Why browser-only processing is different
Most "free" privacy and PDF tools online send your file to a server, do the work there, and ask you to trust them. Today's Tasks doesn't have a server in the loop. Here's what that means β and how to verify it yourself.
1. How most cloud PDF / privacy tools work
file copied here
on their machines
trust they delete it
Even reputable tools advertise that they "automatically delete files after 2 hours". You're being asked to trust that promise. For most documents that's fine. For a contract, a medical record, a tax return, or a confidential settlement β it shouldn't be.
2. How Today's Tasks tools work
stays on your device
processes it locally
stays on your device
Every privacy tool on this site is built with browser-native JavaScript (and where needed, WebAssembly). The file you pick is read by your browser, processed by your browser, and the result is written back to your browser. No network request ever carries your file.
3. Who needs browser-only processing?
Lawyers & paralegals
Attorney-client privilege is broken the moment a draft contract is uploaded to a third-party server.
Doctors & clinics
HIPAA, GDPR, and patient confidentiality apply even when a tool promises 2-hour deletion.
Accountants & auditors
Client tax returns, bank statements, and ledgers don't belong on a free tool's servers, ever.
Journalists & activists
Source documents, leaked materials, and case files require zero-server handling β not "we'll delete it later".
4. Verify it yourself in 60 seconds
- Open a Today's Tasks tool β try Document Redactor or Password Generator.
- Open DevTools. Press
F12(orββ₯Ion Mac), then click the Network tab. Reload the page to start clean. - Use the tool. Type, paste, generate, redact β whatever the tool does. Now look at the Network panel.
- Count outbound requests carrying your input. You'll find: zero. The only network requests are for the page itself, the CSS, and (where applicable) an anonymous k-hash lookup for breach checks.
You can do this test on any tool on this site, any time. We don't get to fake the Network panel.
5. What you should actually look for in the Network panel
“Count the requests” is the short version. The longer version is worth knowing, because it is the difference between checking and assuming.
With the Network tab open and the page reloaded, use the tool β paste text into the Document Redactor, generate a password, encrypt a secret. Then read the list. Requests for the page itself, the stylesheet, the fonts and the ad script will be there; those are the page loading, and they carry nothing of yours. What you are looking for is a request that appears at the moment you acted, and whose method is POST or PUT rather than GET. Click it and read the request body. If your file or your text had been uploaded, it would be sitting there in plain sight, because that is the only way it could reach a server.
There is no version of this where a tool uploads your file and the Network panel stays quiet. The panel is part of your browser, not part of this site β which is exactly why it is worth more than any promise on a marketing page.
6. The two places bytes really do leave β stated plainly
A page that claims “nothing ever leaves your device” without exception is easier to write than one that is accurate. Two tools on this site do make a network call, and both say so on their own pages:
- Breach checking by password. The Data Leak Checker and the breach indicator inside the Password Generator use k-anonymity: your password is hashed in your browser and only the first five characters of that hash are sent. The service returns hundreds of candidate matches and the final comparison happens locally, in your tab. The service never sees your password, your full hash, or which entry you were checking.
- Breach checking by email address. The same tool's email mode sends your actual address to the Have I Been Pwned public API, because that lookup cannot be done anonymously. This one is a real disclosure, not a technicality β which is why the tool recommends the password mode when you want to check without revealing anything.
Everything else β redaction, metadata stripping, encryption, the vault, the calculators β makes no outbound call carrying your input at all.
Separately, and worth being straight about: the site itself carries third-party advertising and anonymous analytics, described in the privacy policy. Those are about the pages you visit, not the contents of the files you process β but “no server sees your document” and “no third party is present on the site” are different claims, and only the first one is ours to make.
7. What the tools do instead of a server
Removing the server does not remove the work; it moves it into the tab. A few concrete examples, each documented on its own tool page:
- Share a secret encrypts with AES-GCM 256 in
your browser and packs the ciphertext and its key into the part of the link after the
#β the URL fragment. Fragments are never included in network requests, so the link can travel through chat or email while the secret itself is only ever assembled again in the recipient's browser. There is no backend holding it. - Password Vault Lite derives its key from your passphrase with PBKDF2 β 250,000 iterations, SHA-256, 256-bit β and stores AES-GCM ciphertext in your browser's localStorage. Nothing is uploaded, which also means there is no company holding your passwords that could be breached. The honest flip side, stated on that page too, is that if you lose the passphrase or clear site data, nobody can recover it for you.
- The to-do list keeps your items in localStorage on the same principle: no account, no sync, and no copy of your day on anyone's server.
The trade-off is consistent: you give up cross-device sync and server-side recovery, and you get a tool where “who else can read this?” has a checkable answer rather than a promised one.