Prove it yourself: your files never leave your device

Most “online” converters upload your file to a server, process it there and send it back. ToolsRift works differently — and you can check that in two minutes with tools already built into your browser.

How on-device processing works

When you open a ToolsRift tool, your browser downloads the tool's code, just like any web page. When you drop a file in, that code reads the file directly from your device, processes it in a Web Worker (a background thread in your browser) using WebAssembly or JavaScript, and creates the result in your device's memory. The result is handed to your browser as a download. There is no server on ToolsRift that accepts files — no upload endpoint exists.

Test 1: watch the network

  1. Open Compress PDF (or any file tool).
  2. Open your browser's developer tools: press F12 (or Ctrl+Shift+I, or ⌘+⌥+I on a Mac) and choose the Network tab.
  3. Click the “clear” icon so the list is empty, then drop a PDF into the tool and run it.
  4. Look at the requests that appear. You may see the tool's own code files load, and advert or analytics requests if you allowed them. You will not see a request whose size matches your file, and no request body contains your file. Click any request and check its “Payload” or “Request” section to confirm.

Test 2: switch the internet off

  1. Open a tool page and let it load completely.
  2. Turn on airplane mode, or disconnect Wi-Fi.
  3. Use the tool. It still works — because nothing needed to be sent anywhere.

(A few tools download an extra component the first time you use them, such as an OCR language pack or the background-removal model. Use them once while online; after that they work offline too.)

Every outside service the site talks to

Pages also contact a small number of outside services. None of them receive your files:

HostWhy
pagead2.googlesyndication.com, tpc.googlesyndication.com, googleads.g.doubleclick.net, adservice.google.comGoogle AdSense — loads and measures the adverts that pay for the site (content pages only).
fundingchoicesmessages.google.comGoogle's consent message (cookie and privacy choices).
www.googletagmanager.com, www.google-analytics.comGoogle Analytics 4 — anonymous usage events such as “tool finished in 2.1 s”. Never file names or contents.
static.cloudflareinsights.com, cloudflareinsights.comCloudflare Web Analytics — cookie-less page views and speed.
cdn.jsdelivr.netPublic code host for a few large libraries that load only when a tool needs them (for example OCR language data or a rare-format video decoder).
huggingface.co, *.hf.co, cdn-lfs*.huggingface.coThe background-removal AI model, downloaded once to your device and cached. Your photo is not sent.
challenges.cloudflare.comOnly if enabled: a privacy-friendly anti-spam check on the “Report a problem” form.

The honest part: ads and analytics load from Google and Cloudflare; your files are never sent anywhere. You control advertising and analytics cookies with “Privacy & cookie settings” in the footer.

What we test automatically

Before every release, an automated browser test runs ten file tools with sample files and checks that no request leaving the page contains file data and that no request body larger than 2 KB is sent (other than allow-listed advert and analytics beacons). If that test fails, the release does not go out.

Why this matters

Contracts, bank statements, ID scans, medical letters and family photos are exactly the files people convert online. If a file is never uploaded, it cannot be leaked, logged, kept or misused by the site you used to convert it.

Read the full privacy policy and cookie policy.

Start typing to search every tool.

↑ ↓ to moveEnter to openEsc to close