Language

Image

How to check browser processing in the Network panel

You can inspect a processing session rather than relying on a privacy label. Start with a non-sensitive sample and record what the page requests while selecting, converting and downloading it.

Record the complete session

Open browser developer tools before starting. In Chrome, use the Network panel, leave recording enabled and select All so filters do not hide request types. Reload the tool page to include its initial assets, then keep the panel open throughout the task.

  1. Convert a non-sensitive PNG or use the tool’s sample.
  2. Inspect the network log after file selection, conversion and download.
  3. Repeat with a validation error and, for HEIC, with its decoder loading for the first time.

Reference: Chrome DevTools: inspect network activity

Inspect requests, not just the request count

Open each relevant request and check its full URL, method, initiator and any request payload. A JavaScript or WebAssembly file downloaded from the site supplies processing code; it is not the selected photo being uploaded. File content could appear in a request body or encoded data, so the method or filename alone is not sufficient evidence.

Reference: Chrome DevTools: request details

Account for analytics separately

Production pages load Google Analytics for visit measurement. Those requests mean the page is not network-silent. The site’s analytics initializer uses the canonical page URL and does not intentionally add workspace files or text to the data layer. Inspect the payloads visible in your session instead of assuming that every third-party request is a conversion upload—or that every request is harmless.

State what your check establishes

A useful observation is specific: “During this PNG conversion, I saw asset and analytics requests and did not find the selected file in request payloads.” That is evidence about the observed session, not proof covering every input, browser extension, future deployment or hidden environment condition. Testing after code changes and across success and error paths gives a more useful record. Do not share an unredacted network archive if it contains identifiers, cookies or sensitive request data.

Use the tools