privacy

What Happens to Your Photos in Browser-Based Editors

Pixlr, BeFunky, Photopea, and similar web editors let you upload raw photos directly in the browser. Here's where those files actually go and what the terms permit.

Browser-based photo editors occupy a convenient middle ground: more powerful than a phone app, no installation required, free or nearly free to use. Photopea handles layered PSD files. Pixlr handles RAW formats. BeFunky is aimed at marketing graphics. Adobe Express brings cloud features without requiring a Creative Cloud subscription.

What these tools have in common — beyond their in-browser operation — is that using them typically involves uploading your photos to servers you don’t control, often without a clear understanding of what happens to those files after the editing session ends.

This matters more than it might initially seem. Browser-based editors are frequently used for photos you’re actively working with: real documents, fresh personal photos, work-in-progress creative projects, images you haven’t yet compressed or stripped of metadata. The files you upload to a browser editor are often higher-resolution and more data-rich than what you’d post to social media.


How Browser Editors Actually Handle Your Files

There’s meaningful variation between tools, and understanding the technical model matters.

Truly client-side processing

Some browser-based editors process images entirely in your browser, using JavaScript and WebAssembly, without uploading anything to a server. Photopea is the most prominent example: it’s a remarkably capable photo editor that runs the entire application — including RAW decoding and PSD layer processing — in the browser tab. Your files never leave your device.

You can verify this with your browser’s network inspector (F12 → Network tab): upload a photo to Photopea and watch the network tab. You’ll see no upload request for the photo content itself.

This model has real privacy benefits. If nothing leaves your browser, nothing can be logged, retained, or breached server-side. The trade-off is that your device is doing all the computational work, and complex operations on large files can be slow on older hardware.

Hybrid processing

Most browser editors use a hybrid model: the interface runs in the browser, but certain operations — applying filters, AI-powered features, format conversion — involve uploading the file (or a processed version) to the provider’s servers.

Adobe Express’s free tier is a well-documented example. Basic editing runs locally, but AI features like “Generative Fill” or “Remove Background” send the image to Adobe’s servers for processing. You can use Express without triggering any server upload by avoiding those features, but the distinction isn’t clearly marked in the interface.

Pixlr’s AI tools — Background Remover, AI Enhance, AI Upscaler — explicitly require server processing. When you use them, your photo is uploaded. When you don’t, basic operations appear to stay local, though Pixlr’s network traffic in the background is less clearly documented than Photopea’s.

Full cloud processing

Some tools upload your file immediately on selection, before you’ve applied any edits. BeFunky’s platform uploads to its servers when you open a file in the editor. Canva uploads files to its cloud on import. Tools that offer “recent files” or session persistence across browser restarts are almost certainly storing files server-side, since the browser can’t hold the file between sessions without cloud infrastructure.


What the Terms Say About Your Uploaded Photos

Terms of service for browser editors vary, but several common patterns appear across the category.

Licence grants

Most tools that offer any cloud storage, cloud processing, or AI features include a content licence in their terms. This licence grants the service a right to use your uploaded content for operating and improving the service. The scope varies:

  • Pixlr’s terms grant “a non-exclusive, worldwide, royalty-free, sub-licensable and transferable licence to use, reproduce, distribute, prepare derivative works of, display, and perform the Content.”
  • BeFunky’s terms include a broad licence for “hosting, storing, reproducing, modifying, creating derivative works.” The licence is perpetual for content stored on BeFunky’s servers.
  • Adobe Express operates under Adobe’s general content licence, which was revised in 2023 and again in 2024 following public controversy. Adobe’s current terms state that they do not use content submitted through consumer tools to train AI models, and do not acquire ownership of your content. This is notably more restrictive than earlier terms, and Adobe added explicit opt-outs for AI training.

The presence of a broad licence doesn’t necessarily mean your photos will be used as training data — but it means they could be, within the scope of the licence, unless the company makes a more specific commitment.

Data retention

How long do servers hold uploaded files after your editing session ends?

Photopea doesn’t retain files (nothing is uploaded). Pixlr’s privacy policy is ambiguous about retention duration for files used in AI features. BeFunky states it retains cloud-stored files for as long as your account is active or until you delete them. Adobe’s cloud features are governed by the same 30-day deletion policy as Adobe Creative Cloud.

Many browser editors offer no user account at all — files are processed and the session ends. In these cases, server-side retention may be brief (minutes or hours) or nonexistent if processing is truly local. But “brief retention” is not the same as “no retention,” and files sitting on a server for any duration are potentially accessible in ways local files are not.

GDPR compliance and data rights

EU-based users have rights under GDPR to access, delete, and object to processing of their personal data. For photo files that include personal information (images of people, documents with personal details), these rights apply.

Exercising them with browser-based editors is often difficult in practice. Services that don’t require account creation don’t have a mechanism to associate uploaded files with an identity, which means they can’t meaningfully respond to a deletion request for specific files. Services that do require accounts should have a clear process for data deletion — but the process varies in quality.


The Metadata Problem

Photos uploaded to browser editors often contain EXIF metadata — GPS coordinates, device model, timestamp, camera settings. This metadata is part of the file and is uploaded along with the image.

Some editors strip metadata as part of the processing pipeline; others preserve it. Either way, the metadata was in the file when it was uploaded, and even if the server strips it before delivering the processed version back to you, the upload event itself transmitted that metadata.

For personal photos that include location data, this means a browser editor’s server — even one that doesn’t store your photos — has, at the moment of upload, received your device’s GPS coordinates, timestamp, and potentially device identifier.

If you regularly upload personal photos to browser-based editors, using a metadata stripping tool first is worth considering. Tools like ExifTool, Metapho (iOS), or in-browser metadata viewers let you review and strip EXIF data before uploading. This is a simple, one-time operation that prevents location data from leaving your device in the upload.


The AI Feature Trade-Off

The most significant privacy boundary in browser editors is the line between basic editing (local processing) and AI-enhanced features (server processing).

Background removal, subject selection, AI upscaling, face enhancement, generative fill, smart crop — these are the features that have made browser editors dramatically more useful in the past few years. They’re also the features most likely to require server-side processing and, in many cases, to be explicitly excluded from no-AI-training commitments.

The privacy implication isn’t that using these features is always wrong. It’s that you should know where the boundary is in each tool and make a conscious decision about which photos go through which features.

Using Photopea’s local processing for personal photos and Canva’s AI background removal for a marketing graphic you don’t mind uploading are both reasonable choices — but they’re different choices with different data implications.


How to Choose a Browser Editor With Privacy in Mind

Photopea is the clear winner on privacy: genuinely client-side, no account required, no file uploads. It handles the file formats professionals use and is capable enough for most editing tasks. Its limitation is performance on complex operations and very large files.

Adobe Express has made specific commitments about AI training that are stronger than its competitors, and Adobe is large enough that contractual violations would have legal consequences. The AI features require uploads, but the commitment not to train on user content is explicit.

Pixlr is capable and convenient, but the licence grant is broad and the data practices for AI features are less clearly documented. For personal photos, the AI features are worth avoiding.

BeFunky retains files in its cloud storage by default if you use the cloud project feature. Using it in session-only mode (without saving to BeFunky cloud) limits data retention, but the initial upload still occurs.

Canva has extensive terms governing user content and explicit AI training policies that have been controversial. For personal or sensitive photos, Canva’s cloud model means your files are part of a large, persistently stored content library governed by complex terms. For marketing graphics using stock imagery or original graphics you don’t mind uploading, it’s a different calculation.


Where to Store Photos You Edit

After editing personal photos in a browser tool, where you save the result matters as much as which tool you used.

Saving directly from a browser editor back to the editor’s cloud (Canva’s cloud, BeFunky’s project storage, Adobe cloud) creates persistent server-side storage under that service’s terms. Saving to your local device and then to a separate storage service of your choice gives you more control over where edited versions end up and under what terms they’re retained.

If you’re using a privacy-focused personal storage service that explicitly commits not to use your content for AI training, saving your edited photos there rather than back to the editing tool’s cloud is a straightforward way to keep your content under consistent terms.


The Practical Summary

Not all browser editors are the same. The distinction between a tool that processes entirely in your browser and one that uploads your photo to a server is significant — and it’s often not visible from the interface.

Before uploading a photo to a browser-based editor — particularly one that contains sensitive personal information, location metadata, or images of other people — it’s worth spending two minutes checking whether the specific feature you’re using requires a server upload, what the service’s terms say about how uploaded content can be used, and where you’ll store the result.

That’s not a reason to avoid browser-based editors. It’s a reason to use them with your eyes open.

Your memories deserve better than an ad platform.

Try daftei free →
← All posts