
Drop your PDF into the X-ray
or click to choose a file — scanned locally, never uploaded
What the scanner checks — and what each result means
The scanner inspects ten document-level structures that can expose identity, editing history, hidden content, or active behavior. A finding means the structure exists; it does not automatically mean the PDF is malicious.
| Check | What is detected | Important boundary |
|---|---|---|
| Author name | Standard document-info author fields. | Names inside visible page text are not detected. |
| Creator software | Creator and producer application fields. | A recorded application is not itself a security problem. |
| Editing timestamps | Creation and modification dates in document properties. | Dates embedded inside page text or images are outside this check. |
| XMP metadata packet | An embedded XMP metadata stream. | The scanner reports presence and common fields, not every custom namespace. |
| Comments and markup | Page annotations such as comments, highlights, and markup. | Flattened comments that became visible page content cannot be distinguished. |
| Embedded attachments | Files referenced by the PDF EmbeddedFiles name tree. | External links and every uncommon attachment location may require deeper inspection. |
| JavaScript code | Document-level JavaScript name trees and common JavaScript actions. | Obfuscated or malformed structures may evade a browser-level scan. |
| Automatic open actions | Catalog OpenAction entries that can run or navigate when opened. | Viewer behavior varies and additional actions can exist elsewhere. |
| Form fields | Interactive AcroForm fields that may retain entered values. | The scanner does not decide whether a value is sensitive. |
| Hidden layers | Optional-content groups that can hide or reveal content. | White text, cropped content, and steganography are not detected. |
Reproduce the scan with a public sample
Download this intentionally leaky PDF, scan it here, and compare the result. It contains harmless example metadata plus an embedded text attachment; it contains no real personal information or executable script.
Expected findings
- Author name
- Creator software
- Editing timestamps
- Embedded attachment
What this scan cannot prove
- A clean score is not a malware guarantee, legal compliance certificate, or professional forensic examination.
- Visible page text, images, OCR results, redaction quality, external links, and steganography are not classified for personal data.
- Encrypted, damaged, malformed, or unusually structured PDFs can limit what a browser parser can inspect.
- PDF viewers interpret actions and optional content differently, so suspicious findings should be reviewed in the intended viewer.
- The score is a practical sharing checklist, not an industry-standard risk score.
Technical references
These primary references document the PDF structures behind the checks. They do not endorse 1PDF or certify an individual result.
- Adobe: Document properties and metadata overviewAuthor, dates, application fields, and XMP metadata.
- Adobe Acrobat SDK: Embedded file contentHow files are represented in the EmbeddedFiles name tree.
- Adobe Acrobat SDK: Actions and JavaScriptHow PDF actions can open attachments, URLs, or execute scripted behavior.
How it works
Step 1
Drop a PDF
Pick any PDF you are about to send or publish.
Step 2
Get your score
We check 10 common leak points and grade the file from A to F.
Step 3
Fix and share
Clean it with one click, then dare your followers to beat your score.
Frequently asked questions
What can a PDF reveal about me?
Your name, company, software, creation and editing dates, reviewer comments, hidden layers, attachments and scripts.
Does my file get uploaded?
No. The scan runs entirely in your browser. Your PDF never leaves your device.
How is the privacy score calculated?
We check ten common leak points and subtract weighted points for each one found. A score of 100 means nothing leaks.
How do I fix a low score?
Each finding links to a free local tool that removes or flattens the risky content.
Found something nasty?
Scrub names and history with Remove Metadata, or deep-clean scripts, attachments and comments with Sanitize PDF — both free, both 100% local.