Privacy
Sumi PDF is a client-side PDF workspace. Core document processing runs in your browser. There is no application server that receives your PDFs for merge, compress, organize, sign, sanitize, or similar tools.
What stays on this device
- PDF and image bytes, filenames, text, thumbnails, and metadata
- The session workspace (memory only; not written to localStorage)
- Passwords you type, which are never stored or exported in recipes
What may be requested
The app may download its own code: JavaScript, CSS, fonts, workers, and optional WASM engines (PyMuPDF, Ghostscript, CoherentPDF, Tesseract, OCR fonts) from this origin or a version-pinned CDN. Those requests are application assets. They must not include your document.
Digital signature certificate fetching can use an optional CORS proxy. It is disabled unless you configure it. It must never receive PDF bytes. Timestamping talks to a TSA you choose.
Offline
The service worker can cache versioned application assets. It does not cache your documents. Clear offline assets from engine settings.
Local preferences
Language, theme, recent tool IDs, shortcuts, and workflow JSON (without documents) may be stored in localStorage. Clear them in settings or by clearing site data.
Limits
“No artificial limits” means Sumi does not impose accounts, quotas, or watermarks. Device memory and the browser still apply. Extremely large files can exhaust RAM.
Full model: docs/SUMI_PRIVACY_MODEL.md in the source repository. Source code.