Why this matters
PDFs silently carry metadata that can identify you, your employer, and your editing history — long after you've shared the file.
PDF metadata has been used in court cases, leaked source identities in journalism, and exposed anonymous peer reviewers in academic publishing.
Most online PDF tools don't show you what's in your file — they just process it on their server, where the metadata becomes their data too.
What the scanner detects
- Author, creator, producer, title, subject, keywords from the PDF info dictionary
- Creation and modification timestamps (often reveal your time zone and working hours)
- Embedded JavaScript and ActionScript triggers
- File attachments and embedded files (often missed by other tools)
- 50+ categories of PII in the visible text: emails, phone numbers, SSNs, credit cards (Luhn-validated), API keys, IBANs, VINs
Ready to scan your PDF?
Drop your file into the scanner. Results in 5 seconds. Nothing leaves your browser.
Open the scannerHow it works
Click "Scan your PDF now" above. The scanner opens in your browser tab — no download, no install.
Drop in your PDF. The file is parsed entirely in your browser using JavaScript. No upload, no server, no logs.
Review your 0–100 risk score, the list of findings, and the AI-generated redaction recommendations. Then take action.
Frequently asked questions
How do I check what's hidden inside a PDF?
Drop your PDF into the scanner above. It parses the PDF info dictionary and content stream locally in your browser, then displays every metadata field, embedded script, and PII pattern it finds. Nothing is uploaded — you can verify in your browser's DevTools (F12 → Network).
What kind of hidden information can be in a PDF?
Common leaks: author name (often your real name from Windows/Adobe account), original file path (reveals your folder structure and OS), editing software and version, creation and modification timestamps, embedded JavaScript, file attachments, comments and annotations, and PII in the visible text like emails and phone numbers.
Is it safe to upload my PDF to a metadata checker?
Not with server-based checkers. When you upload a PDF to iLovePDF, Smallpdf, or Adobe Online, the file (including its metadata) hits their server. Their ToS says they delete it, but you can't audit the deletion. PrivacyScanPDF runs the scan in your browser tab — there's no upload endpoint to hit.
Can PDF metadata really identify me?
Yes. The 'author' field is often auto-populated from your Adobe or Microsoft account. The 'creator' field shows the software you used (e.g., 'Adobe InDesign 2024' reveals your design tooling). The original file path can include your Windows username. Combined, these can de-anonymize documents you thought were anonymous.
Related privacy scans
Is It Safe to Upload a PDF to Remove Metadata?
No — uploading a PDF to remove its metadata is a paradox. The moment the file hits their server, the metadata you wanted to remove has already been disclosed to that third party. The safe way is browser-based: the PDF stays on your device, the metadata is stripped locally, and no copy ever exists on someone else's hardware.
How to Wipe Properties From a PDF Securely
Drop your PDF and the tool wipes every property in the PDF info dictionary — author, creator, producer, title, subject, keywords, creation date, modification date — replacing them with empty strings. The wipe is permanent: the original metadata is removed from the file's bytes, not just hidden. Output downloads to your device; nothing is uploaded.
Can Someone See Who Created a PDF File?
Yes — by default, PDFs store the author name (often your real name from your Adobe or Microsoft account), the creator software (e.g., 'Microsoft Word for Office 365'), and the original file path (which can include your Windows username). Anyone with a free PDF reader can see this. Drop your PDF above to see exactly what it leaks.
Remove Sensitive Hidden Properties From a PDF Online
PDFs hide a surprising amount of identifying information in their properties: author name, editing software, creation timestamps, original file paths, custom XMP metadata. This tool removes all of it — locally in your browser, with no upload to any server. Drop your PDF, get a cleaned version in seconds.
Your PDF never leaves your device
Every operation runs as JavaScript in your browser tab. No upload endpoint exists. Verify it yourself in DevTools (F12 → Network).