How to Check if an Online Image Tool Uploads Your Photos
Updated October 1, 2026
You found a free tool to compress a screenshot or convert a HEIC file. You drag your image in, it works, you download the result. Simple.
But where did your image actually go? For most online image tools, the answer is: to someone else's server. Your file was uploaded, processed remotely, and sent back. That is fine for a holiday snap. It is a different question entirely for a passport scan, a medical photo, a signed contract, or a screenshot with customer data in it.
The good news is that you do not have to trust anyone's marketing copy. You can check in about 30 seconds, and this guide shows you how to do it for any image tool on the web.
Why it matters
Once a file leaves your device, you lose control of it. Even with an honest operator, you are now relying on their retention policy, their access controls, their breach history, and their jurisdiction. Reputable services delete files after an hour or a day. Less reputable ones say nothing at all.
The quiet detail most people miss: images carry metadata. A photo straight from a phone usually embeds the GPS coordinates where it was taken, the exact timestamp, and the device model. Uploading a photo to strip its background may hand over the location of your house along with it.
Method 1: the devtools network check (30 seconds)
This works in Chrome, Edge, Firefox and Safari, and it works on any site.
- Open the image tool's page, but do not add your image yet.
- Press F12 to open developer tools (or right-click the page and choose Inspect).
- Click the Network tab.
- Filter to Fetch/XHR so you only see data requests, not images and stylesheets.
- Click the clear button (a circle with a line through it) to empty the log.
- Now process your image: drag it in, or click to select it.
- Watch the list of requests appear.
What you are looking for is the size column. If a request's body is roughly the same size as your image file, that is your image being uploaded. A 4 MB photo producing a 4 MB request is unambiguous.
A truly client-side tool shows nothing of the sort. You might see a small analytics request of a few hundred bytes, but nothing remotely the size of your file.
Method 2: the offline test (the one that cannot be faked)
This is the stronger test, and it is beautifully simple.
- Load the tool's page normally and wait for it to finish loading.
- In devtools, go to the Network tab and set the throttling dropdown to Offline. (In Firefox the same option is called Work Offline.)
- Now try to process an image.
A tool that runs in your browser keeps working, because everything it needs is already loaded. A tool that uploads to a server breaks immediately, because there is no server to reach.
There is no way to fake passing this test. If the processing genuinely happens on a server, cutting the network stops it. This is the check to use when you want certainty.
What "client-side" actually means
When a tool processes images in your browser, it uses technology built into the browser itself:
- Canvas — the browser's built-in 2D drawing surface, which can resize, crop, rotate and re-encode images.
- WebAssembly — compiled code running at near-native speed in the browser, used for heavier work like advanced compression or machine-learning background removal.
- The File API — reads your chosen file into the page's memory without putting it into a network request.
Your file is read into memory, worked on, and written back out as a download. At no point does it need to be placed in a request body, so at no point does it need to leave the machine.
How ImgToolZone measures up
It would be hypocritical to publish this guide and ask you to take our own claim on faith. So here are our numbers, measured the same way we just described, using a real 12,998-byte PNG through the image compressor while recording every network request:
- Image bytes transmitted: zero. The file never appears in any request.
- Hosts contacted while processing: one — our own domain. No Google, no CDN, no third-party services.
- Requests that send data: one. It is 139 bytes, posted to our analytics endpoint.
That last one deserves an honest explanation rather than a footnote. When you start using a tool, the page sends a small cookieless event so we know which tools get used. The entire payload looks like this:
- event: tool_started · toolId: image-compressor · eventId: a random id
A tool name and a random identifier. No filename, no file size, no dimensions, no image data, and nothing that identifies you. A 12,998-byte image generated 139 bytes of traffic, and none of those bytes were your picture.
We mention it because you will see it when you run the check yourself, and a claim of "zero network requests" would be false. There are also only two server endpoints in the entire application: the analytics one above, and the contact form. There is no upload endpoint, which means there is no upload path to accidentally leak through.
Run both tests on our tools. Then run them on whichever tool you were using before, and compare.
The honest trade-offs
Client-side processing is not free of downsides, and anyone telling you otherwise is selling something:
- Memory is your device's, not a server's. Very large files, or large batches, can hit the limits of a phone or an older laptop.
- Some operations are slower. A server with a dedicated GPU will beat a browser at heavy lifting.
- Machine-learning features need a one-time download. Background removal fetches its model file on first use, which takes a moment on a slow connection.
- Your browser needs to be reasonably current. WebAssembly and modern Canvas features are not in ancient browsers.
For everyday work — compressing, converting, resizing, cropping, stripping metadata — these rarely matter. For a 200 MB TIFF on a budget phone, they might.
A quick checklist
Before you upload a sensitive image anywhere, ask:
- Does the Network tab show a request the size of my file?
- Does the tool still work with the network switched off?
- If it does upload, does the site say how long files are kept, and does that sound credible?
- Does my image contain GPS data, and have I stripped it first?
Summary
You never have to guess. Open devtools, watch the Network tab, and process an image: a request the size of your file means it was uploaded. For certainty, go offline and try again — client-side tools keep working, server-side tools stop.
Our tools pass both checks, and you can confirm it yourself in half a minute. Start with the image compressor, or strip metadata from a photo before you share it anywhere.