Most online image tools work the same way: you choose a file, your browser sends it to a server, the server processes it and sends a result back. That is a normal, workable design, and it also means a copy of your image existed on someone else's computer.
Why that matters more than it sounds
For a holiday snapshot, probably not much. For other things it does. A scanned passport, a signed contract, a medical image, an unreleased product photo, a client's confidential design, a screenshot with customer data in it. Once the file is on a server you do not control, you are relying entirely on that operator's retention policy, their access controls and their security.
You usually cannot verify any of those, and "we delete files after an hour" is a promise, not a mechanism.
How in-browser processing differs
Modern browsers can do the work themselves. WebAssembly lets image codecs, the same C libraries that power desktop software, run inside the page at close to native speed. The file is read from your disk into the tab's memory, processed there, and written back out as a download.
The difference is structural rather than a policy: there is no upload step, so there is no copy to retain, leak or subpoena. It also means the tools keep working with the network disconnected, which is a decent proof in itself.
Verify it yourself in thirty seconds
You do not have to believe the claim. Two checks, both easy:
- Go offline. Load the page, disconnect from the network, then process an image. If it still works, the file went nowhere.
- Watch the network tab. Open your browser's developer tools, switch to Network, and process a file. A server-side tool shows a large upload request. A local one shows nothing of the kind.
Run those checks on any tool that makes this claim, including this one.
The honest limitations
In-browser processing is not magic and it has real trade-offs. Very large files can hit memory limits in a tab. Some operations are slower than a server with more cores would be. Formats needing patent-encumbered decoders are harder to support. And a page can still load third-party scripts, so "your image stays local" is not the same claim as "this site collects nothing at all".
The related habit
Keeping the file local protects the file. It does not remove what is inside it: EXIF metadata with GPS coordinates travels wherever the photo goes afterwards. Strip it before sharing with remove EXIF data, and read the EXIF guide for what it exposes. For faces in a photo you are about to publish, blur faces runs locally too.