Skip to content
BUZZ NEXTERS TOOLS

Security & data handling

We designed BUZZ NEXTERS TOOLS so that the safest place for your files—your own device—is where most processing happens.

Where your files are processed

Each tool page shows where processing happens:
- In your browser: the file never leaves your device. This applies to most PDF, image, QR, barcode, calculator, text and time tools.
- On our server: Office to PDF and HTML to PDF. The file is uploaded over HTTPS and deleted automatically.
- AI: only extracted text is sent to our AI provider.

Automatic deletion

Uploaded input files are deleted as soon as processing ends. Results can be downloaded only with a private link token and are deleted when you remove them or automatically within one hour. A background task removes any leftover files.

Protection measures

  • File type verification using the file's actual content, not just its extension.
  • Size limits, archive-bomb checks and page limits.
  • Conversion engines run without a shell and with timeouts.
  • HTML to PDF blocks private, local and cloud-metadata network addresses, including after redirects.
  • Rate limits, strict security headers and a Content Security Policy.
  • Passwords are hashed with bcrypt; sessions use secure, HTTP-only cookies.

Real redaction

Redact PDF rebuilds each redacted page from pixels, removing the underlying text, images and metadata of that page, then re-reads the output to verify nothing remains. Covering text with a shape—like the white-out tool in Edit PDF—is not redaction.

Reporting a vulnerability

If you believe you've found a security issue, please report it through the contact form with "Security" in the subject. Please don't publicly disclose it before we've had a chance to fix it.