How Itqan handles your files — security & privacy | Itqan

Direct Q&A on encryption, short retention, ads and Consent Mode.

When you upload a contract, invoice scan, or HR file to a browser tool, the first question is usually not “which button do I click?” — it is “what happens to my file?” This guide answers that question for Itqan Tools in a direct Q&A format: transport encryption, temporary processing, deletion, AI-assisted tools, Google Drive and Dropbox imports, and the important difference between cookies (browser preferences) and document files (your PDFs). It also points you to the right protective tools when the risk is inside the PDF itself, not only on the wire.

Use this article together with the official pages: the Security & protection overview, the Privacy Policy, the Cookie Policy, and the Editorial policy. Legal texts win if anything here is summarized for readability.

Q: How does Itqan protect a file while it travels to the server?

Connections to Itqan use HTTPS, which means modern TLS encrypts data in transit between your browser and our servers. That protects uploads and downloads against casual interception on public Wi‑Fi, hotel networks, or shared office links. TLS is the same foundational layer used by banks and government portals for web traffic; without it, a PDF would travel as readable bytes on the path.

TLS does not replace document-level protection. If you email the finished PDF later over an unprotected channel, or leave it unlocked on a shared laptop, transport encryption on Itqan does not follow that copy. For documents that must stay closed to unintended readers, combine the secure session with tools such as password-protect PDF after you finish editing.

Practical habit: prefer HTTPS bookmarks (the lock icon in the address bar), avoid posting tool URLs inside untrusted SMS shorteners, and close the tab when you are done on a shared computer so the download tray is not left open for the next user.

Q: Are uploaded PDFs kept forever as a personal cloud drive?

No. Itqan file tools are built around temporary processing, not long-term document hosting. You upload, the job runs, you download the result, and retention follows the published deletion approach described on the security and privacy pages — the platform is not a substitute for Google Drive, Dropbox, OneDrive, or an internal DMS.

That design has a clear trade-off: it reduces the chance that yesterday’s sensitive attachment sits indefinitely in an account folder you forgot about. The flip side is that you must save the output yourself. If you need a permanent archive, download to your controlled storage, then apply your organisation’s retention rules (years for contracts, months for drafts, and so on).

Do not treat the result page as backup. After you leave, assume the working copies follow temporary handling and secure deletion practices — not recoverable “trash” in a consumer cloud sense.

Q: What does “secure deletion” mean in plain language?

After processing windows expire, temporary files are removed using recognised wiping approaches so ordinary recovery tools cannot casually resurrect them from disk. Exact technical steps evolve with infrastructure, which is why the security page describes the principle (secure deletion / wipe) rather than a marketing countdown timer you should treat as a legal SLA.

Your responsibilities still matter:

  • Download only to devices you control.
  • Clear browser downloads on shared PCs.
  • If a file contained secrets, also remove local copies you no longer need.
  • For irreversible removal of visible secrets inside a PDF before sharing a redacted version, use PDF redaction — password protection alone does not erase text that authorized recipients can still see.

Q: How are AI tools different from ordinary PDF compress or merge?

Some Itqan features — PDF summarize and translate, OCR, headline or logo helpers, math explanations, background removal, and similar — may send only the content required for that request to Itqan servers and, when configured, to model providers (for example a hosted inference API or a local model instance). Payloads are temporary; uploads are not used to train advertising models. Always review AI outputs before you rely on them for legal, medical, or financial decisions.

Ordinary tools such as merge, split, compress, or watermark still process files on the platform, but they do not “interpret” meaning the way a language model does. If your organisation forbids sending certain classes of documents to any external AI, skip AI-assisted tools for those files and stick to deterministic PDF utilities — or process offline under your IT policy.

For a scenario-focused discussion of summarization versus translation limits, see the topic guide network and the individual tool how-tos after you read this privacy overview.

Q: What happens when I import from Google Drive or Dropbox?

Many PDF tools let you pick a file from Google Drive or Dropbox instead of local disk. That flow uses the cloud provider’s authorized picker: you grant access for the selected file (or session scope the provider shows), Itqan receives the bytes needed for the job, and processing continues like a normal upload. Saving results back to Drive or Dropbox (when the result page offers it) writes to your cloud account under your credentials — Itqan does not become the long-term owner of that library.

Tips for safer cloud import:

  • Import only the single file you need, not an entire folder of unrelated HR records.
  • Revoke app access from Google or Dropbox account settings if you no longer use the integration.
  • Remember that cloud provider policies still apply to files resting in Drive/Dropbox before and after the job.
  • If a shared Drive link is confidential, prefer downloading locally on a secured device, then uploading, rather than operating from a public kiosk.

Q: Cookies versus files — are they the same privacy topic?

They are related but not identical. Cookies and similar storage help the site remember language, session, and (with consent) advertising or analytics preferences. You control non-essential cookies through the consent bar and Consent Mode settings described in the Cookie Policy. Changing cookie preferences does not delete a PDF you uploaded five minutes ago; those are separate processing objects.

Files are the documents you submit to tools. Their lifecycle is temporary processing and deletion, covered primarily by the Privacy Policy and Security pages. Ads that may appear on free tool pages are governed by consent; they should not be confused with “the ad network reads my contract PDF.” Keep the mental model: cookies = browsing preferences; uploads = job payloads.

Q: What should teams do before uploading highly sensitive PDFs?

Use a short pre-flight checklist:

  1. Classify the document. Public brochure, internal draft, personal data, or regulated record?
  2. Minimize. Split away pages you do not need with organize/split tools, or redact identifiers first.
  3. Prefer redaction over black rectangles in a screenshot. True redaction removes underlying text; a drawn box in an image editor may leave selectable text underneath.
  4. Protect the output. After processing, apply PDF password protection when the recipient set is limited.
  5. Verify the download location. Corporate laptop Downloads folder versus a USB stick left at a café.
  6. Log the business reason if your ISO or internal policy requires it — Itqan is a processing utility, not your compliance register.

GCC admin, legal, and finance teams often combine this guide with the comparison article on redaction versus watermark versus password so the content controls match the platform controls.

Q: Does Itqan sell my documents or train ads on them?

Published privacy commitments state that personal data is collected as needed to deliver the service, is not sold for marketing, and that AI uploads are not used to train advertising models. Cookie-based advertising (when you allow it) is about site measurement and ads — not about reading the bytes of your merged PDF as a marketing profile. For rights to access, correct, or request deletion of personal data where applicable, follow the Privacy Policy process rather than inventing an informal email thread without reference numbers.

Q: How do editorial standards relate to security content?

Security and privacy pages are legal/product statements. Blog topic guides like this one are explanatory. The Editorial policy describes how Itqan aims for original, useful articles instead of thin doorway pages. When we link tools from an article, the goal is to help you finish a real workflow — compress, redact, protect, OCR — not to invent fake urgency. If a how-to steps page and this Q&A ever seem to differ on a product detail, trust the live tool UI and the legal pages, then tell support so we can correct the guide.

Q: Which tools help after the privacy basics are clear?

Once you understand transit encryption and temporary retention, day-to-day risk often moves inside the document:

  • Redact PDF — permanently obscure national IDs, salaries, or medical lines before external sharing.
  • Protect PDF — require a password to open or to restrict printing/editing where the tool supports those flags.
  • PDF tools hub — find merge, compress, OCR, and conversion in one place for business workflows.
  • How to password-protect a PDF — step detail for the protect tool.
  • How to redact a PDF — step detail for irreversible content removal.

Q: What mistakes create false confidence?

  • Assuming TLS equals end-to-end secrecy forever. It protects the pipe during the session; the downloaded file on disk is your job to store wisely.
  • Blacking out text in a Word export without redaction. Recipients may still copy underlying content.
  • Sharing the password in the same email as the PDF. Use a second channel.
  • Uploading an entire HR zip “just in case.” Minimize first.
  • Ignoring AI review. Models can misread numbers; humans remain accountable.
  • Confusing cookie rejection with file non-upload. Declining ads cookies does not block a PDF tool you actively use — and accepting cookies does not mean your PDF becomes an ad targeting document.

Q: Where should I go next?

Read the Security & protection page for infrastructure and encryption features, keep the Privacy Policy and Cookie Policy bookmarked for rights and consent, and skim the Editorial policy if you care how guides like this are maintained. When you are ready to harden a specific file, open Protect PDF or Redact PDF from the PDF hub and finish the job while the session is still open on a device you trust.

Back to blog