How PDF download protection works
This article explains what CustomGPT.ai's PDF download protections actually prevent, and what they don't - so you can set accurate expectations when configuring them or describing them to your own users.
Why downloads can't be fully prevented
Any content rendered in a browser has to reach the user's device first - that's simply how browsers display anything, PDFs included. Once the file has arrived, there's no way to take it back: a user with basic technical know-how can always find a way to save a local copy, no matter what obstacles are placed in front of them.
This isn't specific to CustomGPT.ai. It's the same reason you can still download a YouTube video or save an Instagram photo, even though both platforms invest heavily in making that difficult. Preventing access to arrived content altogether isn't possible - raising the effort required to get it is.
What Prevent PDF Download actually does
With Prevent PDF Download turned on, CustomGPT.ai removes the visible download control from the PDF viewer and obscures the file's name and where it's served from.
The user can read the entire PDF inside the chat, but they won't find a download button, and can't grab the file from an obvious, guessable link.
This doesn't change the underlying fact above - it just removes the easy paths to a copy. Someone who specifically sets out to bypass it still can (more on that below); the setting is aimed at the vast majority of users who won't.
Limit page visibility raises the bar further
Limit page visibility adds a layer on top of Prevent PDF Download.
The user will only see the page used to generate the response, together with one page before and one page after it. Everything outside that range is replaced with a blank, labeled placeholder rather than the real page content.
The two settings are independent and can be turned on together or separately, under Personalize > Citations. For the full mechanics of how page limiting works, see How PDF Citations work.
Important: These protections are designed to stop casual downloading, not a determined technical user. Anyone familiar with browser developer tools can work around them. In practice, this stops the vast majority of users - but it is not a guarantee against someone who specifically sets out to bypass it.
Related articles
Updated about 9 hours ago
