Privacy
Exactly what happens to your files and your data.
Last updated 5 October 2026
The short version
- Your files are processed inside your browser. They are never uploaded to us.
- There is no account, no sign-up and no contact form.
- We run no analytics and set no cookies.
- Six things are saved in your own browser. They are named below. One is the text you type into the Markdown Converter. Two are copies of this site’s own files: about 7 MB so it opens with no internet connection, and up to about 27 MB more if you use every tool.
- Our host, Vercel, logs every request for the pages themselves — as every website host does.
What happens to your files
When you drop a file onto a tool, your browser reads it from your disk and hands it to the page. The work — merging a PDF, cleaning a spreadsheet, shrinking a photo — happens in that tab, using code that was downloaded to your device. The finished file is built in memory and passed to your browser’s own download. There is nowhere to send a file to, because there is no server: the site is a set of static files.
While a tool is open, your file stays in the tab’s memory on purpose, so you can change a setting and run it again without picking the file a second time. When you close the tab, it is gone. We will not claim more than that: the browser releases that memory when it chooses, and nothing here overwrites or securely erases anything.
One thing does change in your files. The Image Compressor re-encodes each photo, and the copy it gives you has no EXIF data — so the camera details, and the GPS location if your photo carried one, are not in the compressed version.
Anything you save is written to your own disk by your browser, exactly as with any other download.
What is stored on your device
Six things, all kept by your browser for this site alone. None of them is an identifier, and we cannot read any of them, because nothing is ever sent back to us.
| What it is | Saved under | What it holds | How long it lasts |
|---|---|---|---|
| Light or dark mode | free-secure-kit:theme | The word light or dark | Until you clear this site’s data |
| Your Markdown draft | free-secure-kit:markdown-converter:doc | The full text you have typed or pasted into the Markdown Converter | Until you clear the editor, or clear this site’s data |
| Markdown export style | free-secure-kit:markdown-converter:theme | The name of the style you picked for exports | Until you clear this site’s data |
| Downloaded tool files | free-secure-kit-assets-v1 (Cache Storage) | The model and engine files the Background Remover, Passport Photo and PDF unlock tools need, kept so they are not fetched again. About 27 MB if you use all of them. | Until you remove them in the tool, or clear this site’s data |
| A copy of the site | fsk-shell-… (Cache Storage) | The pages, styling and code of this site, about 7 MB, so it opens with no internet connection. None of your files, and nothing about you. | Replaced when the site is updated — the new copy arrives before the old one goes, so both are there briefly; gone when you clear this site’s data |
| Support message flag | free-secure-kit:support-nudge-seen | A single 1, so a thank-you message can appear at most once | Until you close the tab |
The last one is only written if a contributions link is switched on. To remove all six, clear this site’s data in your browser settings.
Both caches hold our code rather than anything of yours. Once the Background Remover has downloaded the tool files it shows a link to remove them from this browser, which clears them for every tool that shares them.
Working without an internet connection, in plain terms
The first time you visit, your browser saves a copy of this site so you can use it with no internet connection. Tools you have already used work too. A tool that still has files to download does not, until you open it once with a connection. That copy is the pages, the styling and the code — about 7 MB. It is the same thing you would have downloaded anyway to see the site; it is simply kept instead of being fetched again.
What it does not hold is anything of yours. Your files never travel over the network in the first place: the browser reads them straight from your device into memory, so there is nothing for this to see, store or send. It does use the network — that is how it fetches the copy, and how it falls back when it has nothing saved — but only ever to this site, for this site’s own files. It contains no name, number or anything else that could identify you.
What it costs you is disk space, and a copy of this site sitting on the machine until you clear it. On a shared or public computer that is worth knowing, the same as the Markdown draft below. When we publish a change, your browser fetches the new version and offers you a Reload; the old copy is then deleted.
The Markdown draft, in plain terms
Everything you type into the Markdown Converter is saved in your own browser, half a second after you stop typing, so that it is still there when you come back. It survives closing the tab, quitting the browser and restarting the computer. Pressing Clear in the editor and confirming removes it straight away. On a shared, work or public computer, the next person who opens this tool in that browser will see what you wrote. Clear the editor before you walk away.
Apart from the tool files listed above, no other tool keeps anything between visits. No file name, file size or file content is written to storage anywhere, and the site sets no cookies and uses no database in your browser.
What we collect
The site itself collects nothing, because nothing is transmitted from the page. There is no analytics, no error reporting, no session recording and no tracking pixel. Vercel Analytics and Vercel Speed Insights are specifically not installed — they are not in the project’s dependencies and nothing of the kind is loaded by any page. Using a tool never tells us your name, your email address, what you converted or that a file existed at all. The one exception is the request log our host keeps, which is the next section.
The site is served over HTTPS, and every page carries a policy telling your browser it may only open connections back to this site. That is a strong extra guard against a mistake in our code reaching somebody else’s server, rather than a cast-iron guarantee.
What our host can see
The pages are served by Vercel, and Vercel’s servers record every request they answer: your IP address, your browser and device description, the address requested, and the time. This is true of every website you visit. On a site with no server code of its own there is no way for us to switch it off, so we would rather say so than pretend otherwise.
Those logs never contain the contents of your files, their names or their sizes — nothing you work on is ever part of a request. One detail is worth knowing: each tool’s code is downloaded only when somebody opens that tool, so the log does show which tool was opened and when.
An IP address counts as personal data in many places. The logs are held by Vercel under its own privacy policy. We do not use them to build a profile of anyone.
Third parties
- Vercel hosts the site and sits in front of every page, as described above.
- GitHub is involved only if you click one of our links to the source code or the issue tracker, at which point you are on GitHub’s site under its rules.
- PayPal and Razorpay each host a contribution page of their own, and each takes the payment on its own page. Neither is involved at all unless you choose to contribute. See below.
Third-party code does run in your browser — the PDF, spreadsheet, image and Markdown libraries that do the actual work. All of it is bundled into this site and served from here. Nothing is fetched from an outside content network while you use a tool, and no web fonts are downloaded: the text you are reading is set in your own system’s fonts.
One caveat about your own documents. If your Markdown contains an image hosted elsewhere, it is blocked while you preview it here. But a web page you export and save has no such protection, so opening that saved file later will fetch the image from wherever you pointed it.
Contributions
Nothing on FreeSecureKit is for sale, and no feature is unlocked by paying. A contribution is a voluntary gift towards the time this takes. It buys nothing and unlocks nothing.
There is no payment widget on this site and no payment code in any page. If you choose to contribute, you follow a link out to a page the payment company hosts itself, and everything after that happens away from here. That is deliberate: no payment script ever runs on a page that is handling your files.
There are two such links, because no one company reaches everybody. PayPal is for contributors anywhere outside India, and you pay in US dollars. Razorpay is for contributors in India, and you pay in rupees. Each is one company doing both jobs: it hosts the page and it takes the money. You type the amount in yourself, and neither route converts your currency for you. Each company holds what it collects under its own privacy policy: PayPal and Razorpay.
We never see or store card or bank details. On the Razorpay page you type an amount and may leave a short note if you want to; Razorpay then asks for whatever it needs to take the payment. On PayPal the same applies. From either we can see the amount, the date, whether the payment went through, any note you left, and whatever contact details that company passes on to us, and we can export that list. We use it only to answer a question about a contribution or to make a refund, which goes back through whichever company took the payment, to however you paid. We do not add you to any mailing list.
Children
The tools are suitable for anyone, and there is no account to create. We do not knowingly collect personal information from a child; the only personal details that ever reach us are whatever Razorpay or PayPal passes on about a payment.
Changes to this policy
If the site changes in a way that affects this page, we will change the page and the date at the top of it. Every previous version is in the project’s public commit history, so you can see exactly what changed and when.
Asking a question
Open an issue on the GitHub issue tracker and we will answer there.
Check it for yourself
FreeSecureKit is open source under the MIT licence. Every claim on this page can be checked against the code, and so can the network tab of your own browser while you use a tool. The source is at github.com/sarkhailstorm/free-secure-kit.