Skip to content

How it stays private

The file has nowhere to go.

Saying a file is “processed locally” costs nothing. This page shows the mechanism behind it, the checks you can run yourself, and exactly where the claim stops.

Other servers this page has contacted since it loaded
0

A live PerformanceObserver raises this number if the page loads anything from another origin.

The rule the browser enforces
Content-Security-Policy: … connect-src 'none'

This directive is in the HTTP Content-Security-Policy header on every page. It tells the browser to refuse fetch, XHR, WebSocket and beacon connections from the tool.

What happens when you choose a file

  1. The browser gives this tab a temporary reference to the file you selected. Choosing it does not upload it.
  2. Image pixels are decoded with browser APIs. PDF objects are read by a library served from this same domain.
  3. The result is built in memory and exposed through a local blob: URL. That URL exists only in this browser session.
  4. Download writes the new bytes back to your device. Reloading the page discards the working memory.

Three ways to verify it yourself

CheckWhat to doWhat you should see
Network panelOpen browser developer tools, choose Network, then process a file.No request carrying the file, filename or output.
Offline testOpen a tool once, disconnect from the internet, then use it.The visited tool still runs from its service-worker cache.
Security headerInspect the document response in browser developer tools.connect-src 'none', blocking fetch, XHR, WebSocket and beacon connections.

The boundary, stated precisely

The site itself still has to reach your browser, so Cloudflare serves the HTML, scripts, styles and fonts and may keep ordinary security logs such as an IP address and timestamp. Your selected file, its name, its pixels and the result are not sent with those requests.

One exemption is worth naming. The offline cache is kept by a service worker, and a worker runs under the policy served with its own script, so /sw.js is served without the document's connect-src and can ask this domain for the pages and assets it stores for offline use. It never touches the file you chose. That one is read from your disk by the page and never becomes a request at all.

No advertising network is active on this deployment. Nothing on a tool page contacts another company automatically.

Third-party code, served locally

The PDF engine uses pdf-lib, and the two PDF-to-image converters draw pages with pdf.js, whose Apache 2.0 licence is published with the site. The HEIC converter uses the LGPL-3.0-licensed heic-to decoder, whose LGPL-3.0 licence is published with the site. These scripts are copied into the build and served from NoUpload; opening a tool never asks a package CDN or its author for code.