🛡️

Privacy by Design: How This Site Handles (Read: Never Touches) Your Files

A concrete look at the architecture, what runs where, and how you can independently verify that nothing is uploaded.

How-to for offline tools. Every step happens on your device.

The one-sentence architecture

This website is a set of static files — HTML, CSS and JavaScript — served to your browser. There is no backend application, no database, and no upload endpoint. All processing is performed by your browser's own JavaScript engine and WebAssembly codecs.

What happens when you use a tool

StepWhere it runsNetwork activity
Loading the pageBrowser fetches HTML/JS/CSSStatic files only (cacheable)
Selecting a fileFile API reads from your disk into memoryNone
Processing (convert/compress/crop)Canvas + WebAssembly in your tabNone
Saving the resultDownload manager writes to your diskNone

Why "we don't store your files" isn't good enough

Many cloud converters say files are "deleted after one hour" or "never stored". Even when true, this framing skips the real issues:

  • The file transits their infrastructure, where it can be logged, scanned or mishandled in transit.
  • Metadata retention, abuse monitoring and legal interception rules apply to what they process, not what they "store".
  • You are trusting a policy, enforced by people you've never met, forever.

Local processing removes the question entirely. The strongest deletion policy is a server that never received the bytes.

Verify it yourself in 60 seconds

Test 1: The Network tab

Open your browser's Developer Tools (F12), switch to the Network tab, then use any tool here — for example the EXIF Viewer on a photo. You'll see the initial static resources load, then complete silence while your file is analyzed.

Test 2: Airplane mode

Load any tool page, then turn off Wi-Fi / unplug ethernet. Drop files in and process them. Everything works, because nothing was ever going to be sent anywhere.

Test 3: View source

This entire site is static. Search the page source for fetch, XMLHttpRequest or upload — you'll find image- and module-loading code only, no data exfiltration paths.

What about analytics and cookies?

This site sets no cookies, runs no third-party trackers, and loads no external fonts or scripts. All libraries (JSZip, gifenc, libwebp and friends) are bundled locally under assets/vendor/, so even library code is fetched from this domain only, and cached for offline reuse.

A note on memory

Processing happens in your tab's memory. Close the tab and it's gone: the JavaScript heap, the image bitmaps, the results — all discarded. There is no service worker that persists files, no IndexedDB storage of your images, no local cache of anything you processed.

Recommended workflow for sensitive material: open a private/incognito window, use the tools, download results, close the window. Not because the site requires it — just because it's a good habit that protects you everywhere else too.