NEWS
Verax AI Risk Assessment is live. See what's exposed
ChatPDF
ChatPDF
 
Risk Overview
Moderate Risk
4
/10
Document Analysis
·
Conversational AI
·
Knowledge Assistant
·
Top Risks

Policy documents hosted on Notion (not on chatpdf.com) — unusual and hard to monitor for changes; no independent security certifications for ChatPDF GmbH itself; uploaded PDFs processed by OpenAI API in the US; no stated retention period for PDF vector embeddings stored server-side.

Mitigations

Prefer signed-in sessions for access to delete functionality; delete PDF files after each session; avoid uploading confidential pre-publication manuscripts; German/EU jurisdiction is protective for legal risk. For institutional use, seek enterprise agreement with documented data handling commitments.

Get started
Is your team using 
ChatPDF
 
safely?

Highest Risk Categories

The highest-scoring risk categories identified in this assessment.

Training Use

Privacy policy hosted on Notion — full text not directly accessible for review. Company states users have 'full control over data including option to delete files and chats at any time.' No explicit 'we never train on your PDFs' statement found publicly. ChatPDF uses OpenAI API — OpenAI API terms (post-March 2023) do not train on API content by default. Moderate risk due to policy inaccessibility and reliance on OpenAI's defaults.
5
/10

Data Retention

ChatPDF allows users to delete files and chats. No fixed retention period published in accessible policy. No-signup usage available (PDFs processed ephemerally for anonymous users). Signed-in users retain chat history. No stated post-deletion server-side retention period for uploaded PDF text/vector embeddings.
5
/10

Security Posture

Nudge Security profile lists SOC 2, GDPR, ISO 27001, HIPAA, PCI, FedRAMP compliance badges — these reflect underlying providers Vercel and OpenAI, not ChatPDF GmbH itself. ChatPDF has no independent security page, bug bounty, or security portal. Small 4-person German company. Underlying infrastructure is strong; application-layer security posture is undocumented.
5
/10

Unlock the complete assessment

Run a free assessment to access the full AI tool risk analysis.
Start Free Assessment
Updated July 2026 • AI-assisted research • Reviewed by Verax • Report an issue

Reference Documentation

Official documentation and policies referenced as part of this assessment.