PdfMerge Merge, Sort & Split PDFs

← All posts

2026-09-09

Is PDF Mergy Safe? Understanding Local Processing

Is PDF Mergy Safe? Understanding Local Processing
merge pdf sort pdf split pdf

Is PDF Mergy Safe? Understanding Local Processing

Anyone who handles contracts, tax forms, or client records has asked a version of this question: Is PDF Mergy safe? More specifically: if I use a browser-based tool, does my PDF leave my machine? The only useful answer is not “trust us” — it is “verify it.”

RSJ PDF Merge, Sort & Split — PdfMerge — is a browser PDF tool at https://pdfmerge.rsj.de/ that merges, sorts, rotates, removes pages, and splits PDFs. It claims to process files entirely in the browser, with no uploads. In this article, you will see what that means, what privacy evidence looks like, and how to check the claim yourself in a few minutes using your browser’s developer tools.

Why Verification Matters for Browser-Based PDF Tools

Before the verification steps, let’s answer: what is local PDF processing and why should you care?

A cloud-based PDF merger often requires you to upload the file to a server, which is convenient but creates a data-handling risk. Even if the provider is reputable, the file now exists on someone else’s infrastructure during processing. A desktop PDF tool avoids that upload but often requires installation and a local app.

PdfMerge sits between those two options. It gives you browser-based convenience without the upload step of a typical cloud merger. You do not need to install anything, and you can inspect the network behavior yourself.

That last point matters because privacy claims are easy to make and sometimes difficult to trust. A PDF often contains personal data, financial details, or confidential work product. You should not have to rely on a marketing page. Local processing is a property you can observe: if the PDF bytes are not sent over the network, the browser is doing the work.

What Does a Privacy Proof Look Like?

For a browser-based PDF tool, proof of local processing usually means three things:

  1. No network request contains your file data. The browser may download the app shell, scripts, styles, fonts, or images, but it should not upload a PDF payload or send extracted page content to a remote endpoint.
  2. The core operations happen client-side. Merging, sorting, splitting, page removal, and rotation are implemented in JavaScript that runs in your browser’s JavaScript engine.
  3. The behavior is repeatable and inspectable. You can open the developer tools, run the operation again, and see the same absence of upload requests.

RSJ PDFMerge’s web app is a static page that runs JavaScript locally. The merge, sort, split, and page-removal functionality is implemented client-side. When you work with the free version, the 100-page limit is also enforced by the page itself, not by a server-side check.

The Chrome extension follows the same model. It captures the PDF in the active tab and opens RSJ PDF Merge, Sort & Split from https://pdfmerge.rsj.de, so processing remains local. The extension does not add a separate upload path for your PDF.

In the network inspector, a local processing session should look quiet: requests for the app’s own assets, but no POST or PUT that carries your document to a remote service.

Step-by-Step Verification Using RSJ PDFMerge

You can verify PdfMerge’s behavior without installing anything. Use a non-sensitive sample PDF first.

  1. Open https://pdfmerge.rsj.de/ in a desktop browser such as Chrome, Edge, or Firefox.
  2. Open the browser’s developer tools. The usual shortcut is F12, or right-click the page and select Inspect.
  3. Go to the Network tab. Keep it open while you test.
  4. Add two or three small PDF files to PdfMerge, reorder them if you like, and merge them.
  5. Watch the requests that appear in the Network tab.

You should see only the requests needed to render the page: the document, JavaScript bundles, CSS, fonts, and other static assets. A quick way to think about it:

normal_requests:
  - method: GET
    type: document
  - method: GET
    type: script
  - method: GET
    type: stylesheet
  - method: GET
    type: font

upload_indicators:
  - method: POST
  - method: PUT
  - content_type: application/pdf

During a merge operation, you should see no upload_indicators requests to an upload endpoint. The browser may create internal blob: URLs to hold the resulting PDF, but those are not network requests and do not leave your device.

The same check works for sorting pages, deleting pages, and splitting a document. Each action should complete without a network call that carries file data. The 100-page free limit is applied locally, so exceeding it does not require the document to be sent anywhere for validation.

Interpreting Results and Edge Cases

Some network activity is normal. Loading PdfMerge requires HTML, CSS, JavaScript, and possibly font or image assets. These requests are about rendering the app, not about processing your PDF.

The key signal is the absence of a request that could contain your file. If you see a request whose method is POST or PUT and its URL includes words such as upload, merge, convert, or process, investigate further. In PdfMerge’s default behavior, you should not see that kind of request during document handling.

Large PDFs can still cause browser memory pressure. A very large merge might make the tab slow or cause the browser to request more memory, but that is a performance limitation, not a privacy leak. The file stays in your browser’s memory.

The Pro tier’s ZIP features also operate locally. Merging PDFs from a ZIP archive and exporting multiple PDFs as a ZIP happen in the browser, so there is no server-side unzipping step. The same network pattern applies: no upload of the source PDFs, no download from a conversion server.

If you configure the Chrome extension to use a different web app URL, verify that target URL yourself. The official default points to https://pdfmerge.rsj.de, which is the version described here.

For a deeper comparison of browser-based and desktop workflows, see the article Browser-Based PDF Merger vs Desktop Software: Which Is Better?.

FAQ: Is PDF Mergy Safe?

Does RSJ PDFMerge upload my PDF files to a server?

No. RSJ PDFMerge processes PDFs entirely in your browser. You can verify this by opening the browser’s developer tools and monitoring network requests during a merge operation; you will see no uploads of your file data.

Is the Chrome extension safe to use?

Yes. The extension simply captures the PDF in the active tab and opens RSJ PDF Merge, Sort & Split from https://pdfmerge.rsj.de. It does not send your PDF to any server; all processing remains local.

What are the limitations of the free version regarding safety?

The free version is limited to 100 pages per document, but this limit is enforced locally in your browser. There is no difference in safety between free and paid versions; both process files locally without uploads.

Can I use RSJ PDFMerge offline?

The web app requires an internet connection to load the page initially, but once loaded, all PDF processing happens locally in your browser. No data is sent to a server during processing.

Conclusion: Trust but Verify

PdfMerge is safe because its design keeps PDF data in your browser, and that behavior is verifiable. You do not need to take the privacy claim on faith: open the Network tab, merge a file, and watch what does and does not happen.

For most users, the free version is enough to test the workflow on documents up to 100 pages. Pro unlocks unlimited pages and ZIP features, still with the same local processing model. No installation is required, and the tool is convenient for quick PDF tasks such as merging several scanned pages, removing a page, or splitting a document for email.

Open https://pdfmerge.rsj.de/, run a merge with a sample file, and check the network inspector. If you see no file uploads, you have your answer.

Related posts

EU label: AI-generated content