UseVelyoBrowser-local tool

Privacy-first browser diagnostic

Check your PDF before you send it

Catch hidden comments and attachments before your client does.

Scan a PDF locally

Why scan before sharing?

A finished-looking PDF can still reveal more than you expect

Information can remain in the document structure even when it is not visible during a quick review. This scanner looks for five common signals that deserve a closer check.

  • Hidden text

    Text may remain extractable even when it is not visibly rendered.

  • Metadata

    Author, creator, software, and date details can travel with a file.

  • Comments

    Annotations and review notes can remain attached to document pages.

  • Embedded content

    Attachments or scripts may be packaged inside the PDF structure.

  • Incomplete redaction

    A dark cover can leave the underlying text available for extraction.

Who is this for?

People who share documents beyond their immediate team

  • Legal professionals
  • Freelancers
  • Small businesses
  • Researchers

Privacy statement

Your PDF stays on this device

The scan runs locally in your browser. Your PDF is not uploaded to the UseVelyo compression API or sent to an external document-processing service.

This is a diagnostic aid, not a guarantee that a document contains no privacy risks.

Three-step review

How to check a PDF for supported privacy risks

Choose a PDF, run the browser-local scan, and review both the findings and the scanner's stated limits.

  1. Step 1

    Choose a PDF or synthetic demo

    Select one PDF up to 25 MiB and 500 pages, or begin with a synthetic demo that contains no user data.

  2. Step 2

    Run the browser-local scan

    Choose Scan PDF. The browser worker checks supported document structures without uploading the file to the compression API.

  3. Step 3

    Review findings and limits

    Read each reported signal, note which checks were limited, and review the original document before relying on the result.

Try a synthetic demo first

These small PDFs are generated in this page and contain no user data.

Local, read-only processing: the PDF is parsed in a browser worker. It is not uploaded, changed, converted to Base64, or sent to the compression API.

Important limits

This scanner does not detect every privacy risk. A reported redaction issue is a heuristic that requires human review, not proof that a file is safe or unsafe.

White text on a light background can be flagged heuristically. Complex masks, images, scanned content, and unusual PDF graphics may not be classified reliably.

It does not validate digital signatures, certificate chains, complete encryption state, incremental update history, or non-JavaScript actions.

The scanner is read-only. It does not remove metadata, attachments, comments, form values, scripts, visible content, or any other content from the PDF.

Read the engineering postmortem on how real-world false positives changed the detector: PDF redaction false positives.

Frequently asked questions about the PDF Privacy Scanner

What does the PDF Privacy Scanner check?

It checks supported patterns for document metadata, hidden-text indicators, comments and annotations, embedded files, JavaScript, and possible incomplete redactions. The report contains diagnostic signals, not a complete inventory of every kind of hidden content.

Can it verify redaction on an image-only scanned PDF?

No. When a scanned page has no extractable text layer, the scanner cannot compare underlying text with a visual cover. Image-based redaction and OCR-only content may require separate visual or OCR-assisted review.

Can it detect every way content can be hidden in a PDF?

No. Complex clipping masks, arbitrary graphic overlays, unsupported PDF structures, and some image-based content can fall outside the supported checks.

Does a clean report mean the PDF is safe to share?

No. A clean report means the supported checks did not report a risk. It is not a safety guarantee, compliance determination, or substitute for reviewing the document before sharing it.

Is the PDF uploaded while it is scanned?

No. The PDF is processed locally in a browser worker and is not uploaded to the UseVelyo compression API or an external document-processing service.

Use the scanner for a specific review