There are two different things people mean by protecting a PDF, and conflating them is how documents leak.
The first is controlling who can open the file at all. That is a password, and it works — the contents are encrypted, and without the password there is nothing readable to find. This tool does that, and it also does the reverse: if you know the password on a document, you can take the protection off.
The second is stopping a particular person from seeing a particular thing inside a document that they are allowed to open. A password does nothing for that. Once the file is open, everything in it is available — every name, every figure, every comment left in the margin. If a name has to be gone, it has to actually be deleted from the file, which is a different tool and one we keep deliberately separate.
The warning that matters most here is about loss. A PDF password has no recovery mechanism: it is not an account you can reset, there is no email link, and we have no copy because encryption happens in your own browser. A document whose password is forgotten is a document nobody opens again. The tool says that before you set one and asks you to confirm, because the moment to hear it is not afterwards.
One more distinction worth being straight about. A PDF can also carry flags asking readers not to print or copy the file. We can set those, and most software honours them — but they are a request, not a lock, and software that ignores them is not doing anything clever. We will describe them as what they are rather than selling them as security.
Everything happens in this browser, including the encryption, so the password itself never travels. There is no signup, no limit, and no watermark.