Local-first tools make a privacy claim, and the claim is easy to make and easy to fake. Here is what actually happens, so you can check rather than trust.
The five steps when you drop a file onto a local tool
- The browser reads the file from your disk into the page’s memory. It has already been on your machine; nothing has moved.
- The file’s first bytes are checked to confirm it is genuinely the type it claims to be. This happens before any parser touches it.
- A processing engine — a library compiled into the page — reads those bytes and writes the result into memory.
- The result is turned into a download and handed to your browser’s download manager.
- The page is closed or reloaded, and the memory is released.
At no point in those steps is there a network request carrying your file. That is the whole mechanism. There is no queue, no job ID, and no server that briefly held your document.
What does still leave your device
Be precise, because a claim of "nothing leaves your device" is usually overstated:
- The request for the web page itself, including your IP address and user agent. That is how the web works.
- Font files, if the site loads them from a third-party CDN. No file information is involved.
- Analytics, if a site collects them. A good local-first tool records which tool was used and nothing about the file.
Your file contents, filenames, sizes and pasted text are not on that list. That is the meaningful part, and it is the part worth insisting on.
How to check a claim yourself
- Open your browser’s developer tools and switch to the Network tab.
- Drop a file into the tool and watch what happens. A local tool shows no request containing your file, and no upload at all.
- Turn the network off entirely — the tool should keep working, because the work is already on your machine. If it stops, the processing was remote.
The offline test is the honest one
A tool that keeps working with no connection cannot be uploading anything. It is the fastest way to sort a local-first tool from a marketing claim.
The trade-off you accept
Local processing means your device does the work, so speed and file size depend on your machine rather than on someone else’s cluster. A very large PDF or a long batch will be slower than a server-side tool, and a low-powered phone will feel it. In exchange, your document never sits on hardware you do not control, and there is no operator who could be compelled to hand it over.
For most files, that is a good trade. For files measured in gigabytes, it is a real one, which is why every Furtu tool page states its size limits rather than leaving you to discover them.