Verify it yourself: nothing is uploaded
Do not take our word for it
Every redaction tool says it keeps your files safe. Blinded says something stronger: your document never leaves your computer at all. It is opened, read, searched and rebuilt inside your browser tab, and the finished file is written by your browser onto your own disk.
That is a claim you can check, and you should. Each of the tests below takes a few minutes and needs nothing but the browser you already have. The first needs no technical knowledge at all.
Test 1: turn the internet off
1. Open blinded.dev and wait a few seconds after the page has loaded. On a first visit, the tool keeps a copy of itself on your computer for exactly this test.
2. Turn off Wi-Fi, unplug the network cable, or switch on airplane mode.
3. Open a document, search it, redact it and save the result.
Everything works: the reading, the search, the logo matching, the text recognition on scans and the export. A tool that sent your document to a server could not do any of that with no connection to send it over.
Test 2: watch the network
Your browser records every request a page makes, and shows them to you. In Chrome or Edge press F12 (on a Mac, Cmd+Option+I); in Safari, turn on the Develop menu in Settings, Advanced, then choose Develop, Show Web Inspector. Open the Network tab and tick Preserve log.
Now open a document, redact it and export it, and read the list. What you will see is the tool fetching its own files from blinded.dev: scripts, fonts, the PDF reader and the text recognition data, each one a download (a GET request). What you will not see is any upload: no POST or PUT request, nothing sent to another website, and no request anywhere near the size of your document. In Chrome, type method:POST into the filter box to be sure: the list is empty.
Test 3: read the rule your browser enforces
The tool page is sent with a content security policy: a set of rules the browser enforces on the page, whatever its code tries to do. To see it, click the first request in the Network tab (the page itself), then Headers, and find content-security-policy under the response headers. An independent scanner shows the same headers: securityheaders.com.
Two lines matter. connect-src 'self' blob: means the page may not contact any website but blinded.dev itself, so it cannot send anything to a third party, an analytics service or another server of ours. form-action 'none' means it cannot submit a form anywhere at all.
The policy does let the page talk to blinded.dev, because that is where its own files come from. So the fair question is whether blinded.dev collects anything. It is a static site with no server code to receive a file, which Test 2 shows directly: every request to it is a download of the site’s own files.
Test 4: read the code
Everything the site runs is published on GitHub, and the site is deployed from it: the files there are the files your browser runs. The one compiled file, the matching engine lib/fft.wasm, is built from lib/fft.c beside it, and rebuilding it gives the same bytes, which the project’s own tests check.
Which version is live is shown at the foot of the tool: the short code beside Source, linking to that exact commit on GitHub. It is written when the site is deployed, so it is the one file on the site that is not in the repository.
And the page cannot quietly run anything else. Every script and stylesheet the tool page loads carries a fingerprint of the published file (the integrity attribute on each <script> tag, which you can read with View Source). Your browser computes the fingerprint of what it receives and refuses to run a file that does not match. So if the page matches the published one, so does every script it loads. The files those scripts load in turn, the PDF reader, the text recognition engine, the search worker and the fonts, come from fixed addresses written in that checked code, but do not carry fingerprints of their own.
Search it for fetch(: every request the tool makes is for one of its own files, the questions page, the license page, the matching engine and the reader’s data. There is no upload code to find.
What does go over the network
Loading the site downloads its files, like any website. The only other traffic is buying a license, and that happens on a separate page with a policy of its own that talks to the payment processor. The page that holds your document cannot reach it. A license, once bought, is checked inside your browser, with no call home. See the privacy page for the full list of what our hosting and our payment processor can see.
If any of these tests shows you something different, write to support@blinded.dev. We would want to know first.