Stack PDF

Merge a PDF without uploading it

Most free PDF tools are upload sites: your documents travel to a machine you do not control, get merged there, and sit in storage for some period afterwards. Merging does not actually require any of that.

Drop PDFs here

They stay on your device. Nothing is uploaded.

Stack

empty

Add two or more PDFs. They merge in the order you set here, top to bottom.

What “without uploading” means here

The merge runs as code inside the page you are looking at, using your own device’s processor and memory. Your files are opened by the browser, combined, and handed back to you as a download. No request carrying your documents is ever made, because there is no server on the other end to receive one — this site is static files on a CDN.

This is not a privacy policy promising good behaviour. It is a different architecture: the capability to send your file somewhere does not exist in the page.

Check it yourself in thirty seconds

You do not have to take our word for it, and you should not take any site’s word for it.

Press F12 to open developer tools and select the Network tab. Clear the list. Now add your PDFs and press Merge. Watch what appears: nothing, beyond what the page already loaded. Compare that with any upload-based merger, where you will see a large POST request carrying your document the moment you add it.

The offline test is even simpler. Load this page, disconnect from the internet, and merge anyway. It still works.

When this actually matters

For a cat photo, it does not. For documents that identify you or commit you to something, it does: passport and ID scans, signed contracts, tax returns, payslips, medical letters, anything with an account number on it.

The risk with upload-based tools is rarely malice. It is retention and breach — your file sitting on a server for hours or days, backed up, logged, and occasionally exposed when that company has a bad week. A document that never leaves your laptop cannot be included in someone else’s data breach.

Many workplaces also forbid putting client or patient documents through third-party web services at all. In-browser processing sidesteps that, because nothing is disclosed to a third party.

What this does not protect you from

Being honest about the boundaries: in-browser merging protects the file in transit and at rest on someone else’s server. It does not protect you from malware on your own machine, from a malicious browser extension that can read page contents, or from whoever you send the merged file to afterwards.

It also does not encrypt anything. The merged PDF is an ordinary file on your computer. If the contents are sensitive, how you store and send it next is still your problem to solve.

Questions

How can I check that nothing is uploaded?
Open your browser's developer tools before you merge, go to the Network tab, and clear it. Add your files and press Merge. You will see no request carrying your file — the only entries are the page's own scripts, which loaded before you picked anything. The file names never appear in a request body.
Does it work with no internet connection?
Yes, once the page has loaded. Load the page, then turn off your wi-fi, then merge. It works because the code that does the merging is already in your browser. That is also the simplest proof that nothing is being sent anywhere.
Is there a file size limit?
Nothing we impose. The limit is your device's memory, because the whole stack is held in the tab while it merges. Phones handle a few hundred megabytes comfortably; laptops handle far more. Very large merges may make the tab unresponsive for a few seconds.
Do you keep a copy of the merged file?
There is nowhere to keep one. The site is a set of static files with no backend. The merged PDF exists as a temporary object in your browser until you download it, and is gone when you close the tab.

Related