Skip to content
100% local · 0 KB uploadedCompress PDF

How to Share a PDF Safely

🔒 Your files never leave your device. All processing happens locally in your browser.

"Sharing a PDF safely" means three different things at once: protecting the file itself (so the wrong person cannot open it), protecting what the file reveals about you (metadata), and protecting the channel (so the file is not intercepted in transit). This guide covers all three layers, in the order you should apply them, and is honest about which layers a browser-based tool like IXPDF can handle today.

Learn more aboutwhy local PDF processing mattersfor document security.

The three layers of safe sharing

  1. Strip metadata — the PDF's Title, Author, Subject, Keywords, CreationDate, ModDate, Producer, and Creator fields can reveal who made the document, when, and with what tool. This is the cheapest layer and the one most people skip. IXPDF does this locally with Edit Metadata.
  2. Password-protect the file — add encryption so the file cannot be opened without a password. This is the strongest layer when applied correctly (AES-256, a strong password). IXPDF'sProtect PDF tool is currentlyResearch Required — see the section below for why, and which tools to use instead today.
  3. Use an encrypted channel — even a password-protected file should travel over TLS, and for sensitive content, end-to-end encryption. Email is TLS by default; end-to-end requires a provider like ProtonMail or Tresorit, or a separate step (e.g., encrypting the file with GPG before attaching).
Apply the layers in order
Metadata first (cheap, always do it), then password protection (when the content warrants it), then channel (when the recipient and threat model warrant it). Skipping metadata while password-protecting the file is a common mistake — the password stops a stranger opening the file, but the metadata still leaks through the file's properties.

Layer 1: strip metadata before sharing

Every PDF carries a document information dictionary with fields like Title, Author, Subject, Keywords, CreationDate, ModDate, Producer, and Creator. These are visible in any PDF reader's "Document Properties" dialog. They travel with the file wherever it goes — email, cloud storage, a public website. If you wrote the document in Word and exported to PDF, the Author field is probably your name. If you edited it in Acrobat, the Producer field says so.

To strip metadata locally:

  1. Open /tools/edit-metadata/.
  2. Drop in your PDF. The tool reads the metadata and shows every field.
  3. Clear the fields you do not want to share — typically Author, Title, Subject, Keywords, and Creator.
  4. Download the cleaned PDF. The file never leaves your device.

For the full picture of what each field reveals and how to clear it, see How to Remove PDF Metadata.

Layer 2: password-protect the file

Password protection adds encryption so the file cannot be opened (or, optionally, printed, copied from, or edited) without a password. This is the strongest layer when applied correctly: AES-256 encryption with a strong password is, as of 2026, not practically breakable.

IXPDF Protect PDF is Research Required
IXPDF's Protect PDF tool is currently marked Research Required. The reason is technical: the JavaScript PDF library IXPDF uses (pdf-lib) does not yet support writing encrypted PDFs, and adding encryption requires either a different library or WASM-compiled qpdf — both of which are under evaluation. The tool page exists and explains the limit honestly. For now, use one of the trusted local tools below to password-protect a PDF.

Trusted local tools for password protection:

  • Adobe Acrobat Pro (paid) — File → Protect Using Password, choose AES-256.
  • Preview on macOS (free, built-in) — File → Export → Encrypt, set a password. Uses AES-128 on recent macOS.
  • qpdf (free, command line) — qpdf --encrypt "userpw" "ownerpw" 256 -- input.pdf output.pdf. The most flexible option; lets you choose AES-128 or AES-256 and set permission flags independently.
  • PDF24 Creator (free, desktop) — has a "Set PDF password" tool that runs locally after install.

For the full guide on password types, encryption algorithms, and which to pick, see How to Password Protect a PDF.

Layer 3: use an encrypted channel

A password-protected PDF is safe at rest, but it still has to travel from you to the recipient. The channel matters.

  • Standard email (Gmail, Outlook, Yahoo): transport is TLS between mail servers, so the file is encrypted in transit. But the email provider can read the attachment at rest on their servers. For non-sensitive content, this is fine. For sensitive content, it is not.
  • End-to-end encrypted email (ProtonMail, Tresorit Mail): the attachment is encrypted on your device and only the recipient can decrypt it. The provider cannot read it. This is the right channel for sensitive PDFs.
  • Cloud-storage link (Drive, Dropbox, OneDrive): the file is uploaded to the cloud provider; access is controlled by the share settings. Set an expiry, restrict to the recipient's email, and prefer this only when the file is not sensitive enough to warrant end-to-end encryption.
  • Signal, WhatsApp, Wire: end-to-end encrypted messengers. Good for small PDFs; size limits apply (100 MB on WhatsApp, 100 MB on Signal).

Send the password through a different channel

If you password-protect the file and send it by email, do not send the password in the same email. That defeats the purpose — anyone who compromises the email gets both the file and the key. Send the password through a different channel: a text message, a phone call, a separate email to a different address, or a password-sharing tool like OneTimeSecret. This is called out-of-band key exchange and it is the single highest-leverage habit in secure file sharing.

Step-by-step: the safe-sharing workflow

  1. Strip metadata. Open /tools/edit-metadata/, clear Author/Title/Subject/Keywords/Creator, download.
  2. Password-protect (if sensitive). Use Acrobat Pro, Preview, or qpdf to add an AES-256 password. IXPDF's Protect PDF is under research — see above.
  3. Pick the channel. Standard email for non-sensitive, end-to-end encrypted email or messenger for sensitive, cloud link with expiry for large non-sensitive.
  4. Send the password out-of-band. Text, call, or separate channel — never the same email as the file.
  5. Confirm receipt. For sensitive files, ask the recipient to confirm they opened it. Silent failures are how shared files get lost.

Common mistakes

  • Password-protecting but leaving metadata. The password stops a stranger opening the file, but the Author field still says your name. Strip metadata first.
  • Sending the password in the same email. The most common mistake. Anyone who reads the email has both the file and the key.
  • Using RC4 encryption. Old PDFs (and old tools) use RC4, which is deprecated and breakable. Re-encrypt with AES-256. qpdf and recent Acrobat default to AES.
  • Sharing a Drive link with "anyone with the link".That link can be forwarded. Restrict to the recipient's email and set an expiry.
  • Trusting "secure" in a tool's marketing copy."Secure sharing" usually means TLS in transit, not end-to-end encryption. Read the provider's documentation, not the landing page.

For broader best practices on handling sensitive documents, read ourSafe PDF Handling guide.

Try it now

Remove metadata before sharing — local, private, no upload.

Open Edit Metadata

Try it now

Ready to put this into practice?

Run the tool locally in your browser — no upload, no account, no watermarks. Your file never leaves your device.