Most online image tools work the same way: you upload a file, a server somewhere processes it, and you download the result. That means your picture sat on someone else's computer, and you are trusting a privacy policy about what happened to it there.
This tool does the work in the page itself. The processing code runs inside your browser tab, on your machine, using your CPU. The image is read from your disk into the tab's memory and never sent anywhere.
Why that is worth caring about
Because the images people want cleaned are often not casual. Draft work for a client. Photographs of family. Product shots before launch. Documents with a proof stamp across them. "We delete uploads after 24 hours" is a promise about a copy that already exists on a machine you do not control.
How it is enforced rather than promised
A claim like this is easy to make and hard for a visitor to check, so the site is configured so that the browser blocks the alternative. The page ships a Content Security Policy with connect-src 'self', which tells your browser to refuse any network request from this page to any other server. If the code tried to send your image somewhere, your browser would block the attempt and log it — the site cannot exfiltrate an image even if it wanted to, and you can verify that yourself.
Open your browser's developer tools, go to the Network tab, and process an image. You will see the page load its own code and its detection model. You will not see your picture go out, because it cannot.
The trade-offs, honestly
Local processing is not free of downsides.
- Your hardware sets the speed. A recent laptop handles a photo in a second or two; video takes considerably longer, and an old phone will struggle.
- The first visit downloads the model. A few megabytes, cached afterwards.
- Very large files can exhaust the tab's memory, where a server with lots of RAM would not.
Those are real costs. They buy something we think is worth more: the certainty that a picture you did not want to share was never shared.