Your document belongs in the private workspace

The strongest privacy promise is a technical boundary: public content explains the task, while a different site performs local processing.

Before a file is selected

A public tool guide contains no file control, processor bundle or document-derived state. Its ordinary same-tab action records only the fixed tool choice, sends no file name or token, and redirects to the configured cookie-free workspace site without a referrer.

  • Do not drag a file onto the public guide.
  • Check the visible destination hostname before selecting anything.
  • Close the workspace if the destination or browser state is unexpected.

During and after local processing

Only the dedicated workspace controller and worker may receive file bytes. There is no advertising, analytics, account, network API, upload or cross-window message channel there. Buffers, canvases and object URLs are cleaned before a fixed content-free return action appears.

  • Limits protect memory, time, pixels, pages and output size.
  • Source names never become output archive paths.
  • A return carries only the fixed tool and completed, failed or cancelled state.