jPDF is a native PDF editor for macOS. It edits document text, annotates, redacts, runs OCR, builds and fills forms, and signs and certifies documents. There is no account to create, no subscription server to talk to, and no analytics or telemetry of any kind.
We receive nothing from your use of jPDF unless you deliberately send it to us - which in practice means submitting a bug report. We do not sell or share your data.
Overview
jPDF runs inside Apple's App Sandbox and works on the documents you open. Editing, redaction, OCR, table extraction, barcode reading, form scanning, and the Apple Intelligence features all run on your Mac.
The application requires macOS 26 or later on Apple Silicon. Some features additionally require Apple Intelligence to be available and switched on; where it is not, those features are disabled rather than routed anywhere else.
Data We Do Not Collect
- No account is required to use jPDF.
- No analytics, telemetry, tracking, or usage reporting of any kind - none, at any time.
- No advertising identifier, device identifier, serial number, or persistent user ID.
- Your documents are never uploaded. No document text, page images, or form field values leave your Mac.
- No record of where your files live on your Mac is sent to us.
- No third-party analytics, crash-reporting, or advertising SDK is present in the application.
- We do not sell or share your personal data for advertising purposes.
Your Documents Stay on Your Mac
Every operation jPDF performs on a document happens locally. That includes editing the page's real text, permanent redaction, OCR of scanned pages, table extraction, barcode and QR reading, export to other formats, form authoring and filling, compression, encryption, and the creation of cryptographic signatures.
Text recognition uses Apple's Vision framework on your device. There is no cloud OCR step and no document data is transmitted for any of this work.
On-Device Data
jPDF stores the following locally on your Mac to provide its features:
- application settings and preferences, such as image export format, resolution, and quality
- your signature library - images you add, kept in the application's own support folder
- form templates you choose to save
- the organisation and email values you optionally supply when creating a self-signed signing certificate
- an activity log of what the application did (documents opened, which save path ran, edits, OCR, signing, and errors), kept for the current session, with the previous session retained so it can be attached to a bug report if you send one
- a short-lived record used to stop an identical bug report being sent twice within ten minutes
- temporary working files created during operations such as merge, split, OCR, redaction, and signing, which are removed when the operation finishes
The activity log records events, not content: it never contains the text of your document, page images, or form values. Your recent-documents list is maintained by macOS itself, not by us.
Apple Intelligence and On-Device AI
jPDF's AI features - AI Text, AI Doc, AI Fields, AI Form, AI Scan, and Deconstruct - use Apple's on-device Foundation Models and the Vision framework, running on your Mac's Neural Engine. Nothing is sent to Apple, to us, or to any other service, and no internet connection is required for them.
jPDF does not integrate Apple's Writing Tools and does not use Private Cloud Compute. Every AI feature in jPDF is strictly on-device. If Apple Intelligence is unavailable on your Mac, these features are simply switched off.
When jPDF Uses the Network
There are three things in jPDF that can open a network connection. You start all three yourself, and none of them sends your document:
- Trusted timestamps (RFC 3161). When you add a trusted timestamp to a signature, jPDF sends a cryptographic hash of that signature to the Time-Stamping Authority you have chosen. A hash cannot be turned back into your document, and the document itself is never transmitted.
- Long-Term Validation (Add LTV). To make a signature remain verifiable after its certificate expires, jPDF asks the revocation responder named in the certificate whether that certificate is still valid, and may download the issuing authority's certificate. These are certificate-status queries about the certificate, not about you or your document.
- Bug reports. Described in the next section. Sent only when you choose to send one.
If you do not use those three features, jPDF does not open a network connection at all. The timestamp and revocation servers are operated by the certificate authorities concerned, not by us, and have their own privacy practices.
Optional Bug Reports
jPDF includes an optional bug reporter, available under Help › Report a Bug…. Sending one is entirely voluntary. Before a report is composed, the application shows you exactly what it will contain; before it is sent, it shows you the finished report so you can read it, copy it instead, or cancel. It is sent over an encrypted connection to an endpoint on our own domain, and is not handled by any third-party form service.
Where the report is stored. That endpoint runs on web hosting provided by Westhost, our hosting provider. Westhost stores and transmits the report on our behalf as a service provider, under its own terms; the contents are used only by us, to investigate the problem you reported, and are not passed to anyone else or used for advertising.
A bug report includes:
- anything you type into the report
- your email address, only if you enter one, and used only to reply to you about the report
- what the application did - the recent activity log for this session, and the previous session's log if jPDF did not shut down normally last time
- structural facts about the open document: page count, file size, and whether it is encrypted, certified, or contains form fields
- information about your Mac: model identifier, macOS version, jPDF version, screen size, memory, whether Apple Intelligence is available, language, and time zone
- a randomly generated report identifier that cannot identify you
A bug report never includes:
- the contents of your document - no text, no page images, no form values
- where the file lives on your Mac
- its file name, unless you tick the box to include it
- your name, or any account, device, serial-number, or tracking identifier
If you never send a bug report, none of this information is transmitted and we never receive it.
Crashes
jPDF has no automatic crash reporting. If the application did not shut down normally, it records that fact locally and offers to include the previous session's activity log the next time you choose to send a bug report. Nothing is transmitted unless you send that report yourself.
File Access and Sandboxing
jPDF runs in Apple's App Sandbox. It can read and write the files you explicitly open or choose through a standard macOS dialog, and remembers that permission for documents you reopen. It requests permission to print, and permission to act as a network client - used only for the three purposes described above.
jPDF does not request or use access to iCloud, Spotlight indexing, Handoff, your camera, microphone, contacts, calendars, or photo library.
Third-Party Components
jPDF is built on Apple's own frameworks together with a small number of statically linked open-source libraries: PDFio (Apache 2.0) for lossless PDF writing, and Apple's swift-certificates, swift-crypto, and swift-asn1 for the signing suite. These are local code libraries. None of them contacts a network service, and no third-party analytics, advertising, or crash-reporting component is included in the application.
Contact
If you have questions about this policy, please contact us through the jPDF support section or the support channel listed on the App Store page.
Additional Links
This page is intended as the public privacy policy for jPDF.