PdfMerge Merge, Sort & Split PDFs

← All posts

2026-09-24

Verify PDF Merge Safety: No Uploads, No Data Leaks

Verify PDF Merge Safety: No Uploads, No Data Leaks
merge pdf sort pdf split pdf

Verify PDF Merge Safety: No Uploads, No Data Leaks

Before you drop a contract, tax form, or internal report into a browser-based PDF tool, ask one practical question: where do my pages actually go? A PDF merger can look polished and still send your file to a server you know nothing about. This article shows you how to verify that a PDF merge is safe, using RSJ PdfMerge as the test case.

You do not need to be a security expert. You need a browser, a few minutes, and the willingness to look at the network requests a page makes. If the tool processes locally, you can see it for yourself.

Why Verification Matters for PDF Merging

A cloud-based PDF merger often requires you to upload the file to a server, which is convenient but creates a data-handling risk. Once a PDF leaves your device, you have to trust the provider to delete it, not train models on it, and not expose it through a misconfigured bucket.

Local processing removes that risk. When a tool runs entirely in the browser, the file stays in memory on your machine. The page may load JavaScript, fonts, and styles, but the PDF bytes never need to travel to a remote backend.

PdfMerge sits between those two options. It gives you browser-based convenience without the upload step of a typical cloud merger. You do not need to install anything, and you can inspect the network behavior yourself.

If you want the conceptual background before the hands-on check, read What Is Local PDF Processing and Why Should You Care? first. This article keeps the focus on verification.

What Proof of Safety Looks Like

For a browser-based PDF merger, proof of safety comes down to three observable indicators:

  • No upload requests: The tool should not send POST or PUT requests containing your PDF data to an external endpoint.
  • Processing in the browser: Merging, sorting, rotating, and splitting should happen locally. You should see no server round-trips that correspond to your document operations.
  • Transparent behavior: The app should state where processing happens and allow you to verify that claim with standard browser tools.

You can observe all of this with the browser’s Developer Tools. The Network tab shows every request the page makes, including the method, URL, and often the payload size. A safe tool should not send file data to an upload API.

A safe local-processing session might look conceptually like this:

# What a safe PdfMerge session should show in the Network tab
safe_requests:
  - url: https://pdfmerge.rsj.de/
    type: document
    contains_pdf_bytes: false
  - url: https://pdfmerge.rsj.de/assets/app.js
    type: script
    contains_pdf_bytes: false
  - url: https://pdfmerge.rsj.de/assets/app.css
    type: stylesheet
    contains_pdf_bytes: false

unexpected_requests:
  - method: POST
    url: https://upload.example.net/
    contains_pdf_bytes: true   # This is what you do NOT want to see

The goal is to confirm that the unexpected condition never appears.

Step-by-Step Verification with RSJ PdfMerge

The best way to verify is to test the tool yourself with sample files. Use two or three PDFs that do not contain sensitive data.

  1. Open RSJ PdfMerge in your desktop browser.
  2. Press F12 or Ctrl+Shift+I / Cmd+Option+I to open Developer Tools.
  3. Go to the Network tab and keep it visible.
  4. Add your sample PDFs and run a merge operation. Use the thumbnail sidebar to reorder, rotate, or delete pages while the Network tab records activity.
  5. In the Network tab, filter for requests that could carry file content:
DevTools → Network → Fetch/XHR
Filter: method:POST OR method:PUT
Expected result: 0 requests carrying PDF bytes
  1. Check the full request list as well. You should see assets such as HTML, CSS, JavaScript, and possibly fonts or icon files. You should not see an upload endpoint receiving multipart form data or binary PDF content.
  2. Open the app documentation or interface text. RSJ PdfMerge states that PDF files are processed entirely in the browser and are never uploaded to a server.

The same network-check pattern applies when you follow How to Split a PDF into Multiple Files in Your Browser. Whether you are merging, sorting, rotating, or splitting, the document data should remain local.

Interpreting Results and Edge Cases

Normal network activity will include requests for the app shell and static assets. Fonts, scripts, and stylesheets may come from the same origin or a CDN. These are not file uploads. A request to a CDN is only suspicious if it contains your PDF data or implies server-side processing.

Analytics may also appear in the Network tab. A privacy-focused verification focuses on whether document bytes are leaving the browser, not on whether the app loads a font or reports page metadata.

The Chrome extension uses the same web app. The extension opens RSJ PDF Merge, Sort & Split from https://pdfmerge.rsj.de, and the web app URL used by the extension is configurable in its options page. The extension does not upload files itself; the local-processing guarantee comes from the web app.

The free version supports documents with up to 100 pages. Paid licenses lift that limit and unlock ZIP features, but the safety verification is the same for free, Basic, Pro, and Enterprise use. A paid tier does not change where the PDF is processed.

If you see an unexpected upload request during a session, investigate it. Check the request URL, payload, and response. With RSJ PdfMerge, you should see zero upload requests containing document data.

Comparing Verification Methods: Browser Tools vs. Cloud Services

With a typical cloud PDF service, you cannot truly verify what happens after upload. You can read the privacy policy, but you cannot observe the server-side storage, retention, or access controls. Auditing a cloud service means trusting the provider.

A browser-based tool changes that balance. Because RSJ PdfMerge runs locally, you can verify the critical claim directly in the Network tab. The app either uploads the file or it does not. There is no hidden backend step to take on faith.

You can also compare this with desktop software. A desktop PDF tool processes files locally, but it requires installation and may tie you to a specific operating system. A browser tool like PdfMerge gives you local processing with the convenience of a web app.

For more on the privacy implications, see Merge PDF Files Without Uploading: The Privacy-First Way. For a deeper comparison of browser-based and desktop workflows, see the article Browser-Based PDF Merger vs Desktop Software: Which Is Better?.

Conclusion: Trust but Verify

You can verify PDF merge safety in a few minutes:

  1. Open https://pdfmerge.rsj.de and start a merge operation.
  2. Watch the Network tab for POST or PUT requests containing PDF data.
  3. Confirm that only app assets are requested and no document payload leaves the browser.
  4. Apply the same check to the Chrome extension by using the same web app URL.

RSJ PdfMerge passes this check: no uploads, local processing, and a transparent workflow. Still, you should run your own test with sample files. Trust is useful, but direct observation is better.

If you verify the workflow and want to use it regularly, the €49.99 lifetime Basic license is a cost-effective way to remove the free 100-page limit for merge, view, sort, remove, and split tasks without a recurring subscription.

FAQ

How can I be sure my PDF isn’t uploaded when using an online merger?

Use your browser’s developer tools to monitor network requests. In RSJ PdfMerge, you will see no requests containing your PDF data because all processing happens locally in your browser.

Does RSJ PdfMerge store my files on its servers?

No. RSJ PdfMerge processes files entirely in your browser. The files are never uploaded to any server, so they cannot be stored or accessed by the service provider.

Is the Chrome extension safe to use?

Yes. The extension opens the RSJ PdfMerge web app from https://pdfmerge.rsj.de and does not upload your PDFs. You can verify this by checking the extension’s permissions and observing network activity.

What should I look for in the network tab to confirm no uploads?

Look for POST or PUT requests that contain your PDF file data. In a safe tool like RSJ PdfMerge, you will only see requests for loading the app’s assets such as HTML, CSS, and JavaScript, not your document content.

Related posts

EU label: AI-generated content