Privacy, in plain terms
PicSafely is a pre-sharing tool. Everything it does to your picture happens inside your browser tab.
- ✓ Your photos never leave your device
- ✓ No account, no email, no password
- ✓ Nothing personal is stored
What runs on your device
Reading the file, listing what it reveals, removing metadata, and checking the cleaned copy all run in your browser — in a background thread where your browser supports one.
Your files are read from your own disk by the file picker. They are held in memory only while the page is open.
What is sent over the network
No image bytes, thumbnails, file names, metadata values or coordinates are sent anywhere. There is no upload endpoint, no analytics, no advertising code and no client-side error-reporting service in this release. If the page itself fails to render, the hosting platform may log that server-side error; such a log concerns the page, never a photo, because photos are never sent to the server.
Being honest about the rest: to open this website, your browser must request the page, the styles, the code and the fonts. All of these come from the website host itself — no third-party service is contacted. Like any web server, the host can see your IP address, your browser version and the time of the request. That happens before you choose any photo and is unrelated to your pictures.
What is stored
Nothing about your photos is written to cookies, local storage or any cache. Temporary preview links to your pictures are created so you can see thumbnails, and they are released when you press “Start over” or close the tab. Closing the tab clears everything.
Cleaned copies exist only in memory until you download or share them; after that they are ordinary files on your device and your responsibility.
One small note is saved in your browser once you close the “home screen” tip, so it doesn’t show again. It contains nothing about you or your photos.
Add PicSafely to your home screen
It opens like an app, with no App Store needed. It’s the same website, so your photos still stay on your device.
What this cannot protect against
- Anything visible in the picture: faces, street signs, documents, reflections, landmarks.
- Copies you already sent or posted.
- Information the receiving service adds or infers itself, such as your account, upload time or IP address.
- A compromised device or browser extension that can read the page.
- Formats we mark unsupported, and metadata hidden in ways no public parser reads.
We do not claim to remove “every trace”, to work with “every file”, or to make anyone anonymous. When we cannot confirm a clean result, the file is shown as not verified and is never included in a ZIP download.
Face blurring, credits and no accounts
Faces are found and blurred inside your browser using a detection model downloaded from this website. Your photo, the faces found in it and their positions are never uploaded or stored.
There are no accounts: no sign-up, no email, no password. The free, watermarked download needs nothing at all. When you first buy credits or Unlimited, your device creates a random restore code (like PS-XXXX-XXXX-XXXX-XXXX-XXXX) and keeps it in this browser. Our server never stores the code itself, only a one-way scrambled version of it, together with your credit balance, your plan, and for each watermark-free export a one-way fingerprint of the original photo (a SHA-256 code) with the date. None of this identifies you, and the fingerprint cannot be turned back into the photo; it exists only so you are never charged twice for the same photo.
Because we don’t know who you are, we can’t recover a lost code. Keep it safe using “Copy” or “Save as file” on the Your credits page.
The Blur page also asks our server for the current credit price when it opens; that request contains nothing about you or your photo. If you buy, the payment form is loaded from Stripe only at that moment. Stripe (not PicSafely) receives your email, payment details and country to process the payment, tax and receipts, and never your photo. Because the watermark-free file is made on your device, the server checks and records your credits but never sees the picture. Like any website, the host still receives ordinary request information such as your IP address.
Hosting
The app is a static site, so it can be moved to a different host without changing how it works. No claim about the hosting country is made here: that would require checking the deployed site, its content network, logs, monitoring and subcontractors first.