Search for a way to merge two PDFs and you will find dozens of free sites that do it well. They work by receiving your file, processing it on their servers, and giving you back a download. That is a reasonable way to build a web application and there is nothing inherently sinister about it. It is worth understanding what it involves, because the answer varies a great deal by document and the sites themselves rarely make it prominent.
Your file is transmitted to a server, written to disk or object storage, processed, and the result written back. The original and the output both exist as files on infrastructure you do not control, for some period. Most reputable services delete them on a timer, commonly an hour. Deletion means the file is unlinked; whether it is overwritten, and whether it existed in backups or logs in the meantime, is generally not specified.
Read a few and a pattern emerges. They commit to deleting uploaded files after a stated period. They usually do not commit to never reading them, because automated scanning for abuse and malware is standard and necessary. They frequently reserve the right to retain metadata indefinitely. Many are operated by companies in one country with servers in another, which determines whose law applies and who can compel disclosure. None of this is unusual or dishonest. It is simply a different situation from the file not leaving your computer.
A restaurant menu. A conference programme. Photographs you would post publicly anyway. A CV you are about to send to strangers. For most documents most of the time, upload-based tools are fine, and their fidelity is often better because a server can run software a browser cannot.
Documents under a confidentiality agreement. Anything containing personal data about someone who is not you, where you may have a legal obligation about where it goes. Medical records. Financial statements with account numbers. Legal filings before they are filed. Photographs of identity documents — which, notably, is one of the most common things people convert to PDF. In a regulated workplace, uploading a client document to a consumer web service is frequently a policy breach regardless of the service’s own practices.
Everything happens in JavaScript running in your tab, using libraries the page downloaded. The file is read into the memory of that page and never transmitted. The distinction is not that the site promises not to look, but that there is no mechanism by which it could — no request is made. You can confirm this on any site claiming it: open the network tab in your browser’s developer tools, run the tool, and see whether anything is sent.
Browser tools cannot do everything. Matching Word’s page layout exactly needs Word’s layout engine. Reading text out of a scanned image needs OCR models that are impractical to ship to a page. Processing a file larger than available memory needs streaming to disk. Anything genuinely heavy is slower than a server would be. A browser tool that claims to do all of these is either doing them badly or quietly uploading after all.