keptlocal
· Updated · 7 min read · PDFPrivacy

When to Merge PDFs in Your Browser (and When You Shouldn't)

HP
Hitendra Patel
Founder, keptlocal · Senior Technical Lead, Healthcare IT

Contracts, invoices, tax returns, medical records: the kind of documents that end up in PDF merges are often the ones you least want to hand to a stranger's server. Modern browsers can merge PDFs directly instead — no upload required. This is a practical guide to when that matters, when it doesn't, and how to check for yourself that nothing left your device.

For the full story on why free PDF tools default to uploading your files in the first place, see why PDF tools shouldn't upload your files. This post stays focused on merging specifically: what it can and can't do, and when to reach for something else.

How browser-based PDF merging works

Modern browsers can run sophisticated JavaScript libraries that were previously only feasible on a server. pdf-lib is one such library — a pure-JavaScript implementation of the PDF specification that can read, manipulate, and write PDF files entirely within the browser tab, with no server involved.

When you merge PDFs using a browser-based tool like keptlocal's Merge PDF, here is what happens:

  1. You select files using the browser's File API — the files move from your disk into the browser's memory (RAM). They have not touched the network at this point.
  2. pdf-lib reads the PDF object structure from each file's byte array in memory.
  3. It creates a new empty PDF document and copies the pages from each source document into it, in the order you specified.
  4. It serialises the merged document back to a byte array.
  5. The browser constructs a temporary object URL from that byte array and triggers a download. The file goes from browser memory directly to your downloads folder.

No network request is made at any point in that sequence. The entire operation runs on your CPU, in your browser tab, using your device's RAM — the tool's own JavaScript is served once from keptlocal, not re-fetched per file, so nothing about your PDFs' content ever needs a network round trip.

How to verify your files never left your device

You do not have to take our word for it. Here is how to confirm no upload occurs:

  1. Open your browser's DevTools — press F12 in Chrome, Edge, or Firefox, or Option + Command + I on Mac Safari.
  2. Switch to the Network tab.
  3. Load the merge tool page and select your files. Do not click merge yet.
  4. In the Network tab, click the filter icon and select Fetch/XHR to show only data requests (filtering out CSS, fonts, and other static assets).
  5. Now click Merge & download.
  6. Watch the network panel. No new requests appear during or after the merge — because none are made.

If you see a POST request or an upload to an external URL, stop and leave the site — that tool is uploading your files regardless of what it claims. With keptlocal, the network panel stays quiet.

When browser-based merging is not the right tool

Browser-based PDF merging handles the vast majority of real-world use cases. There are scenarios where server-side processing is genuinely the right tool:

  • Very large files (multiple gigabytes): your device's RAM is the ceiling. Merging ten 200 MB engineering drawings may exhaust browser memory on a device with 8 GB RAM. Server-side tools allocate as much storage as needed.
  • Batch automation: merging hundreds of PDFs programmatically as part of a pipeline requires an API or a scripting environment, not a browser UI.
  • PDF/A compliance and archival formats: specialist PDF standards (PDF/A for legal archiving, PDF/X for print) require validation and conversion that goes beyond what pdf-lib currently supports.
  • True PDF compression: our own Compress PDF tool now recompresses embedded images too, but see our guide to PDF compression for when even that isn't enough.

If your use case falls into one of those categories, a server-side tool is the right choice — but go in with clear eyes about what that means for your file's privacy.

Which documents most need local-only processing

Not every merge warrants concern. A PDF of publicly available product specs merged with a price list is not sensitive. But legal documents — contracts, NDAs, court filings, wills — contain personal information and may be subject to attorney-client privilege. Medical records carry HIPAA and GDPR implications. Financial documents give away more than you might expect: the file name "Q3_payroll_2026.pdf" alone tells a third-party server something about your organisation before they even open it. HR documents, client materials, anything under an NDA — each carries some form of confidentiality expectation.

The test is simple: would you hand a physical copy of this document to a stranger and ask them to merge it for you, then hand it back? If not, do not upload it to a server you do not control.

Browser support and working offline

Browser-based PDF merging works in any modern browser: Chrome 90+, Firefox 90+, Safari 15+, Edge 90+. It works on Windows, macOS, Linux, Android, and iOS. No plugin or extension is required. No account or signup is needed.

Once you've opened the merge tool page while online, it keeps working without a connection — not just for the rest of that browser session, but the next time you open it too, even after closing the tab or losing signal entirely. You can verify this yourself: open the page, disconnect from the internet or turn on airplane mode, then merge files. The merge completes normally.

Frequently asked questions

Is it safe to merge PDFs in a browser?

Yes — more so than uploading to a server. The risk of using any browser tool is the same as the risk of running software locally: you are trusting the code that runs. With an open-source library like pdf-lib, the code is publicly auditable. With a closed server-side service, you are trusting not just the code but the company's infrastructure, employees, and future ownership.

Does browser-based merging preserve bookmarks, annotations, and form fields?

pdf-lib copies the page content from each source document. Bookmarks (document outline) from source PDFs are not currently combined into a single merged outline — that is a limitation of how pdf-lib handles document-level metadata. Page-level annotations, form fields, and embedded fonts are preserved.

Can I merge PDFs on my phone?

Yes. The merge tool works on iOS Safari 15+ and Android Chrome. The drag-to-reorder interface uses touch events. For very large files, a phone with limited RAM may run out of memory — for those cases, a desktop browser is more reliable.

Is there a file size limit?

There is no enforced limit. The practical ceiling is your device's available RAM. Most PDFs in everyday use are well under 100 MB, which is trivial for any modern device.

What happens if I close the tab while merging?

The merge operation stops and any partial output is discarded. The source PDFs remain on your device — nothing has been transmitted. Simply reopen the tool and start again.

Ready to merge? Try the keptlocal Merge PDF tool — no upload, no account, no limit.

Free browser tool
Merge PDF

Combine multiple PDFs into one — entirely in your browser.

No upload. No signup. Runs in your browser.

Use Merge PDF