The file picker does not automatically upload your PDF
When a website asks you to choose a local file, the browser can give that page a File object representing the file you selected. JavaScript can read its bytes after your explicit selection. Reading those bytes is not the same as sending them to a server. An upload happens only if page code then transmits the data through a network API such as fetch, XMLHttpRequest, WebSocket or a form submission. That distinction is the foundation of a local-first PDF tool.
PDF parsing and rendering
A PDF contains objects describing pages, fonts, images, graphics and document structure. NoblePDF uses PDF.js to interpret and render PDF content inside the browser. Rendering typically happens into Canvas elements, allowing the application to show page previews and build interaction layers without turning every page into a server-rendered image.
Why WebAssembly is useful
Some mature document libraries are written in languages normally compiled for desktop or server environments. WebAssembly provides a compact, sandboxed execution format that modern browsers can run efficiently. NoblePDF uses self-hosted WebAssembly for supported operations such as qpdf-based PDF processing and OCR runtime components. The browser still controls the environment; WebAssembly does not get unrestricted operating-system access.
Workers keep heavy jobs away from the interface
PDF rendering and OCR can consume significant CPU time. Web Workers allow part of the work to happen away from the main UI thread so buttons, progress indicators and page interactions remain responsive. Workers have their own rules and must be permitted by the site’s Content Security Policy. NoblePDF’s release checks therefore test not only whether the file exists but whether the runtime can actually execute under the shipped CSP.
Memory, Blob URLs and downloads
After processing, a web app can create a Blob containing the output bytes and expose a temporary object URL for download. This is why a local converter can give you a new PDF without first putting that PDF into permanent cloud storage. Blob URLs are temporary browser references; they are not ordinary public web addresses.
Persistent local projects are different
If an editor wants to recover work after a reload, memory alone is not enough. NoblePDF’s full editor can use IndexedDB for local persistence. IndexedDB is isolated by browser origin, which makes origin design important. Placing the editor on a dedicated app.noblepdf.com origin means advertising scripts on the public site do not automatically share the same origin-scoped storage.
What local processing does not guarantee
Local processing does not mean the web page makes zero network requests. It still needs to load HTML, JavaScript, fonts, workers, WebAssembly and other runtime assets. A feature may also intentionally load a remote resource - HTML-to-PDF is an example when its external-resource option is enabled. The useful privacy question is therefore not “did the browser use the network?” but “was my document content transmitted as part of the requested operation?”
How to inspect it yourself
Open browser developer tools, switch to the Network panel, then choose a PDF and perform the operation. You should be able to distinguish small same-origin runtime requests from a large request carrying document bytes. For persistent storage, the Application or Storage panel can show IndexedDB. These observable properties are more valuable than a vague promise that a site is “private.”
Questions to ask when a site claims “local processing”
You can verify a local-processing claim with ordinary browser tools. Clear the Network panel, choose a test PDF, perform the operation, and look for requests whose size resembles the document. Same-origin requests for JavaScript, workers, fonts or WebAssembly are expected; a multipart upload or large request containing document bytes is a different category and deserves explanation.
- Does choosing the file create a large network upload, or only local runtime requests?
- Are document filenames or extracted text copied into URLs, page titles or analytics events?
- Does the app self-host its processing runtime, or can third-party scripts change independently?
- Is persistent browser storage isolated from advertising and unrelated scripts by origin or CSP?
- Does the tool still work when advertising or analytics are blocked?
For persistent editors, inspect the browser Storage or Application panel as well. IndexedDB entries should stay on the application origin, and clearing that origin should remove locally persisted recovery data. Testing in a fresh browser profile is useful because it shows what the product creates without extensions, cached service workers or unrelated site storage confusing the result.
Privacy testing should include failure cases. Block analytics and advertising domains, disconnect the network after the application has loaded, and retry the document operation. A local-first editor should continue to handle the document even when optional monetisation or measurement infrastructure is unavailable.