Skip to content

How to Edit Photos Without Uploading Them

Crop, adjust, blur and add text to photos in your browser without sending them anywhere: what EXIF location data is, and how to check nothing is uploaded.

Computing··6 min read

Most quick photo jobs are small: crop a picture square, blur a face, put a caption on it, make the file smaller. Plenty of websites will do them, but many work by sending your photo to their server, editing it there and sending a copy back. For a holiday snap that may not matter. For a picture of your child, your home, an ID card or a screenshot of your bank, it might.

It doesn't have to work that way. A modern browser can decode, edit and save images on your own computer or phone, with nothing leaving the device. This guide covers what that kind of editor can do, what a photo file can give away about you, and how to check for yourself that nothing is being uploaded.

What a browser can do on your own device

Browsers have had the building blocks for a while: the canvas for drawing pixels, WebGL for running image filters on the graphics card, and file access for opening and downloading pictures. Our photo editor is built on them, and every step runs in the browser tab:

  • Crop and straighten to a fixed ratio such as 1:1, 4:5 or 16:9, or any shape: crop an image.
  • Resize to exact pixel dimensions: resize an image.
  • Rotate and flip, and fix photos that show up sideways: rotate an image.
  • Adjust exposure, contrast, curves and colour, with changes that stay editable.
  • Filters, 12 of them, from black and white to vintage looks: image filters.
  • Text and shapes, for captions, labels and arrows: add text to a photo.
  • Blur the whole picture or just one area: blur an image.
  • Layers, with opacity, blend modes and masks, plus 50 steps of undo.

When you're done, you export a PNG, JPEG or WebP (or AVIF, where the browser supports it) straight to your device. The open project also autosaves in the browser's own storage on that device, so a reload doesn't lose your work.

What's hidden inside a photo file

A photo is more than its pixels. Cameras and phones add metadata in a format called Exif (Exchangeable image file format), a standard published by the Camera & Imaging Products Association (CIPA). It defines fields such as:

Exif data What it can reveal
Date and time the photo was taken When you were somewhere
Camera make and model, lens, settings What device you own
GPS latitude, longitude and altitude Where the photo was taken
Orientation Which way up to show the picture

The GPS fields are the ones to think about. On a phone, they're filled in when the camera app is allowed to use your location. Apple's personal safety guide, for example, explains that iPhone photos carry location metadata when the Camera has access to Location Services, and shows how to share a photo with the location left out (in the share sheet, tap Options and turn off Location). A photo of your front door or your child's school, shared as the original file, can carry the address with it.

You can see what your own photos hold. On an iPhone or iPad, open the photo and tap the info (ⓘ) button to see the date, the camera and a map. On Windows, right-click the file, choose Properties and then Details. On a Mac, open it in Preview and choose Tools → Show Inspector.

Why "no upload" matters

When a photo is uploaded, the original file, metadata included, ends up on a computer you don't control. What happens next depends on that service: how long it keeps the file, who can access it, and whether it's used for anything else. You have to take its privacy policy on trust.

An editor that works on your device takes that question away. There's no copy to delete later, because no copy was made.

It also helps with the metadata. Files exported from our editor are drawn fresh from the pixels, so they carry no Exif at all: no date, no camera model, no GPS position. The orientation is fixed in the pixels themselves, so the picture shows the right way up everywhere. One thing to remember: the editor's own project file (.bdphoto) keeps the photo you opened as it was, so it can be edited again later. Share the exported image, not the project file.

How to check that nothing is uploaded

You don't have to take any website's word for it, including ours. Every desktop browser has developer tools with a Network panel that lists each request the page makes. Here's how to watch it:

  1. Open the editor and let the page finish loading.
  2. Open the developer tools. Press F12, or Ctrl+Shift+I (⌘+Option+I on a Mac). Choose the Network tab. This works in Chrome, Edge and Firefox; in Safari, first turn on Show features for web developers in Settings → Advanced.
  3. Clear the list with the panel's clear button, so only what happens next shows up.
  4. Edit a photo. Open it, crop it, blur something, add text, then export it.
  5. Read the list. An upload would appear as a request to a server, usually a POST, roughly the size of your photo: a 3 MB picture means a 3 MB request. The Size column shows how much each request sent and received.

In our editor you'll see no such request. You will see a font file load from binarydecimal.com the first time you add text or pick a new font, and a few tiny requests to Google Analytics for the site's anonymous usage stats: the page's address and events such as "opened a photo" or "exported", never the picture or anything in it. You can turn those off under Advanced privacy in Settings. None of these requests carries your photo.

For an even simpler test, go offline. Once the editor has opened, turn off Wi-Fi (or choose Offline from the throttling menu in Chrome's Network panel) and carry on: open a photo, edit it and export it. Everything still works, because nothing needed the internet. The one exception is a font you haven't used yet: it can't be fetched while you're offline, so that text is drawn in a fallback font instead.

One more privacy tip: blur isn't a lock

Blurring a face or a car's number plate is fine for most photos, but it isn't a reliable way to hide secrets. Researchers showed in 2016 that trained software could still recognise faces and read digits through blurring and pixelation. For passwords, account numbers, addresses or ID documents, cover the area with a solid box instead (in our editor, a rectangle from Shapes at full opacity). The exported file then contains only the flat colour there, with nothing to recover.

The short version

  1. A browser can crop, adjust, filter, blur and caption photos without uploading them.
  2. Photos often carry Exif data, including GPS location. Share copies without it.
  3. Check any site yourself: watch the Network panel while you edit, or go offline and see if it still works.
  4. For secrets, use a solid box, not a blur.

Sources

  • Camera & Imaging Products Association (2023). CIPA DC-008-Translation-2023: Exchangeable image file format for digital still cameras: Exif Version 3.0. cipa.jp
  • Apple. Manage location metadata in Photos. Personal Safety User Guide.
  • Chrome for Developers. Inspect network activity. Chrome DevTools documentation.
  • Mozilla. Network Monitor. Firefox DevTools user documentation.
  • McPherson, R., Shokri, R., & Shmatikov, V. (2016). Defeating image obfuscation with deep learning. arXiv:1609.00408
privacyphotosexifimage editingbrowsercomputing