Methodik
The claim
Your selected files are processed locally in this browser and are not uploaded by FileSlimmer. That is one specific, checkable claim. This page explains how it is kept true and how you can confirm it without trusting the sentence itself.
How you can check it yourself
- Open your browser's developer tools and switch to the Network tab.
- Load a tool page and let it finish loading. You will see requests for HTML, CSS, JavaScript and, for some tools, a WebAssembly module or AI model. All of them come from this domain.
- Clear the network log.
- Select a file and run the tool.
- Watch the log. No request is issued while the file is being processed.
Turning your network connection off after the page has loaded is the blunter version of the same test: the tools keep working.
How the build enforces it
Four independent mechanisms, each of which fails the build rather than warning:
- Source scan. Every file that can touch your bytes is scanned for
fetch,XMLHttpRequest,WebSocket,EventSource,WebTransport,sendBeaconandFormData. A single unannotated occurrence stops the build. The only permitted exception is a same-origin engine or model download that happens before processing begins, and each one carries a written justification in the source. - Self-hosting audit. The whole source tree and the built output are scanned for third-party hosts. No library, font, model or WebAssembly binary is loaded from a CDN, so there is no third party in the request path to begin with.
- Content Security Policy. The deployed
Content-Security-Policyheader setsconnect-src 'self'. Even if code attempted an outbound request, the browser would refuse it. - Runtime lock. While a processing task is active, the page's own network primitives are intercepted and reject. This is the behaviour the automated browser test asserts.
What we deliberately do not promise
- We do not promise a file will reach an exact size. Compression depends on the content. When a target cannot be reached without crossing the quality floor, FileSlimmer says so and returns the best result it reached.
- We do not promise every file will process on every device. Browser memory is finite, and a large file on a phone may be refused before it can crash the tab. The device limits are applied before your file is read, not after.
- We do not promise a performance score. Lighthouse and Core Web Vitals depend on the device and the network.
- We do not promise anything about your extensions, your operating system or your network. See the privacy statement.
Destructive operations are labelled
Some operations lose information by nature. Rasterised PDF compression removes searchable text, links, forms, annotations, layers, accessibility structure and digital signatures. Editing a signed PDF invalidates its signature. Removing metadata does not remove information visible in the image itself. FileSlimmer warns before each of these rather than after.
Open source
FileSlimmer is built on open-source components. Their licences and source repositories are listed on the open-source notices page, including the relinking offer for the LGPL components.
This document is published by ZENIT GROUP S.A.S., Cali, Valle del Cauca, Colombia.