Why this matters
The XMP XML metadata block is often missed by basic metadata removers — it can duplicate or extend the info dictionary data.
Embedded JavaScript can execute on file open, potentially leaking viewer information or compromising the viewer.
File attachments (a rarely-used PDF feature) can carry malware or tracking scripts.
Enterprise PDF generators (Adobe Experience Manager, IBM FileNet) often add custom metadata identifying the organization.
What the scanner detects
- Full XMP XML metadata block (often the largest metadata source)
- Embedded JavaScript and ActionScript triggers
- File attachments and embedded files
- Annotations, comments, and form fields (which can contain identifying info)
- Custom enterprise metadata fields
Ready to scan your PDF?
Drop your file into the scanner. Results in 5 seconds. Nothing leaves your browser.
Open the scannerHow it works
Click "Scan your PDF now" above. The scanner opens in your browser tab — no download, no install.
Drop in your PDF. The file is parsed entirely in your browser using JavaScript. No upload, no server, no logs.
Review your 0–100 risk score, the list of findings, and the AI-generated redaction recommendations. Then take action.
Frequently asked questions
How do I remove hidden background data from a PDF?
Drop your PDF into the scanner above. It identifies all hidden data layers (XMP, JavaScript, attachments, annotations, custom metadata). To remove: use PrivacyScanPDF's metadata remover to strip the XMP block and info dictionary, then use the redact tool if you need to remove specific annotations or attachments.
What hidden data do PDFs contain?
Beyond the visible page content: an XMP XML metadata block (often duplicates and extends the info dictionary), embedded JavaScript, file attachments, annotations and comments, form fields, digital signatures, and custom enterprise metadata fields. Most basic PDF viewers show only a small subset.
Do I need to remove all hidden data?
Depends on your use case. For casual sharing, removing the info dictionary fields (Author, Creator, timestamps) is usually enough. For anonymous sharing, whistleblowing, or sensitive business documents, you should also strip XMP, JavaScript, and attachments. PrivacyScanPDF's scanner shows you everything so you can decide.
Can hidden PDF data survive 'Save As' and email forwarding?
Yes — all of it. The XMP block, JavaScript, attachments, and custom metadata persist through Save As, email forwarding, and cloud sync. They don't go away on their own. To remove them, you need to actively strip them with a metadata remover.
Related privacy scans
How to Delete the Electronic Footprint From a PDF
Every PDF carries an electronic footprint: who made it, what software they used, when, and sometimes where. This footprint persists across saves, copies, and email forwards. To delete it, you need to strip the PDF's info dictionary and XMP metadata block — not just the visible content. This tool does that locally in your browser.
Scrub Tracking Details Out of a PDF File (Free)
PDFs can carry various tracking details: embedded JavaScript that fires on file open, web beacons that ping a server when the PDF is viewed, identifying metadata in the info dictionary, and XMP identifiers that some document-tracking services use. This tool scans for all of them locally and shows you what's tracking you.
How to Unattach the Original Owner Name From a PDF
When you create a PDF, your editing software auto-attaches your name as the 'Author' in the file's metadata. This attachment persists through saves, copies, and forwards — the original owner stays attached. To unattach it, you need to strip the Author field (and ideally the full info dictionary) from the PDF's bytes. This tool does that locally.
Sanitize a PDF Before Uploading to a Public Server
Before uploading a PDF to a public server (court filing system, grant portal, government website, public records repository), you should sanitize it: remove all metadata, embedded JavaScript, file attachments, and any PII in the visible text. This tool scans your PDF locally and shows you exactly what needs to be sanitized before upload.
Your PDF never leaves your device
Every operation runs as JavaScript in your browser tab. No upload endpoint exists. Verify it yourself in DevTools (F12 → Network).