What stays on your device
Compression, resizing, cropping, conversion, rotation, editing, background removal, upscaling, sensitive-detail blur, watermarks, GIFs, PDFs, metadata cleaning and batch recipes run with local browser APIs. Closing the tab releases the ordinary working session. Only if you explicitly enable unfinished-job recovery does PixHandy keep a bounded local draft for that tool in this browser’s private storage. Drafts from different supported tools can coexist, and all unfinished drafts share a 96 MiB retained-input ceiling. These copies are never uploaded or added to the offline cache. Each is deleted after its job completes successfully, when you choose Forget for it, or when you clear this site’s browser data.
Starting a job from Home or Menu
Choosing images on Home or in Menu keeps them only on the current page. If you then open a compatible job marked Ready, PixHandy places the complete verified selection in a separate, single-use browser handoff for that exact job. A completed handoff is deleted after the job accepts it. Otherwise it becomes unusable after 30 minutes and is removed the next time PixHandy inspects that temporary storage or when you clear this site’s browser data. It is not added to Saved Work, result handoffs, recovery, account data or the offline cache.
Temporary editable-project handoff
When you choose Open editable project from Saved Work, PixHandy validates the selected .pixhandy file and places one single-use handoff—its project data and local image or layer files—in this browser’s private storage so the correct editor can open it. The handoff is never uploaded or added to the offline cache. A completed handoff is deleted after the editor opens it. It expires after 30 minutes; an expired or otherwise stale handoff is removed the next time PixHandy inspects that temporary storage. Closing the tab before the editor opens can therefore leave the handoff until that later cleanup or until you clear this site’s browser data.
Historical account recipe data
Public sign-in and account recipe sync are no longer offered. If you used account sync previously, that historical library remains stored under the account identity used at the time. It contains validated recipe settings, recipe names and the quick-recipe choice, but no source images, results or editable project files. To request access to or deletion of existing account data, contact PixHandy through Support.
Offline does not mean storing your images
The service worker caches public pages, app code, fonts and generated brand icons. Fixed face-suggestion and Tap the subject program assets are integrity-verified and may enter PixHandy’s offline cache only after their first successful online use, so the same fixed files can be reused offline. It does not intercept private workspace pages, API requests, cross-origin responses, non-GET requests, blob URLs or private/no-store responses. Photos and their pixels, filenames, tap coordinates, masks, detected regions and results are never added to the offline cache.
Tap the subject stays local
PixHandy runs its bundled MediaPipe and MagicTouch files in a disposable same-origin worker on this device. Your photo and pixels, filename, tap coordinates, mask and result are not uploaded or sent to PixHandy. A suggested cut can be wrong: Color edge and exact Keep or Remove corrections remain available, and you must review the whole result before download.
Face suggestions stay local
On a compatible browser, PixHandy runs its bundled MediaPipe and BlazeFace files in a disposable same-origin worker to suggest blur regions on this device. Those integrity-verified fixed program files may be cached only after a successful online suggestion run for later offline reuse. Your photo, filename, detected regions and result are not sent to PixHandy; its pixels and all those private values are neither uploaded nor placed in the offline cache. Suggestions can miss faces, so manual regions and whole-image review remain required.
HTML and SVG input are deliberately bounded
HTML capture removes scripts, forms, frames and remote resource URLs. Pasted and single-file HTML style blocks are removed; one bounded local static HTML project (.zip) may instead supply qualified local CSS and referenced PNG, JPG or WebP assets. It does not run JavaScript or recreate a live website. SVG conversion, compression and resize use a separate passive boundary that removes all CSS style blocks and attributes, scripts, event handlers, active markup, embedded images, links and external resources before preview or output. PixHandy does not ask a server to fetch arbitrary pages or linked assets.
After download, you choose the destination
PixHandy controls its own browser workspace, not the website, message or storage service where you later send a result. Review that destination’s privacy and retention rules before sharing a sensitive image.