How it works

How PixWrench works, and how to check it

The short version: your browser downloads the tools, and the tools work on your files without sending them anywhere. Here is the longer version, with a test you can run in a minute.

What runs where

PartWhere it runsWhat it sees
The page, settings and previewsYour browserYour files, in memory, while the tab is open
Image codecs (MozJPEG, libwebp, libavif, OxiPNG, resize)Background threads (Web Workers) in your browserThe pixels they are asked to process
HEIC decoderYour browser’s own decoder, or libheif in a background threadThe HEIC file being converted
Our servers (Cloudflare)Cloudflare’s networkRequests for pages and codec files, the same for everyone. Never your files
Ads and analyticsSeparate scripts on the same pageWhat any web page shows them; the tools never hand them files or text

PixWrench is a static website. There is no upload endpoint, no processing server and no database of files, because there is nothing for one to do. When a tool needs a codec for the first time, your browser fetches it from pixwrench.com like any other script; those files are identical for every visitor and the request contains nothing about your images.

Inside a tool

Take the image compressor. When you drop a photo:

  1. The file type is checked from its bytes, not its name. A “.heic” that is really a JPEG is treated as a JPEG; a PDF renamed to “.jpg” is politely refused.
  2. The header is read without decoding the picture, to learn its size and orientation. Images too big for your device’s memory are caught here, before anything heavy happens.
  3. A background thread decodes the image to raw pixels, applies the photo’s rotation flag so it comes out upright, and applies your changes: resizing with a Lanczos filter, cropping, rotating, blurring or adding a watermark.
  4. The encoder writes the new file. For a target size, it tries up to seven quality levels in a binary search, and only shrinks the dimensions if even the lowest quality is too big.
  5. Metadata is written back as you chose. By default location, camera serial numbers and other hidden details are removed, while the color profile is kept so colors don’t shift.
  6. The result goes back to the page as a file in memory that you can preview, download or add to a zip, which is also created in your browser.

The metadata viewer and remover goes one step further for JPG, PNG and WebP: it removes the metadata blocks and copies the compressed picture data byte for byte, so there is no re-compression at all. The QR code generator encodes your text in the page and then decodes the finished image with an open-source scanner engine to prove it reads back exactly.

Check it yourself

You don’t have to take our word for any of this. Two quick tests:

The offline test

  1. Open the image compressor and compress one photo, so the codec files are loaded.
  2. Turn off Wi-Fi or switch on airplane mode.
  3. Drop in more photos. They still compress and download, because nothing needs the network.

The network log test

  1. Open your browser’s developer tools (F12 on Windows, ⌥⌘I on a Mac) and choose the Network tab.
  2. Use any tool on a few files.
  3. Look at the requests. You’ll see page files, codec files with names like mozjpeg_enc…wasm, and possibly ad or analytics requests, but no request that sends your images.

Our own automated tests do the same thing on every tool: they record every request the page makes while files are processed and fail the build if anything other than a same-site file download happens.

Sensible defaults

  • Upright photos. Phones often store pictures sideways with a flag that says “rotate me”. PixWrench applies that flag to the pixels and resets it, so the result looks right in every app.
  • Location removed. Compressing and converting remove GPS by default. The HEIC converter keeps the date taken because people sort photos by it.
  • Never bigger. If re-compressing a file in the same format wouldn’t make it smaller, the compressor keeps the original picture data and tells you.
  • Settings, not files, are remembered. Your quality and format choices are stored in your browser so they’re there next time. Files, names and QR content never are.

Limits and honesty

Working locally means your device sets the limits. PixWrench decodes images up to 50 megapixels on a computer and 24 megapixels on phones and low-memory devices, and offers to scale anything larger down to 6,000 pixels on its long edge before opening it. AVIF encoding is slow on phones. Very large batches are processed a few files at a time so your tab stays responsive.

Some promises we deliberately don’t make. Blurring or pixelating text can sometimes be reversed, so the blur tool recommends a solid box for anything sensitive. A watermark is a visible mark, not copy protection. A static QR code never expires, but it can only lead somewhere that still exists. And ad scripts share the page with the tools: we never pass them your files, but we don’t claim they are walled off from the page.

How we test

The image logic (file-type detection, metadata reading and removal, resize and crop geometry, target-size search, QR encoding and favicon packing) lives in a separate package with automated tests, including property-based tests that throw thousands of random inputs at it. QR codes are tested by encoding random text, rendering it and decoding it with a real decoder. End-to-end tests run every tool in a real browser with sample photos, check the output’s dimensions, format and metadata, and confirm that no file leaves the page. Changes are listed in the changelog, and the open-source components on the licenses page.