Privacy-first PDF tool for legal, HR & government teams

Your PDF never leaves
your browser. Ever.

Strip hidden metadata that could expose your organisation before it does.

No server upload Batch processing Audit certificate DUAA workflow support GDPR · HIPAA · CCPA aware FOIA disclosure ready SRA workflow aware
See pricing → Try the tool free ↓ Whitepaper (PDF, 12pp)

See what your PDF is hiding right now

Drop a file below. We scan it in your browser — nothing is uploaded anywhere.

AuthorDrop a PDF to scan
Creator software—
Creation date—
Document ID—
XMP packet—
PieceInfo streams—

The hidden risk

Every PDF you share contains data you can't see

When you send a contract, a FOIA response, or an HR document, hidden layers travel with it — readable by any software that opens the file. Most organisations don't know until it's too late.

Redaction you can check yourself — open the file, read the page, see what's been blacked out. Metadata you can't; it doesn't show up in any viewer, even after Sanitize has run. Sanitize removes what it can see, but gives you no record that it ran. That's the gap PDF Cleanse closes: a dated, certified record that reasonable steps were taken to remove it — evidence of due diligence if the file is ever questioned.

Stage 1
Info dictionary
Author name, job title, creation date, software version, revision count. Written automatically by Word, Acrobat and Google Docs.
✗ Reveals author identity and internal tools
Stage 2
XMP packets
Adobe's extended metadata format embedded as XML inside the file body. Invisible in viewers. Fully readable by forensic software.
✗ Survives most standard cleaning tools
Stage 3
Document IDs
Two unique hexadecimal fingerprints in the PDF trailer. Link document versions. Can identify a file even after metadata removal.
✗ Missed by Smallpdf and most online tools
Stage 4
PieceInfo streams
Application workflow data written by InDesign, Illustrator and Acrobat. Contains internal project names, operator IDs and stage information.
✗ Rarely stripped by any competing tool
How it works

Three steps. Under thirty seconds.

No account. No installation. No network traffic during processing.

01
Drop your PDFs
Single file or batch. Read entirely in your browser via the FileReader API. Nothing leaves your device.
02
See what's exposed
Every metadata field is surfaced before you clean. Author names, dates, software fingerprints — all visible.
03
Clean & certify
Four-stage deep clean. Clean files download instantly. A dated audit certificate documents every removal.
Compliance coverage

Built for the frameworks that matter

PDF Cleanse supports — but does not replace — your compliance obligations. Consult your DPO or legal counsel for specific requirements.

Relevant to
GDPR — Articles 5 & 17
Removes metadata layers relevant to data minimisation and erasure workflows. All processing is client-side: no document data is transmitted to the vendor.
Relevant to
UK GDPR / ICO 2025
Removes the metadata layers identified in ICO's 2025 anonymisation guidance as relevant to re-identification risk.
Relevant to
HIPAA workflows
Removes author and document metadata that may carry identifiers. All processing is client-side: no document data is transmitted to the vendor.
Relevant to
CCPA
Removes personal identifiers embedded in documents before disclosure.
Workflow
SRA / Law Society
Fits document-checking workflows before disclosure. The audit certificate provides a process record for file notes.
Workflow
FOIA — UK & Scottish
Fits document-preparation workflows before release. The audit certificate integrates with disclosure logs.
Data (Use and Access) Act 2025

Built for DUAA disclosure workflows

The Data (Use and Access) Act 2025's main data protection provisions came into force on 5 February 2026, with updated ICO guidance on DSAR handling and recipient disclosure. The new statutory complaints-handling duty followed on 19 June 2026. Both are now in force. PDF Cleanse provides a documented, repeatable step in document-preparation workflows — metadata removal with a per-file audit record before a document leaves your organisation.

Every licence includes
  • ✓Two-page Document Disclosure Workflow Guide — mapping the tool to ICO requirements for DSARs, FOIA responses, and complaint handling under DUAA.
  • ✓Technical whitepaper — twelve pages of architecture, framework reference, and deployment guidance for your IT team.
Pricing

One price. No subscription.

One-time purchase. No subscription. No renewal.

Individual
£97
One-time · lifetime licence
For 1 user, on any device they use. FOI officers, paralegals, sole practitioners, HR leads who need a reliable private tool.
  • 1 user
  • Four-stage deep clean
  • Batch processing
  • Audit certificate per session
  • DUAA workflow guide included
  • Technical whitepaper included
Buy Individual — £97
Departmental
£987
One-time · up to 30 users
For legal departments, FOI units and HR teams deploying across a full department or public authority. Covers up to 30 users in one organisation, on any device they use.
  • Up to 30 users
  • Four-stage deep clean
  • Batch processing
  • Audit certificate per session
  • Shared drive / intranet deployment
  • DUAA workflow guide included
  • Technical whitepaper included
  • Receipt · PO accepted on request
Buy Departmental — £987

All tiers: receipt provided · Purchase orders accepted on request · 14-day money-back guarantee, no questions asked.

Questions

Frequently asked

Why not just use Adobe Acrobat?+
Acrobat's Sanitize tool removes the metadata Acrobat can see — author, title, comments, basic XMP. It does not strip embedded hexadecimal residue, orphaned object streams, font-cache fingerprints, or producer-chain traces left by the originating application, and it produces no audit certificate, no SHA-256 hash, and no per-file record that sanitisation ran. PDF Cleanse performs a four-stage clean down to the byte level and issues a per-file audit certificate (PDF + JSON, SHA-256 hashed) — a documented, repeatable record of what was removed, when, and from which file. The technical brief sets out the architecture and certificate format in detail. Plus: no Adobe licence required (£2,400/year for 10 seats), no install, no procurement cycle, no per-user subscription. £97 one-time for one user, £397 for up to 10, £987 for up to 30.
Do I need to run Adobe Sanitise first, or does it work on its own?+
It works entirely on its own — no Adobe Acrobat, no Sanitize step, no licence required. PDF Cleanse performs the full four-stage clean regardless of what's been run beforehand. Two things worth knowing: it only processes PDF files — it doesn't clean JPG, PNG, DOCX or other formats directly — and it doesn't strip EXIF or GPS data from images embedded inside a PDF, since that data lives inside the image itself rather than the PDF structure (see the question below on GPS data).
How much paralegal time does this save?+
Manual metadata checking typically takes around 15 minutes per document. At a fully-loaded paralegal cost of roughly £40/hour, that's £10 per document in staff time — whether or not it gets billed on. A firm processing 10 documents a week spends around £4,800 a year on manual checks. The Team tier pays for itself inside a month at that volume. PDF Cleanse processes a batch of twelve documents in under thirty seconds.
How do I know my file genuinely isn't uploaded?+
Open your browser's developer tools (F12) → Network tab, then drop a file. You will see zero network requests made during processing. The file is read via the FileReader API and processed entirely in browser memory. This is verifiable by anyone with basic developer tools.
How many computers can I install it on?+
There is nothing to install — it is a single HTML file that opens in any browser. The licence is contractual, not technical. Individual covers 1 user on any device they use. Team covers up to 10. Departmental covers up to 30. You can copy the file to a shared drive, a USB, or your intranet.
How long will my licence last?+
Your licence is permanent — the tool itself keeps working for as long as your browser opens HTML files, which is likely well beyond 5 years. This is a one-time purchase: no subscription, no renewal, no follow-up emails to manage. If a newer version is ever released, it'll simply be available on the site for you to download if you want it — there's no obligation on either side to track it.
Does it work in an air-gapped environment?+
Yes. Once the page has loaded, it functions entirely offline. For fully air-gapped networks, self-host the pdf-lib script alongside the HTML file — instructions are in the technical whitepaper.
Can we purchase by purchase order?+
Yes. Email info@pdfcleanse.com with your organisation name and required licence tier. We will issue a proforma invoice. A receipt is provided on payment. This avoids the need for a credit card and fits standard government and legal procurement workflows.
Can I read the technical detail before buying?+
Yes. The technical whitepaper (12 pages, PDF) sets out the four-stage architecture, the audit certificate format, the security posture, deployment options, known limitations, and a competitor comparison. It is written for IT administrators, data protection officers, and procurement teams evaluating the tool for internal use. No email required to download.
Does this guarantee GDPR compliance?+
No. PDF Cleanse is a technical utility that supports compliance workflows. It removes the metadata layers described in the whitepaper but cannot guarantee that every form of embedded data is removed from every PDF. It does not constitute legal advice. Your DPO remains responsible for your organisation's compliance obligations.
What happens to my files after I clean them?+
Nothing. The cleaned file is downloaded to your device. The original and cleaned versions exist only in browser memory during processing and are discarded when you close the tab. PDF Cleanse has no server, no database, and no storage. It is physically impossible for us to retain your files.
Will cleaning a PDF invalidate its digital signature?+
Yes, in most cases. Digital signatures in PDFs cryptographically cover the file's byte content — including metadata. Stripping metadata alters that content, which will invalidate any existing signature. If your document carries a digital signature that must remain verifiable, clean first, then re-sign the output.
Does PDF Cleanse remove GPS or location data?+
Not from embedded images. PDF Cleanse removes PDF-level structural metadata — Info dictionary, XMP packets, document IDs, and PieceInfo streams. If your PDF contains embedded images, those images may carry their own EXIF metadata including GPS coordinates. That data lives inside the image itself. If location data in embedded images is a concern, strip EXIF data from the images before embedding them.
Not ready yet?

We'll remind you in one week

Drop your email. We'll send you a reminder with the whitepaper, pricing, and a direct line to ask questions. No spam, no daily emails — just one follow-up in 7 days.