Choose LocalPDF when
- You work with contracts, invoices, or other sensitive PDFs that should not leave your device.
- You want a local-first workflow without an upload step before processing.
- You prefer a product workspace over browsing utility pages.
All three tools help users handle PDF files. The fundamental difference is how each handles your documents — whether they stay on your device or are uploaded to a server. This page compares their privacy models, workflows, and public security-related responses observed during an automated surface scan on 2026-07-08.
How this data was collected: Public HTTP response headers and browser cookies were collected via an automated surface scanner on the dates shown. This is not a full penetration test or vulnerability assessment. Headers, cookies, and site behaviour may change after the scan date. Always verify current practices directly.
| Area | LocalPDF | Smallpdf | iLovePDF |
|---|---|---|---|
| Primary model | Local-first PDF workspace in the browser | Upload-first online PDF utility suite | Upload-first online PDF ecosystem |
| File handling | Opens from device — zero bytes uploaded to servers | Uploads files to cloud servers for processing | Uploads files to cloud servers for processing |
| Best fit | Sensitive PDF work: contracts, invoices, internal records | General-purpose online PDF tasks at scale | High-volume general-purpose tasks with broader ecosystem |
| Free tier | Free forever — 3 workspaces, up to 25 pages per document | Free trial and limited free tools | Limited free tools with upload limits |
| Paid plans | Pro from $3.99/month or $39.99/year | Individual and team subscriptions with trial | Individual and team subscriptions with trial |
| Tool breadth | Focused PDF workspace (edit, merge, OCR, sign, convert) | 30+ utility tools, AI PDF Assistant | Very large utility portfolio, AI features, API |
The table below shows which standard response headers were served by each site's homepage during a single automated request. These headers help browsers enforce security-related behaviour. Their presence or absence is a factual observation, not a determination of overall security posture.
| Header | LocalPDF | Smallpdf | iLovePDF |
|---|---|---|---|
Content-Security-Policy | Present — default-src 'self', frame-ancestors 'none', upgrade-insecure-requests | Not detected | Not detected |
Strict-Transport-Security | max-age=63072000 (2 years) | max-age=15552000 (180 days) | max-age=15552000 (180 days), includeSubDomains, preload |
X-Frame-Options | DENY | sameorigin | Not detected |
X-Content-Type-Options | nosniff | Not detected | Not detected |
Referrer-Policy | strict-origin-when-cross-origin | Not detected | Not detected |
Permissions-Policy | camera=(), microphone=(), geolocation=() | Not detected | Not detected |
Note: A Content-Security-Policy (CSP) helps limit which scripts and
resources a page can load. X-Frame-Options: DENY prevents clickjacking by
blocking the page from being embedded via iframe. X-Content-Type-Options: nosniff
reduces MIME confusion risks. Referrer-Policy controls what data is sent in
the Referer header during navigation.
Cookies were collected from a fresh browser context without prior site interaction. Cookie counts and flags reflect a single scan pass — consent banners, logged-in states, or region may affect what cookies are set.
| Observation | LocalPDF | Smallpdf | iLovePDF |
|---|---|---|---|
| Cookies set on homepage | 4 (PostHog analytics, Google Analytics ×3) | 1 (_s.lt — session/cdn) | 1 (__cf_bm — Cloudflare bot management) |
| Cookies with Secure flag | PostHog cookie — yes; GA cookies — not set on homepage scan | _s.lt — yes | __cf_bm — yes |
| Cookies with HttpOnly flag | Not observed on homepage cookies | Not observed on _s.lt | __cf_bm — yes |
| Cookies with SameSite | Lax (PostHog, GA) | Strict | None |
| Notable pricing-page observations | No payment/session cookies on /pricing | Same 1 cookie | 2 cookies: __cf_bm + _csrf-ilovepdf (HttpOnly, Lax, without Secure flag) |
Note: The Secure flag instructs the browser to send the
cookie only over HTTPS. HttpOnly prevents JavaScript access to the cookie.
SameSite controls when the cookie is sent with cross-site requests.
These flags are considered good practices for session and CSRF protection cookies.
LocalPDF is the only tool among the three that processes files on-device without uploading them to a server. It also served more security-related response headers during the automated scan. Smallpdf and iLovePDF offer broader online tool portfolios and AI features, at the cost of a server-upload workflow.
LocalPDF is a stronger fit when contract drafts or signed documents should remain local and never reach a third-party server for processing.
LocalPDF keeps invoices, receipts, and financial statements in a local-first workflow — no upload required to edit or review them.
Smallpdf and iLovePDF serve users who need a large online tool set and accept the server-upload model in exchange for feature breadth.
LocalPDF uses a simple Free + Pro model. Smallpdf and iLovePDF use broader subscription tiers with trials. Verify current rates on each site.
LocalPDF processes files locally in the browser. Smallpdf and iLovePDF upload to servers. For sensitive documents, LocalPDF avoids that handoff entirely.
Based on a public automated scan on 2026-07-08, LocalPDF served CSP, XFO: DENY, nosniff, Referrer-Policy, and Permissions-Policy headers. Neither competitor served these in the same scan pass.
Smallpdf and iLovePDF each set 1 cookie during the homepage scan. LocalPDF set 4 (analytics-related). Cookie state depends on consent and region.
See how LocalPDF compares to other PDF tools: