Privacy Policy & Trust Boundary
Our technical commitment to client-side data privacy and zero server image uploads.

1. Zero Image Uploads (Browser-Local Sandbox)
When you select an image file to compress, the file is read into your browser's local memory using the HTML5 File API and decoded into an in-memory Canvas element.
Selected image bytes, dimensions, filenames, and visual contents are never transmitted across the network to any server, cloud storage bucket, AI model, or backend API. Once the required image-processing scripts have loaded, compression itself does not need a server upload.
2. Content Security Policy (CSP) Invariants
This application is designed with strict Content-Security-Policy headers restricting external network access:
connect-src 'self' https://*.google-analytics.com https://*.analytics.google.com— No outgoing fetch, XMLHttpRequest, or WebSocket calls except the Google Analytics page-metrics endpoints. Your images never leave the browser.default-src 'none'— Blocks unauthorized script and frame injections.font-src 'none'— Zero remote typography tracking or font CDN connections.
3. Honest Privacy Boundaries
While our application does not upload or retain your images, standard web infrastructure realities apply:
- This website uses Google Analytics to measure page visits and usage. Analytics may send usage data and use cookies; it does not receive the images selected in this compressor.
- Standard static asset hosting servers log basic HTTP requests for the HTML and JavaScript bundle itself (e.g. your IP address and user-agent when loading the site).
- Browser extensions or local malware on your computer could inspect DOM or memory state independently of this website.
- Re-encoding an image strips common EXIF metadata (such as camera models, timestamps, and GPS coordinates), but it does not represent forensic data wiping.