Privacy policy
UPDATED 10 SEP 2026Files you process
The files you select stay on your device. They are read into browser memory, processed locally, and offered back as a download. At no point are they transmitted. Close the tab and the memory is released.
Check it yourself
You do not have to take any of this on trust, and the page will help you check. The status strip under every tool ends with a live count of the network requests this page has made, split into this origin and everything else — it is read from the browser's own resource timeline on your device, not asserted by us, and it is the same number you will see if you open DevTools and look at the Network panel. On most pages that count will not read zero off-origin, and we would rather explain the number than hide it: the two off-origin requests are Google Analytics, described below, which loads once when the page opens and is configured to run without cookies or storage. What matters is what happens next. Open Network, drop a file into a tool, and run it: you will see the engine fetched from this origin the first time and nothing after it — the count stops moving, because no request carries your file anywhere. Two honest limits on that counter, so you know what it does not cover. It says REQUESTS, not bytes sent: the browser tells a page how many bytes it received and nothing whatever about what a request body contained, so a page printing “0 bytes sent” as a measured fact would be claiming something the browser never told it. And it can only see what this document requested — a request made inside a Web Worker, a WebSocket, or a beacon fired as you navigate away does not appear in a document's resource timeline. Your own Network panel has neither limit, which is why it is the check we point you at rather than the one we print.
Cookies and browser storage
This site sets no cookies: not Transmute's own, and not Google Analytics', which is configured to run without cookies or any other browser storage. Two things do get stored in your browser, and neither is about you or about a file you processed. One is a single localStorage key, transmute-recent-outputs, which remembers the name, size and tool of your last 8 downloads so the Recent Output list can show them — metadata only, never file contents, and it never leaves your browser. The other is a copy of the site's own code: the HTML, scripts, styles and fonts that draw a page, kept so a page opens quickly and, where the browser supports it, without waiting on the network. That copy is code this site published, not anything you brought to it. There is one exception, and it is brief: if you share a file to Transmute from your phone's share sheet, that file is held in the same store for the single navigation it takes to hand it to the page, which deletes it on arrival — it is the only way a shared file can survive the jump from the share sheet to a page that was not yet open, and nothing else you open is ever written there. The engines listed under External resources are deliberately outside it — none of them is fetched in the background, and none is written to storage for later use except at your explicit request, one named engine at a time, with its size shown before the download starts. Clearing site data removes all of it.
Analytics
Google Analytics counts aggregate traffic — page views and which tools get used. It is the one third-party script the site loads, and it stores nothing in your browser: no cookies, no identifier that survives the visit, which also means it cannot recognise you when you come back. Nothing about the files you process is ever recorded.
Advertising
Transmute carries no advertising, and no ad network is loaded on any page.
External resources
A few tools fetch a library the first time you use them, and every one of those files comes from this domain rather than a third-party CDN — so opening a tool hands nobody else your IP address. That list is the FFmpeg.wasm video engine, the MP3 encoder, the HEIC decoder for iPhone photos, qpdf — a 2.3 MB WebAssembly module, served as /qpdf.js and /qpdf.wasm, that only the four PDF security tools use: password protection, unlocking, permissions and repair — and, since September 2026, three more: the barcode reader behind the QR code reader, served as /zxing_reader.wasm (1,093,289 bytes), the archive reader behind the archive extractor, served as /libarchive.wasm (613,235 bytes), and the PNG optimiser behind the PNG compressor, served as /squoosh_oxipng_bg.wasm (164,172 bytes). The eighth is the newest and by some way the largest of the small ones: the OCR engine behind Image to Text, served from /tesseract/ as five files totalling 5,088,998 bytes — the library, its worker, the WebAssembly core and its binary, and eng.traineddata.gz, the English language model. None of the eight is fetched when you open the page. Each waits until a tool actually needs it: FFmpeg for a format your browser cannot decode on its own, the MP3 encoder for the first MP3 written, the HEIC decoder for the first iPhone photo opened, qpdf the first time one of those PDF tools actually reads a file, the barcode reader on the first scan, the archive reader on the first archive, the PNG optimiser on the first PNG you compress, the OCR engine on the first image you read text out of. Asking for one of them to be kept for offline use is the only other moment any of them is fetched, and that is a request you make by name — see Cookies and browser storage above. The barcode reader, the archive reader and the OCR engine are worth one more sentence, because they are the libraries here that would have broken the promise above on their own: both npm packages are published expecting to pull their WebAssembly from a public CDN — the barcode one has jsDelivr's address compiled into its loader — and both are wired here to the same-origin paths named above instead, so that address is never contacted and never even constructed. The OCR engine is the starkest case of the three: left alone it fetches its language model from a public CDN and its WebAssembly core from another, so all four of its paths are overridden here and it is pointed at /tesseract/ instead. The PNG optimiser names no CDN anywhere, but it is not a lucky default either: its loader looks for the WebAssembly beside the worker script that runs it, which is an address this site does not serve, so the same-origin path above is passed to it explicitly. The other PDF tools pull no WebAssembly engine at all — the 10 MB one they used to download has been removed, and what replaced it is ordinary JavaScript, served from here like everything else. Every font is self-hosted too, including the Markdown to PDF tool's print typefaces. Beyond the analytics described above, the site makes no third-party requests at all — and nothing it fetches ever carries your file data.
Children's privacy
Transmute does not knowingly collect personal information from children under 13. The site is a general-purpose utility and requires no account or personal data entry.
Changes to this policy
This policy may be updated from time to time. Any change is reflected on this page with a new date.
Questions about this policy? Reach the maintainer at ishank.dev.