PRACTICAL GUIDE

Browser-Based Tools and Privacy: What Local Processing Means

What it means for a website to process a file without uploading it, how to check the claim yourself, and where the claim genuinely stops applying.

Last updated

A website is code that runs on your machine

The distinction that matters is not between a website and an application. It is between a page that sends your file somewhere to be processed and a page that downloads the processing code to you and runs it in your browser.

In the second model the server hands over a program and then plays no further part. The image is decoded, the PDF is rewritten and the hash is computed by your own processor, on data that never leaves the machine. The page can be online while the work is offline.

Why it matters more than it sounds

The files people put through online tools are the sensitive ones: contracts, payslips, passport scans, medical results, photographs of their children. Uploading one creates a copy on hardware you do not control, subject to a retention policy you did not read and a breach you will not hear about. Not uploading it removes that entire class of question rather than answering it well.

How to check the claim rather than trust it

Open your browser's developer tools, go to the Network tab, and use the tool. If the file is being uploaded you will see a request carrying it, with a size that matches. If nothing of the sort appears, nothing of the sort happened.

The stronger version of the test: load the page, disconnect from the network, and use the tool. Anything that still works was never going to send your file anywhere. It is the only verification that does not require taking anyone's word for anything.

Where local processing stops being the whole story

Local processing says nothing about analytics. A page can process your file on your device and still report that a tool was opened, which is normal, or report the filename, which is not. It also says nothing about what you paste: a tool that formats JSON locally is safe, and pasting a production API response into a browser tab on a shared machine is still a decision worth making deliberately.

When to use something else entirely

For material under a legal or contractual duty of care — client files under privilege, regulated health data, anything covered by an agreement that names approved software — the right answer is the approved offline tool, not the best available website. Not because a browser cannot do the work, but because the obligation is usually about provenance and auditability rather than about where the bytes went.

Frequently asked questions

How can I be sure a tool is not uploading my file?

Watch the Network tab in your browser's developer tools while you use it, or go offline and try again. A tool that works with the network disconnected cannot be sending anything. It is worth doing once for any tool you plan to use regularly.

Does this site upload anything I process?

The tools here are built to process files in your browser, and each one says so on its own page. Analytics record that a tool was opened or completed and are not designed to carry the content, the filename or the values you enter.

Is a browser tool as safe as desktop software?

For keeping a file off other people's servers, yes: neither uploads it. Desktop software wins where you need to work with no network at all, where an organisation requires approved tooling, or where you want the exact same version available for years regardless of what a website does next.

What about the passwords and tokens I generate or decode?

Those are produced or read on your device — the password generator uses the browser's own cryptographic random source, and the JWT decoder splits and decodes the token locally. Neither the generated value nor the decoded payload is transmitted, which is the only arrangement under which using a web page for this makes sense.

Explore all security tools →