Privacy & Security

flarePDF is engineered on a zero-knowledge architecture. Your files, sensitive agreements, and documents are processed locally on your device and never uploaded to any remote server.

Last updated: March 2025 • Zero-knowledge architecture v2.4

Client-Side WebAssembly

All document rendering, text rewriting, and page manipulation occur in active browser memory via WebAssembly and JavaScript. Your files never touch a remote server.

Zero File Uploads

Unlike traditional cloud PDF editors, flarePDF does not upload your files to any remote server or database. Documents stay strictly on your local hardware.

Offline Capability

Once loaded, flarePDF tools continue functioning with zero internet connection. You can disconnect Wi-Fi mid-edit and all processing continues seamlessly.

Ephemeral RAM Lifecycle

Documents reside solely in your browser tab’s volatile RAM. The moment you close or refresh the tab, all document buffers are permanently wiped.

How to verify our zero-knowledge claims

You do not have to take our word for it. You can inspect network traffic directly in your browser:

  1. 1Open your browser’s Developer Tools by pressing F12 or Cmd + Option + I.
  2. 2Switch to the Network tab and select the Fetch/XHR filter.
  3. 3Drop any confidential PDF, edit text, merge pages, or compress the file.
  4. 4Observe that zero outgoing file payloads or POST requests are made. Everything executes 100% locally.

Data handling & storage specifics

What we do NOT collect or store

  • Your documents, file names, or contents
  • Extracted text, OCR snippets, or images
  • Tracking cookies, marketing pixels, or third-party ads

What is kept locally

  • Theme preference (light or dark mode) in localStorage
  • Wasm engine binaries cached in browser cache for fast loads
  • Zero identifiers or tracking tokens sent to outside servers

DocuSign Pro & legally binding electronic signatures

flarePDF’s core 13 PDF editing, merging, and conversion tools run completely offline and client-side. When users initiate multi-signer electronic contract workflows via our premium DocuSign integration:

  • Documents are encrypted in transit using 256-bit TLS 1.3 and at rest with AES-256 encryption.
  • Signatures generate tamper-evident audit trail certificates fully compliant with the US ESIGN Act, UETA, and the EU eIDAS regulation.
  • Signer verification tokens and audit certificates are signed with cryptographic SHA-256 hashes.

Questions or Security Disclosures

Have a security inquiry or want to report a vulnerability? Contact our engineering team directly at [email protected]. We respond to all disclosures within 24 hours.