Skip to content

Verify it yourself

You don’t have to take our word that what you type stays on your device. Your browser can show you.

Last updated 8 October 2026

At the bottom of every page, On this device counts what the page has sent since it loaded. Tap it to see the list. It’s our own code, though, so here are three checks that rely only on your browser. They work in Chrome, Edge, Firefox and Safari on a computer.

1. Watch the Network tab

The Network tab lists every request a page makes: where it went, how, and what it carried.

  1. Open the developer tools: F12, or Ctrl+Shift+I (⌘+⌥+I on a Mac). In Safari, first turn on Settings → Advanced → “Show features for web developers”, then choose Develop → Show Web Inspector.
  2. Open the Network tab and reload the page, so the list starts from the beginning.
  3. Use the tool: type numbers, open a file, change options.
  4. Look at the new rows. In Chrome and Edge, typing -domain:binarydecimal.com in the filter box hides this site’s own files, and method:POST shows only requests that send something.

What you should see:

  • files from binarydecimal.com: the page’s code, styles, fonts and images;
  • requests to Google Analytics (google-analytics.com, googletagmanager.com), unless you turned usage stats off in Settings → Advanced privacy. Click one to see what it carries: the page’s address without its inputs, and names such as “page_view”;
  • nothing else, unless you chose it: a stock photo from Unsplash in the vision board, a mermaid.ink image link, or your own AI provider after you added a key.

None of them carries what you typed, unless you asked for it: a message you send through the contact form, or a question to your own AI provider. Many tools keep their inputs in the page’s address so a result can be shared; that address is sent to our host only when a page is opened with it, as with any website (see Hosting).

2. Use a tool offline

A tool that needs no server keeps working without a connection.

  1. Open a tool and let it load.
  2. Go offline: in Chrome or Edge’s Network tab, change “No throttling” to Offline, or turn off Wi-Fi.
  3. Use the tool. The answers still change as you type.
  4. Reload. The page opens from the copy your browser kept the first time, and the footer says Works offline.

3. Read our Content Security Policy

A Content Security Policy is a list the site sends with every page, naming the only places that page may load from or send data to. Your browser checks every request against it.

  1. In the Network tab, click the first row: the page itself.
  2. Under Headers → Response Headers, find content-security-policy-report-only.
  3. Read connect-src: where the page’s code may send data. It lists this site, Google Analytics, and the four AI providers you can add your own key for (OpenRouter, OpenAI, Anthropic and Google’s Gemini API). form-action allows forms to post only to this site.

From a terminal: curl -sI https://binarydecimal.com/ | grep -i content-security.

The policy is in report-only mode for now: your browser checks it and writes any breach to the Console, but doesn’t block it. Our browser tests fail on any breach, and we’ll switch it to blocking after an upcoming change of hosting.

What the counter counts

  • An upload is a request that can carry something out of the page: one with a body (a form, an AI request, a beacon), or one to another site whose address has data in it.
  • Not uploads: loading this site’s files, and Google Analytics, which is listed on its own because what it receives is fixed (see the privacy policy).
  • It reads your browser’s list of the page’s requests and the page’s own fetch, XHR and beacon calls. Background workers (the PDF and Python tools) aren’t in that list; they load only this site’s files, which the Network tab shows.

Found something that doesn’t match? Please tell us.