Processed on this device

Privacy

Sumi PDF is a client-side PDF workspace. Core document processing runs in your browser. There is no application server that receives your PDFs for merge, compress, organize, sign, sanitize, or similar tools.

What stays on this device

What may be requested

The app may download its own code: JavaScript, CSS, fonts, workers, and optional WASM engines (PyMuPDF, Ghostscript, CoherentPDF, Tesseract, OCR fonts) from this origin or a version-pinned CDN. Those requests are application assets. They must not include your document.

Digital signature certificate fetching can use an optional CORS proxy. It is disabled unless you configure it. It must never receive PDF bytes. Timestamping talks to a TSA you choose.

Offline

The service worker can cache versioned application assets. It does not cache your documents. Clear offline assets from engine settings.

Local preferences

Language, theme, recent tool IDs, shortcuts, and workflow JSON (without documents) may be stored in localStorage. Clear them in settings or by clearing site data.

Limits

“No artificial limits” means Sumi does not impose accounts, quotas, or watermarks. Device memory and the browser still apply. Extremely large files can exhaust RAM.

Full model: docs/SUMI_PRIVACY_MODEL.md in the source repository. Source code.