Images & photos · Social Image Resizer
Resizing Under NDA: Why Embargoed Images Should Stay on Your Device
· Why it matters
privacy browser-processing confidentiality
A free upload-and-resize site is a third party holding your unreleased creative, with retention and access terms you did not negotiate. This post explains the exposure and how a browser-only resizer removes it entirely.
The launch image on someone else's server — the concrete exposure of uploading embargoed creative to a convenience tool
An embargoed launch image carries value before it carries traffic. Sending it to an unassessed resize service creates another copy and another organisation in the handling path. Even when the operation is routine, the transfer itself may conflict with a client workflow that approved only agency devices and named publication destinations.
Avoid turning general risk into an accusation about a particular provider. Retention, access and security depend on that service’s actual design and terms. The simpler argument for local processing is architectural: if the cropper does not receive the file on a server, that processing transfer is absent rather than merely governed by a promise.
Remote service risks must be assessed service by service, not alleged without evidence
A remote resizer could have request logs, storage, monitoring or staff-access controls, but those possibilities are not facts until investigated. A proper review asks what endpoint receives bytes, how long temporary data persists, who can access it, which jurisdiction applies and how deletion is verified.
ToolAcre avoids that application-server path for this tool. Its product record marks localProcessing true, main.js reads the File with createImageBitmap, and export bytes are built from canvas in the tab. That evidence supports “the image-processing path is local,” which is more precise than a universal statement about every browser component.
Client confidentiality and NDAs — why 'it was just a resize' does not satisfy a contract or a security review
An NDA or confidentiality policy can define approved systems regardless of how harmless the operation feels. “It was only a resize” does not change where the file travelled. The person preparing assets should follow the actual agreement, client instructions and organisational security review rather than rely on generic legal claims in a blog article.
Document the workflow before launch day: source location, approved browser, ToolAcre route, output folder and final destination. Keeping those boundaries explicit reduces the temptation to paste an unreleased asset into whichever service appears first. This article is operational guidance, not legal interpretation of a particular NDA.
The local conversion path is proven, while “nothing to delete” is too broad for the full browser environment
The inspected path validates JPEG, PNG or WebP up to 40 MB, decodes locally, frames the bitmap, encodes locally and creates Blob downloads. There is no conversion fetch call. The app also revokes object URLs through a scoped helper so generated preview references are not left indefinitely in page memory.
“Nothing to delete afterwards” is still too broad. Downloaded files remain wherever the user saves them, the original may live in a synced folder, and browser or operating-system components have their own behavior. Reloading discards the app’s in-page state, but the whole workstation remains part of the threat model.
Prove image isolation without claiming the page loads no third-party resources
Use a distinctive harmless test image and open developer tools before the real job. Clear the Network list, load the test, change crop controls and export. Search requests for the filename or recognizable file payload. Source inspection and the network guard tests then provide independent evidence about the conversion path.
Do not expect an empty Network panel. Production pages may fetch site assets and disclosed analytics resources. The privacy summary says ToolAcre analytics excludes image contents and file names, but that is different from saying no third-party script ever loads. Look specifically for image upload, request bodies and initiators tied to the operation.
Worked example: preparing embargoed hero images for four placements — the whole run without a single file leaving the laptop
For four embargoed placements, keep the master in the approved local workspace, select the needed current presets and export. Review the generated files by dimensions, then move only approved derivatives to the publishing handoff. Avoid cloud-sync folders if the project policy forbids them; the cropper cannot control where the source or downloads directory synchronises.
Record the date and route of the network check with the production procedure. If deployment or page configuration changes, repeat it. A one-time observation is evidence for that build and session, not a permanent guarantee. This discipline matches the tool’s own approach to versioned, dated platform presets.
What this does not cover — the security of your own device, cloud-sync folders and the platform you eventually post to
Local resizing does not secure a compromised laptop, malicious extension, shared downloads directory or the social destination that eventually receives the file. It also does not replace access controls on the master. Those layers remain the organisation’s responsibility and should be reviewed according to the embargo’s actual sensitivity.
The boundary is nevertheless valuable: removing an unnecessary processing server removes one transfer and one party from the path. Phrase the benefit exactly that way. Absolute privacy language obscures remaining risks, while a verified local processing statement helps a security reviewer understand what changed.
Takeaway: keep unreleased work local — the Social Image Resizer crops and resizes in your browser, so there is no third party to trust
Keep unreleased work local when the contract and threat model call for it, and prove the route rather than trusting a badge. ToolAcre’s code, product configuration and network-isolation test align on local image framing. A runtime Network-panel observation can confirm the deployed path for a harmless marker file.
The result is not “zero risk.” It is a narrower, auditable workflow: approved source, browser-local crop and encode, controlled download and authorised publication destination. That is the level of precision confidential creative deserves, and it avoids turning convenience into an undocumented disclosure.