How MiniPx keeps your files private
Many popular image compression tools work by uploading your file to a server, processing it remotely, and sending back the result. During that round trip, your original photo exists on infrastructure you do not control — often for minutes, sometimes longer.
MiniPx takes a fundamentally different approach. All image processing runs in JavaScript directly inside your browser tab using the Canvas API and Web Workers. When you compress a photo, resize an image, or convert between formats, the work happens on your CPU — not on a remote server. Your files never enter a network request.
For compression, resizing, format conversion, the PDF tools and every free tool, this architecture is not a premium feature or an optional mode — it is the only way those tools work. There is no server-side fallback for them, no cloud processing for larger files, no optional upload path: every one of those operations, from a 100KB icon to a 25MB camera RAW photo, runs locally. MiniPx has exactly one server-side path, it is named in the next section, and it is not on unless you put it there.
Cloud HD: the one exception, and you switch it on
Cloud HD runs a heavier model than a browser can manage, on hardware we rent, for 7 AI tools. On three of them — the background remover, the image upscaler and the passport photo maker — it is a switch you turn on per tool, and they run on your device otherwise. The other 4 — restoring, colourising and enhancing old photos, and removing an object from one — are built on it and have no on-device mode. All of it needs a paid Pro account, so it is unreachable for anyone who has not subscribed and has not turned it on.
On a Cloud HD run, one photo — the one you are working on — is uploaded to Cloudflare R2 and processed at Modal Labs, both in the United States, and it is deleted when the run finishes, and in all cases within 24 hours; passport and ID photos go the moment the run completes. It is never used to train, tune or evaluate anything, and there is no screen anywhere in MiniPx that could show it to us. Everything else on this page — compression, conversion, resizing, the PDF tools — is unaffected, and so is a buyer who never switches Cloud HD on. Section 2A of our Privacy Policy is the full account: what is sent, where it goes, how long it exists and the legal basis for the transfer.
What this means for you
Personal photos stay personal. Compress holiday snaps, family photos, or selfies without a copy existing on someone else's infrastructure.
Sensitive documents stay secure. Passport scans, ID photos, medical images, tax documents, contracts — compress, convert and resize them knowing nothing leaves your device, and that the one path which would send a photo to us is a Pro switch you have to set yourself.
Business files stay confidential. Product photos before launch, internal presentations, unreleased marketing assets — compress without leaking to third parties.
EXIF metadata gets stripped. Every compression removes GPS coordinates, device info, and timestamps that are invisibly embedded in your photos. Your output files contain no hidden personal data.
GDPR and UK data protection
The architecture removes the hard part of GDPR rather than satisfying it by paperwork: because no file you compress, convert or resize is transmitted to or stored on our servers, there is no image data processing to disclose for that content, no processor agreement to sign, and no breach surface. That claim covers every tool on this site except one. A Cloud HD run is ordinary processing and we treat it as such: it happens because you asked for the service you bought, so the lawful basis is Article 6(1)(b), it takes place in the United States under the European Commission's standard contractual clauses (Module 2) with the companies that store and run it, and the photo is deleted when the run finishes, and in all cases within 24 hours. An organisation that leaves Cloud HD off is in the first case, not the second.
The website is a separate question, and it would be dishonest to fold it into the same sentence. We run Google Analytics (property G-CPKR150KT7) for page-view measurement. It sets first-party cookies (_ga, _gid) and processes your IP address and a pseudonymous identifier, which is personal data under GDPR and the UK Data Protection Act. MiniPx shows no ads, so there are no advertising cookies on any page. There is no session replay and no fingerprinting, but we are a data controller for that analytics data and we do not claim to be exempt from regulation because of it. What we can say precisely: outside a Cloud HD run you have switched on, we never see, receive, or store the images you process. Full disclosure, including lawful basis, the Cloud HD transfer safeguards and how to exercise your access and erasure rights, is in our Privacy Policy.
Sector-specific use cases
Earlier versions of this page told regulated professionals what their compliance obligations were. That was overreach on our part. We can tell you precisely how the software behaves, and we have every incentive to get that description right. We cannot tell you what your regulator, your DPO, or your professional body will make of it, and you should be suspicious of any vendor who does. So what follows is the architectural fact, and the assessment stays where it belongs — with you.
The fact, once, for all four sectors. Image files opened in MiniPx are decoded, processed and re-encoded by JavaScript in your browser. They are not uploaded, not stored on our infrastructure, and not transmitted to any third party. What does leave the browser is set out in our Privacy Policy: Google Analytics events carrying anonymous operation metadata, and, if you use the on-device AI tools, a model-file download from a third-party host that sees your IP address but not your file. There is exactly one server-side processing path for image content and it is Cloud HD: it needs a paid Pro account and an explicit switch, it sends that one photo to the United States for the run, and it deletes it when the run finishes. An organisation without Pro cannot reach it at all; an organisation with Pro can leave it off. The four paragraphs below describe the software with Cloud HD off, which is how it arrives.
NHS and healthcare. Patient images, clinical photographs, referral documents and scan results fall under NHS data governance standards, and uploading them to a server-side compression tool creates a processing relationship your organisation has to account for. MiniPx does not create that relationship for the image content, because on every tool but Cloud HD the content never reaches us — and Cloud HD needs a Pro subscription and a switch that is off until somebody sets it. Whether that changes your DPIA position, your DSPT return, or your Caldicott assessment is a judgement for your information governance lead — bring them this paragraph rather than our conclusion.
Education. Schools and universities handle student photos, exam scripts, safeguarding records and SEND documentation, and processing children's data attracts the higher standards of the Age Appropriate Design Code. The relevant fact is that no student image is transmitted to us unless a Pro account switches Cloud HD on. Whether MiniPx nonetheless belongs on your record of processing activities is a decision for your DPO, not for us — note that the analytics, the AI-model download and the Cloud HD disclosures above are the parts that would inform that decision.
Legal and professional services. Solicitors, barristers and accountants handle privileged and confidential client material, and sending a contract scan or a court filing image to an external server puts that material in a third party's hands. With MiniPx the document is never disclosed to any third party, because on the tools a scan goes through — compression, conversion, resizing, PDF — it never leaves the device; the one path that would send it, Cloud HD, is Pro-only and off unless switched on. Whether privilege or your confidentiality obligations are affected in your specific matter is a question for your firm's risk or compliance function, and we are not in a position to answer it for you.
Government and public sector. UK departments classify material under the Government Security Classifications policy, and OFFICIAL-SENSITIVE material is not to be processed on external services without assessment. The fact we can supply for that assessment is that the material stays on the user's device throughout processing on every tool except Cloud HD, which is Pro-only, off until switched on, and processes in the United States when it is. The assessment itself, and whether your departmental policy permits the site at all, is your security team's call.
Verify it yourself
You do not need to take our word for it. Open your browser's developer tools (F12 on desktop, or use your browser's inspection mode), switch to the Network tab, then compress an image. You will see the page load resources (HTML, CSS, JavaScript) and Google Analytics events, but zero outgoing requests containing image data unless you have switched Cloud HD on for that run. Or simply disconnect from the internet after the page loads — compression, resizing and format conversion still work.
The compression logic uses the browser's native Canvas API for JPEG/PNG/WebP encoding and jsPDF for PDF creation. No proprietary server-side processing is involved and no third-party image service receives your file; the only server that ever receives one is ours, on a Cloud HD run you asked for.
Two network requests are worth naming rather than glossing over, because you will see them in that Network tab and we would rather you saw them here first. The model file. The on-device AI tools (background removal, upscaling, face detection) run their model on your device, but the model file is not ours and is not bundled with the page. The first time you use one, your browser downloads it directly from huggingface.co — which redirects the download itself to Hugging Face's own CDN, us.aws.cdn.hf.co or cas-bridge.xethub.hf.co — or from storage.googleapis.com, around 44 MB to 109 MB depending on the tool, cached afterwards so it happens once. Those are the four hostnames you will see, and they are the same four listed in the source at app/lib/engine/models.js; the redirect targets are still Hugging Face, Inc., not a further party. That host sees your IP address and user agent, the same as any file download. It does not see your image, because your image is not part of the request: the model travels to your file, never the other way round. The Cloud HD upload. This is the one request that ever carries an image, and it happens only on a Pro account, only on a run you switched on or a tool that says it is server-only, and nowhere else. If either transfer is unacceptable in your environment, every non-AI tool on MiniPx works without both.
Comparison with other tools
| Feature | MiniPx | TinyPNG | iLoveIMG |
|---|---|---|---|
| Processing location | Your browser | Their server | Their server |
| Files uploaded | Never, unless you switch on Cloud HD | Always | Always |
| Works offline | Yes | No | No |
| EXIF stripping | Automatic | Partial | Optional |
| GDPR-safe by design | Yes | Policy-based | Policy-based |
