Security and data handling
Your photos, signatures and PDFs are processed in your browser and are never uploaded. ExamFitr has no server that receives files: the site is a set of static files, and every tool runs on your device.
Last updated .
How your files are handled
- When you choose a file, the browser reads it into memory on your device. It is not sent anywhere.
- Each tool works on that in-memory copy using the libraries below, all served from this website.
- The result is created as a file in your browser's memory and saved by the download button.
- When you close or reload the tab, the images are gone. Nothing is written to storage on your device except the small settings listed in the cookie policy.
| Tool | What does the work |
|---|---|
| Photo and signature editor (resize, crop, exact KB, signature clean-up, name and date) | Canvas and the browser's own JPEG/PNG encoder |
| Background removal | MODNet model run by ONNX Runtime Web in a Web Worker, or MediaPipe (Light mode) |
| Face centring | The browser's FaceDetector where available, otherwise face-api |
| HEIC and TIFF input | heic2any and UTIF, decoded in the page |
| Image to PDF and PDF compression | PDFs are written in the page; existing PDFs are read with pdf.js |
| Passport print sheets, converter, increase KB, resize in cm | Canvas, in the page |
The models and libraries are downloaded from this site the first time you use a feature and cached by your browser. These downloads go one way, from the site to your browser. No third-party CDN is used.
How we tested it
On we ran every tool in Chrome with real test files (25 scenarios: exam photos and signatures, every compress-to-KB page, background removal in both modes, passport sheets, name and date, join, increase KB, resize in cm, image to PDF, PDF compression and conversion) while recording every network request the page made.
- 131 requests in total, all to this website, all of them downloads of the site's own scripts and model files.
- 0 requests to any other website.
- 0 requests that sent data (POST, PUT or similar). No request carried file contents.
The test script is tests/measure_examples.py in the project, and it runs again before each release.
Check it yourself
- Open the resizer, then open your browser's developer tools (F12) and go to the Network tab.
- Process a photo. You will only see requests to this site for scripts and, for background removal, the model files. None of them sends your image.
- Or load the page, switch your device to airplane mode, and use the tool. It keeps working, because everything runs locally (background removal needs one online visit first to cache the model).
Browser protections
- Content Security Policy: pages may only connect to this site (
connect-src 'self'), so a page can't send data to another server even by mistake. - Frame protection: pages can only be framed by this site, except the embeddable resizer, which is designed to be placed on other sites and still runs entirely in the visitor's browser.
- HTTPS only (HSTS), no MIME sniffing, a strict referrer policy, and camera, microphone and location access switched off.
- Cross-origin isolation (COOP/COEP), which also lets background removal use several CPU threads.
What we do collect
Nothing from your files. Analytics is currently switched off on this site, so no visit data is collected either. The full details are in the privacy policy.
Limits
- Browser extensions you install can read pages you visit; that is outside our control.
- If you email us a file (for example with a size report), that email is handled like any other email, not by the tool.
- The site has not had an independent security audit.
Report a security problem
Email support@examfitr.com with the steps to reproduce. Please don't test against other visitors.