What PDFCore does not collect
The application does not collect your PDFs, converted documents, file names, OCR text, annotations, passwords, scanner pages or usage analytics. It has no account system, advertising SDK, telemetry client, web server or automatic uploader.
Local document processing
Opening, rendering, editing, OCR, scanning, conversion and saving are performed on the Windows computer. The website button opens pdfcore.com in your default browser, but PDFCore does not attach or upload the open document.
Temporary files
Conversion and rendering operations use uniquely named temporary work folders. A protected document opened with an authorized owner password may be copied to a short-lived local working directory so editing and conversion tools can operate consistently. PDFCore deletes that session directory when the document is replaced or the application closes. As with any desktop program, an unexpected power loss or forced process termination can prevent immediate cleanup; normal Windows storage hygiene still applies.
Passwords and protected PDFs
PDFCore does not attempt to recover forgotten passwords. An open password may allow viewing, while owner authorization is required for changing permissions or using restricted editing and conversion tools. Passwords supplied for a merge task remain in memory for that task and are not written to a PDFCore cloud service because there is no such service.
Redaction versus visual cover
Secure redaction rasterizes each affected page so covered source text and interactive objects are removed from that page. Unaffected pages remain in their original object form. Cover and replace adds a visual cover and replacement text; the covered source content may still be extractable. Use secure redaction for permanent removal and independently verify highly sensitive output before distribution.
Compression choices
The recommended structure-preserving mode retains the PDF object model. Rasterized archive modes rebuild every page as an image and therefore remove selectable text, links, forms, bookmarks, signatures and accessibility structure. The app names and warns about this destructive trade-off before proceeding.
Installer trust
The current PDFCore installer is not Authenticode-signed. Windows may show an unknown-publisher warning. The download page publishes the exact file size and SHA-256 checksum so you can verify the release artifact. A checksum confirms file identity; it is not a substitute for a trusted publisher signature.
Security reporting
If you believe you found a security issue, do not send a confidential document. Visit the support page for the current reporting route and include the PDFCore version, Windows version, reproducible steps and a synthetic sample when possible.