Free Online Tools and Client Data: A Safety Checklist for PDFs, QR Codes, Images and Invoices (2026)
Every small business compresses PDFs, prints QR codes, resizes photos and sends invoices with free online tools. Each one is a data-handling decision. Here are the four risks hiding in free, a checklist per tool, and how Jobbit's free tools handle your files.

Every small business runs on free online tools. A contract gets compressed before it goes to a client. A menu gets a QR code. A product photo gets resized for a listing. An invoice gets made from a template. None of these feel like security decisions, and all of them are: each one moves client data through a service you have not read the terms of, in a format you may not fully control.
This is the checklist we give clients when we review how a business handles its everyday documents. It is short, it is practical, and it ends with how the free tools on jobbit.uk handle the same jobs, because Jobbit Security is part of the company that built them and we would rather explain the trade-offs than pretend there are none.
The four risks hiding in "free"
Uploads leave your machine. The moment you drop a PDF on a compressor's website, the file is on someone else's server. Some tools delete it within the hour. Some keep it to train models or to serve advertising. Many say nothing at all. A tool that is free and has no visible business model is being paid for somehow, and the file is often the currency.
QR codes can point anywhere. A printed code is a link you cannot read. Dynamic codes, the kind most free generators default to, route through the provider's server first, which means the destination can change or expire without the code changing. Attackers exploit the same blindness by sticking their own codes over legitimate ones on parking meters, menus and posters, a technique called quishing.
Images carry more than pixels. A photo from a phone usually contains EXIF metadata: the time, the device, and often the GPS coordinates of where it was taken. Resize a photo of your home office for a listing and a careless tool will publish your home address in the file.
Invoices are an attack surface. Invoice fraud, often called mandate fraud, is one of the most common ways UK businesses lose money: a criminal impersonates a supplier and asks for the bank details on file to be changed. Editable invoice files, inconsistent numbering and templates reused across clients all make the impersonation easier and harder to spot.
Checklist: compressing and sharing PDFs
- Read the retention line before you upload. If you cannot find it in thirty seconds, assume the file is kept.
- Sort documents into three bins: public, internal, and regulated or privileged. Only the first bin goes to an anonymous free tool.
- Prefer tools that work inside an account you control, so there is a record of what was uploaded and by whom.
- Check the output. Aggressive compression can turn a signature or a small-print clause into an unreadable smudge, which is its own problem when the document is a contract.
- Compress once, at the end. Repeated compression compounds the damage.
The jobbit.uk guide to compressing a PDF for free with no upload limit covers the size-versus-legibility trade-off in detail.
Checklist: QR codes on anything you print
- Use static codes for print. A static code encodes the final address, so nothing can be changed after the poster goes up and nothing expires when a subscription lapses.
- Point codes at a domain you own, never at a shortener you do not control.
- Keep a register of every code you have printed, where it is, and what it points to.
- Scan your own codes in the wild every few months. If the destination is not yours, someone has covered it.
- Tell staff that a code on a poster, a parking meter or an email attachment is a link from a stranger, and to treat it that way.
The free QR code guide on jobbit.uk explains why most free codes stop working and how to make one that does not.
Checklist: resizing and publishing images
- Strip metadata on export. Check the output file's properties before it goes on a listing, a job advert or social media.
- Be deliberate about what is in the frame: screens, whiteboards, paperwork and door numbers all leak.
- Keep originals in a controlled folder, and publish only the resized copies.
- For staff photos, get consent for the specific use, not a blanket one.
Formats and platform sizes are covered in the image resizing guide.
Checklist: invoices that cannot be tampered with
- Send PDFs, not editable documents, and never a template with other clients' details left in.
- Number invoices sequentially and state your bank details the same way every time, so a change stands out.
- Put a line on every invoice saying that you will never change bank details by email, and ask customers to phone a known number if they receive such a request.
- Do the same in reverse: verify any supplier's change of details by calling a number you already hold, not one in the message.
- State payment terms and statutory late-payment interest clearly. An invoice that reads like it was produced by a process is harder to impersonate than one that reads like a favour.
The invoice guide on jobbit.uk lists the nine fields a UK invoice needs and the late-payment terms that get it paid.
How Jobbit's free tools handle the same jobs
Jobbit's four tools, a QR code generator, a PDF compressor, an image resizer and an invoice generator, are forms that send a single message to the Jobbit agent, which does the job inside your own workspace and hands the file back. The overview post, four free online tools on jobbit.uk, links all of them.
Against the checklist above, this is what you get and what you should still do:
- Account, not anonymity. The tools run on the free plan with no card, but inside an account, so there is a record of what was done. Jobbit's stated principle is that your files, code and exports are yours to take with you.
- Consent for training. Records of how tasks are done are used to improve the agent only with consent and clean provenance. Nothing is scraped. Read the terms before you rely on that for regulated material, as you would with any provider.
- Static QR codes. The QR tool makes static codes that encode the final address and never expire, in PNG and SVG, which is the right default for print.
- Sensible defaults for the rest. PDFs to a target size with legible text, images to exact platform dimensions, invoices with the nine UK fields and payment terms. Check the output as you would from any tool.
We say all of this as the team that tests Jobbit's own systems. The company's principle is "test yourself first", and the reasons it runs an in-house red team are set out in our post on what Jobbit is, from a security lead's point of view.
When a free tool is the wrong answer
Some material should never go through a shared online service of any kind: health records, legally privileged documents, payroll files, anything covered by a client's own security schedule. For those, use tooling that runs on your own machines or under a contract that names retention, location and deletion. And if a business is handling client files at volume, the question is no longer which free tool to use but whether the process around them has ever been tested.
That is what we do. If you would like a second pair of eyes on how your business handles documents, uploads and payments, book a scoping call. No obligation, and a consultant replies within one working day.
Frequently asked questions
Is it safe to upload a contract to a free PDF compressor?
Only if you know where the file goes and how long it is kept, and the document is not one you would mind a stranger reading. For anything under NDA, legally privileged or containing personal data, use a tool that states its retention clearly, keeps the file in an account you control, or runs on your own machine.
Are QR codes a security risk?
The code itself is just a link. The risk is where it points. Dynamic codes route through a third party that can change or expire the destination, and attackers replace printed codes with their own, a technique known as quishing. Print static codes that encode the final address and check them in the wild.
Does resizing a photo remove location data?
Not necessarily. Photos from phones carry EXIF metadata, often including GPS coordinates and the device model. Many resizers copy it across. Check the output, or use a tool that strips metadata on export.
How do I stop invoice fraud?
Send invoices as PDFs rather than editable files, keep numbering sequential, and never accept a change of bank details by email alone. Confirm changes by calling a number you already hold, not one in the message. Your customers should do the same with your invoices.
Are Jobbit's free tools safe to use with client files?
They run inside your own Jobbit workspace on the free plan, with no card and no watermark, and Jobbit's principle is that your files are yours. Task records are used to improve the agent only with consent. As with any tool, keep regulated or privileged material out of shared services unless you have checked the terms.
