What this does not do, stated plainly
It is not redaction. The cover is a rectangle drawn on top and the new text is drawn on top of that. The original characters are still in the file's text layer underneath, and anyone who selects the text, copies it, or opens the file in a tool that reads the content stream can recover them. If your reason for changing the words is that the old words must not be readable, this is the wrong tool and so is every "black box over it" method — the only safe approach is to remove the content, not to hide it.
Nothing reflows. Replacing "12" with "12,480" makes the run longer, and it will run past where the original ended rather than pushing the rest of the line along. For short corrections — a date, a number, a name, a title — this is invisible. For a sentence that grows by half a line, it is not. Where the change is big enough to need the paragraph to re-wrap, converting to Word and editing there really is the right route, and PDF to Word has a layout mode built for exactly that handover.
The font may be substituted. A PDF often embeds only the glyphs it actually uses — a subset. If the original file embedded no "@" because the document never contained one, typing an email address means that character does not exist in the embedded font and has to come from a standard one. The editor matches the closest standard face by metrics, which is usually indistinguishable at body size and occasionally is not.
When the scan is a picture of text
If clicking a word does nothing, the page probably has no text layer at all. Scans and photographs of documents are images: to a PDF reader the page is one big picture, and there is no run of glyphs to click because there are no glyphs. You can tell in two seconds — try to select the text with your cursor in any PDF reader. If nothing highlights, it is an image.
Making that editable needs optical character recognition, which is a different job and one this site does not do yet. What you can do to a scan is annotate it: Annotate PDF draws on top of the page, which is the correct way to add a correction, a note or an initial to a document that has no text to edit.
Why none of this uploads your file
The whole operation runs in the browser tab. The File API reads the bytes, a PDF library parses them in memory, the pages are rendered to a canvas, and the edited document is written back out as a download that was assembled on your own machine. There is no upload step and no server copy, which matters more here than almost anywhere else on the site: the documents people need to correct are contracts, invoices, offer letters and forms with account numbers on them.
You do not have to take that on trust. Open your browser's developer tools, switch to the Network tab, and edit a PDF. Nothing carrying the file appears.