The browser requests the site interface and processing code from Cloudflare.
The website arrives. Your image does not leave.
Local processing means the application code is delivered to your browser, then the browser performs the image work on the device. This page separates that technical promise from vague claims like “secure” or “100% private.”
File access, previewing, decoding, Canvas work, and supported worker tasks stay inside the tab.
The browser creates a temporary result URL and downloads the file only when you ask.
What goes where
“Local” applies to selected files and processing. Ordinary website requests still reach the hosting network so the page can load.
What the current product deliberately omits
- No server image-upload endpoint
- No account, database, or cloud image library
- No session replay or behavioural advertising scripts
- No filename or image-content analytics
- No remote AI image-processing API
- No permanent processing history
Hosting can still see a page request
Cloudflare may process the IP address, requested URL, time, browser information, and security signals needed to deliver and protect the website. Those ordinary requests do not include the selected image, filename, preview, or result.
Browser limits still apply
Large images use device memory, supported codecs vary, and closing a tab during processing ends the job. Local processing reduces data exposure; it does not make every device equally capable.
Future network features need a new label
If an API, cloud sync, or server-based AI feature is added later, the interface and policy must identify the transmission before a file is sent. It cannot be silently covered by the local-tools promise.