← All articles

What Actually Happens to Your Files With "Online" Tools

2026-09-10 · 6 min read · Privacy Security

Search for "convert PDF to Word" or "compress image online" and the first page of results will be full of free tools. Almost all of them work the same way under the hood, and almost none of them tell you honestly. This article explains what is really happening to your file, why it matters more than most people think, and how to verify a tool's privacy claim yourself in about two minutes.

The default architecture: upload, process, download

When an online tool says it processes your file "in the cloud", here is what that sentence unpacks to. You click upload. Your browser sends the entire file over the internet to a server somewhere — a physical computer owned by the company, or more often, rented from Amazon or Google. That server runs the conversion or compression, holds your file in its memory and usually on its disk, and then sends the result back to you.

That last part — "holds your file on disk" — is the part the marketing skips. Servers are set up to log, cache, and back up data by default, because that is how you keep a service running when it gets popular. Your file does not simply pass through and vanish; it typically persists for some amount of time, and you have no way of knowing how long.

When this is harmless, and when it is not

For a screenshot of a funny error message, none of this matters. Nobody wants your screenshot. But consider the kinds of files people casually feed to free online tools every day:

These are exactly the files where "uploaded to a server I cannot audit" becomes a real risk. The file could be mined for data, cached in a breachable backup, or simply retained for longer than the company's privacy policy admits. And because you cannot see the server, you cannot verify any claim they make about deletion.

How to spot a client-side tool

The alternative is a tool that processes files entirely in your browser using JavaScript. The code is delivered to you, your file never leaves your device, and the work happens on your own machine. This is not a niche trick — modern browsers can re-encode images, parse PDFs, and run hashing algorithms locally, because the Web platform now ships those capabilities.

The tell-tale signs of a client-side tool:

The two-minute verification, no tools required

You do not have to take any tool's word for it. Every browser ships with a way to see every request a page makes:

  1. Open the tool's page and press F12 (or right-click → Inspect) to open DevTools.
  2. Click the Network tab and tick "Preserve log".
  3. Use the tool — upload your file, run the conversion.
  4. Watch the Network tab. If the tool is client-side, you will see the initial page load and then nothing. No upload request, no tracking pixel, no silent POST to a server.

That silence is the proof. A server-side tool will show a POST or PUT request carrying your file's bytes the moment you click convert. A client-side tool will not, because there is nothing to send.

What this means for how you choose tools

You do not need to abandon every online tool, and you should not be paranoid about a screenshot. The rule of thumb is simple: the more sensitive the file, the more you should prefer client-side processing. For a passport scan or a signed contract, the difference between "uploaded to an unknown server" and "never left my laptop" is not theoretical — it is the difference between a file you control and a file you have permanently handed to someone else.

This is also why a privacy policy that says "we delete your files within 24 hours" is less reassuring than it sounds: you are still trusting the company to do what it claims, with no way to verify it. A tool that never receives your file in the first place does not need a deletion policy, because there is nothing to delete.