PDFind

Security

Effective date: 22 September 2026

PDFind is designed so PDF content stays in the customer's Microsoft 365 environment and in the Office task pane.

Storage and isolation

Attached PDFs are stored in the signed-in customer's OneDrive or an administrator-approved SharePoint drive. The default Files.ReadWrite.AppFolder permission limits PDFind to its own application folder. Each workbook uses a separate workbooks/<workbook-id>/documents folder and the document picker lists only files attached to the current workbook.

Local document processing

PDF rendering, embedded-text extraction and English/Polish OCR run in the Office task pane. PDF pages, recognized text, Excel cell values, file names and search queries are not sent to PDFind's entitlement or telemetry API and are not sent to an external OCR provider.

Permissions

Account and telemetry records

The entitlement service stores Microsoft tenant and user object IDs, subscription state, non-reversible PDF fingerprints, usage counters and workbook identifiers. Privacy-safe telemetry is aggregated by day and accepts only predefined feature names, Office platform, PDFind version, OCR duration and support error code. It does not store the authenticated user ID in telemetry rows.

Failure behaviour

The public add-in fails closed if Microsoft sign-in or entitlement verification is unavailable. If Microsoft storage becomes unavailable, PDFind labels the document as session-only rather than claiming it was saved.

Report a concern

Email eugene@pdfind.io with the subject “Security — PDFind”. Do not send confidential PDFs, access tokens or passwords.