Online File Tool Privacy Checklist: 7 Questions to Ask Before You Upload
Before you upload a file to an online tool, you should be able to answer seven questions about what happens next. Most people skip this step — and most tools are counting on that. This checklist takes under two minutes and tells you whether your file is genuinely safe to hand over.
1. Does the tool actually need to upload your file?
Many tools that look like upload tools are actually running in your browser. A browser-based tool reads your file locally — it never leaves your device — while a server-side tool uploads the file to the company’s infrastructure before processing it.
How to tell: open your browser’s network tab (F12 → Network) before you drop the file in. If you see a POST or PUT request go out when you add the file, it was uploaded. If you see nothing — or only small API calls — the work is happening locally.
For a full breakdown of the two models and how to verify which one a tool uses, read browser-based vs server-side file processing.
2. Does the privacy policy say how long your file is stored?
If a tool does upload your file, the privacy policy should say:
- How long the file is retained after processing
- Whether it is deleted automatically or requires you to request deletion
- Whether it is shared with third parties for any reason
Vague language like “we take your privacy seriously” or “files are handled securely” is not an answer. Look for a specific retention window — “deleted within 1 hour”, “removed after 24 hours”. If you cannot find one, treat the file as retained indefinitely.
3. Is the connection encrypted?
Check that the URL begins with https:// before uploading anything. A plain http:// connection means your file travels over the network unencrypted and can be intercepted by anyone between you and the server — your ISP, a coffee shop router, a corporate proxy.
HTTPS is the absolute baseline. A tool without it should not receive any file you care about.
4. What does the tool do with the processed output?
The input file is one thing; the output is another. Some tools store the results — extracted text, parsed data, converted files — on their servers, accessible via a shareable link. That link may be public, guessable, or indexed.
Check: does the result page have a URL you could share? Does the tool send you an email with a download link? Either means the output is on their server. A tool that writes results directly to your browser’s memory and lets you download locally keeps nothing.
5. Is the tool asking for permissions it does not need?
A file conversion tool that asks you to sign in with Google, grant access to your Drive, or install a browser extension is asking for more than the task requires. Each of those grants ongoing access that goes well beyond the single file you are trying to process.
Legitimate browser-based tools need no account, no OAuth flow, and no extension. If a tool cannot work without one of those, ask why.
6. What kind of file are you uploading?
Not all files carry the same risk if they end up on someone else’s server. Before uploading, ask what the file contains:
- High risk: contracts, medical records, legal documents, financial statements, HR files, anything with names, addresses, or ID numbers
- Medium risk: internal business documents, client data, anything marked confidential or proprietary
- Lower risk: a public PDF you downloaded, a stock photo, a file with no personal information
The higher the sensitivity, the stronger your reason to use a tool that processes the file locally — or to strip sensitive data before uploading.
For a specific look at what happens when you upload a PDF, read is it safe to upload a PDF online.
7. Does the tool’s description match what the network actually does?
The hardest check — and the most important one. A tool can claim “nothing is uploaded” on its homepage while quietly uploading your file in the background. The only way to verify is the network tab.
Open DevTools (F12), go to the Network tab, clear it, then add your file. Watch what requests fire. An honest browser-based tool produces no outbound upload. If you see a request to /upload, /process, /api/convert, or any endpoint sending your file’s bytes — the tool’s claim is false, whatever the marketing copy says.
The short version
Run through these before uploading anything sensitive:
- Does it need to upload? (Check the network tab)
- Does the privacy policy name a retention window?
- Is the connection HTTPS?
- Where does the output go?
- Is it asking for unnecessary permissions?
- How sensitive is this file?
- Does the network activity match the claims?
If you cannot answer questions 1, 2, and 7 confidently, the safest default is to use a tool that runs entirely in your browser. Every tool on EasyExtract processes files locally — the file is read by your browser and never sent to any server. You can verify that with the network tab on any of them.
Frequently asked questions
Open your browser’s developer tools (F12), go to the Network tab, clear it, then drop your file into the tool. If you see a POST or PUT request go out, the file was uploaded to a server. If the network stays quiet, the tool is processing the file locally in your browser.
It depends on the tool. A browser-based tool that never uploads your file is safe for sensitive documents — nothing leaves your device. A server-side tool should only be used for sensitive files if you trust the provider and have read their retention and deletion policy.
At minimum: a specific file retention window (e.g. “deleted within 1 hour”), a clear statement that files are not shared with third parties, and a description of what happens to the processed output. Vague reassurances are not a policy.
HTTPS encrypts your file in transit, so it cannot be intercepted between your device and the server. But it says nothing about what the server does with the file once it arrives — stores it, shares it, uses it for training data. Encryption in transit is necessary but not sufficient.
A browser-based tool that reads your file locally and never uploads it. You can verify this by watching the network tab — a genuine browser-based tool produces no outbound upload request when you add a file.