A PDF looks like a photograph of a page. What you see is what you send. That is the reasonable assumption almost everyone makes, and it is wrong.
Underneath the visible page, most PDFs carry a second layer of information called metadata. It never appears when you read the document, it survives being emailed, and it travels with the file wherever it goes. It is often more revealing than the document itself.
What's actually in there
Depending on the software that produced it, a typical PDF may carry:
- Author name. Usually pulled from your computer's user account or your Office licence — often your full legal name, even if the document is signed differently.
- Organisation. Frequently the company that owned the software licence when the file was first created.
- Creation and modification timestamps. Including times you edited a document you may prefer to appear finished earlier.
- Producing software and version. A precise fingerprint of your setup.
- The original title. Often the first filename ever given to the document — which is how Draft 3 — do not send to client.docx ends up inside a polished final PDF.
- File paths. Some tools embed the full path of source files, exposing your username and internal folder structure.
Why this matters more than it sounds
Metadata leaks are rarely dramatic. They're quiet, and they tend to land in exactly the situations where you were trying to be careful.
Job applications. You adapt a CV or proposal from a template a colleague sent you. The author field still names them, or their employer. The recruiter sees a document authored by someone else entirely.
Anonymity. Whistleblower submissions, anonymous complaints, and confidential feedback have all been traced back to authors through document properties. If a document is meant to be anonymous, the visible text is only half the problem.
Legal and professional work. Filed documents, expert reports, and disclosure bundles carry authorship and timing data. Opposing parties do look. Timestamps that contradict a stated timeline are awkward at best.
Client confidentiality. If a file path embedded in a document reads /Clients/Henderson-Divorce/, you have just disclosed the existence of another client to whoever received the file.
None of these require a hacker. They require someone to click "Properties."
Strip metadata before you send
PDFRange's metadata cleaner removes hidden document properties in your browser. The file is never uploaded to a server — it never leaves your computer.
Clean a PDF nowScanned documents carry more, not less
It's tempting to assume that scanning a page produces a "clean" file. Often the opposite is true. Scanners and multifunction office printers routinely embed the device model, the machine's name on the network, and occasionally the account of the person who scanned it. Photos taken on a phone and converted to PDF can carry camera details and, in some cases, location data.
How to remove it
Three habits cover almost every case:
- Check before you send. Make document properties part of your final review, the same way you'd check the recipient line on an email.
- Strip metadata from anything leaving your organisation. Internal documents are one thing. Anything sent to a client, a court, a portal, or a stranger should be cleaned.
- Be careful where you clean it. This is the part people miss. Uploading a sensitive document to a random website to "remove its metadata" hands the entire file to a third party. You have solved a small privacy problem by creating a much larger one.
That last point is why PDFRange processes files locally in your browser. The document is read by your own machine, cleaned there, and saved back to your disk. Nothing is transmitted, so there is no server copy, no retention window, and nothing to breach.
The short version
Every PDF you send carries more than the page. Most of the time it's harmless. Occasionally it names your employer, your client, your filename, or the hour you were working — to someone you'd rather not tell.
Checking takes ten seconds. Cleaning takes about the same.