Scan a PDF for private data

or drop one here
Choose a PDF file first.

A PDF carries more than its pages. This scan lists the author, the producer, the creation and edit dates, the XMP packet and the trailer identifier that your file is about to hand a stranger. Remove what you choose and download a clean copy, without the file ever leaving this tab.

How to remove private PDF metadata

  1. Choose a PDF

    Press Choose a PDF, or drop one on the page. The file is read and scanned in this browser tab.

  2. Review what it carries

    The scan groups document details, software fields, dates, other metadata and embedded file attachments. Values are shown only inside the tool.

  3. Choose what to remove

    Every finding starts selected. Keep all selected, clear the list, or choose individual items. The scan does not treat words printed on the pages as metadata.

  4. Read the check, then download

    The cleaned file is opened again. Selected data must be gone, unselected findings must remain, and every page and selectable character must survive before Download appears.

Metadata is not the same as the words on the page

A PDF carries two separate kinds of information about you. The first is metadata: the author field your word processor filled in, the name of the program that produced the file, the creation and modification dates, the keywords, the identifier in the trailer, and any file someone attached to the document. None of it is drawn on a page, which is why people forget it exists and send it out with the file.

The second kind is page content: a name in a letterhead, an address in a footer, a signature scanned into an image. This page does not touch that. Removing a metadata field cannot remove something that is printed on the page, and no scan of the information dictionary will find it. Use Redact PDF for that job, because it rebuilds the affected pages instead of editing a field.

The split matters when you are deciding whether a file is safe to share. Run the scan, clear what you do not want to keep, then read the pages yourself. As a metadata cleaner it makes removal explicit: you see each value before it goes.

Questions

Is the scanned PDF uploaded?
No. The scan, cleanup, verification and download all run in this browser tab.
What can the privacy scan find?
It checks the PDF document information dictionary, XMP metadata, the document identifier and embedded file attachments. This includes common fields such as title, author, subject, keywords, creator, producer and dates.
Does it inspect the words on each page?
No. A name printed on a page is page content, not metadata. This tool does not search or redact page content.
Can I keep some metadata?
Yes. Clear any finding you want to keep. The output check confirms that unselected findings remain.
What does pdfpix verify?
It opens the output again, confirms every selected finding is gone and every unselected finding remains, then compares page count, page size and selectable text with the original. A failed output is not offered for download.
Where does a PDF store the data about me?
In three places. The document information dictionary holds fields such as author and producer. An XMP packet holds a second copy of much of the same thing in XML. The trailer holds a document identifier that follows the file across saves.
Will stripping metadata break the PDF?
No. None of those fields are needed to draw a page. Readers open a file with an empty information dictionary and no XMP packet without complaint, and the check confirms that page count, page sizes and selectable text are unchanged.

The other pdfpix tools

All 30 of them run in a browser tab like this one. Each reads its own output back and checks it before offering the download, and none of them needs an account.

Where to go next