Verify it yourself
You do not need to trust us. Your browser can show every request a page makes. Here is how to check that your file stays on your device.
What you will check
On-device tools run in an isolated frame whose security policy makes your browser block the ways the tool’s code could send data: fetch, XHR, WebSocket, beacons, and loading anything from other sites. If that is true, processing a file produces no request that carries the file: at most, the tool loads its own program files once.
A security policy cannot stop a frame from navigating itself to another address, so the list below also checks that no new page is loaded while the tool works.
Step by step
- Open a tool that runs on your device, for example one marked On your device · no upload.
- Open the developer tools.
- Chrome and Edge: press F12, or Ctrl+Shift+I (⌘⌥I on a Mac), then open the Network tab.
- Firefox: press Ctrl+Shift+E (⌘⌥E on a Mac).
- Safari: first turn on Settings → Advanced → Show features for web developers, then choose Develop → Show Web Inspector and open Network.
- Prepare the list. Turn on Preserve log (Chrome, Edge) or Persist logs (Firefox), then clear the list.
- Process a file. Choose a file and run the tool until you see the result.
- Read the list.
- Filter by Fetch/XHR (or XHR): check for requests carrying file contents. If you enabled optional usage analytics, the page can send short
POSTrequests to/api/v1/eventswith page keys and tool steps, excluding file contents. These requests come from the page, not the tool frame. - Filter by Doc (HTML in Firefox, Document in Safari): no new entry appears while the tool works. A frame that navigated itself elsewhere would appear here.
- The remaining entries, if any, are the tool’s own program files (scripts) loaded from its own address. Their Size column shows no upload, and none of them has your file as its request body.
- Filter by Fetch/XHR (or XHR): check for requests carrying file contents. If you enabled optional usage analytics, the page can send short
- Optional: look at the policy. Click the tool frame’s document in the list and open its response headers. The
Content-Security-Policyheader containsconnect-src 'none': the rule your browser enforces. - Optional: go offline. After the tool has loaded, switch the Network panel to Offline and process another file. It still works, because nothing needs the network.
Cloud tools look different, on purpose
Tools that run on our server say so before you choose a file. After you press the button that starts the upload, you will see a PUT request to /api/v1/jobs/…/input whose body is your file, followed by short status requests. The request never contains the file name. Before that click, there is no upload request.