Files that never leave your phone: how local processing protects your privacy

Last updated: 2026-09-07

How Many Sensitive Files Have You Uploaded?

Think back to the online conversion tools you've used: ID photos, scanned contracts, bank-statement screenshots. To turn them into a PDF or an image, they were uploaded to a server you've never heard of. Most services claim they "delete immediately after processing", but you have no way to verify that, and the upload itself already happened.

What "Local Processing" Means

Every feature of Image to PDF — image to PDF, stitching, PDF to image, merge, encrypt, decrypt — runs on your phone. Specifically:

In other words, "files never leave your phone" isn't a slogan — it's a direct result of the architecture. With no upload channel, there is no upload.

Where History Is Stored

Every conversion writes to the App's history: operation status, duration, source and output formats, file size. These records live in a local database on the device, and are only readable on that device. Clear the cache or uninstall the App, and they're gone — without going through us. In fact, we couldn't see them if we wanted to.

The Data Boundary Around Ads and Subscriptions

The App's business model is worth spelling out:

Habits for Sensitive Files

Even with a local-processing tool, habits still matter:

  1. Move important output in time. Save conversion results through the share sheet to Files, iCloud, or another drive. Don't leave them only in the App directory.
  2. Encrypt before sending out. Use Encrypt on sensitive PDFs to set an opening password, and send the password through a separate channel.
  3. Clean up regularly. Clear history and output files you don't need in Settings to keep your device tidy.

Privacy isn't protected by promises — it's protected by architecture. Next time you're about to convert a file, ask yourself: does this file need to leave my phone?