Security & Architecture | FlamePDF

Understand how FlamePDF delivers browser-based tools, processes files locally where supported, and handles network requests.

Are files uploaded when I use FlamePDF’s local tools?

For supported local workflows, the browser processes selected file contents on your device instead of uploading them to a FlamePDF conversion server for that operation. The website still makes network requests for page resources, and optional services may make additional requests.

Architecture at a glance

Execution environment
Browser-side JavaScript; some operations use web workers. The execution path varies by tool.
Selected file handling
For supported local workflows, file contents are processed on the device and are not uploaded to a FlamePDF conversion server for that operation.
Network activity
The page loads app resources and may request model files, advertising, or analytics resources depending on the feature and live configuration.
Temporary data
A selected file may be held in browser memory while a tool runs. App resources may be cached, and an output file is created when you choose to export or download it.
Browser APIs
JavaScript is required. Some tools require WebAssembly; certain image and PDF paths use OffscreenCanvas when available and have a regular Canvas fallback in supported workflows.
Memory limits
Practical capacity depends on the browser, operating system, available memory, file format, selected tool, and other open tabs; there is no single reliable browser-wide file-size ceiling.
Input formats
Accepted formats vary by tool. Examples across the site include PDF, DOCX, XLSX, CSV, JPEG, PNG, and WebP. Check the selected tool for its supported inputs.

How file processing works

For supported local tools, file bytes are read by the browser and processed on your device using JavaScript and, where required, WebAssembly. The selected document or image is not uploaded to a FlamePDF conversion server for that operation. Tool support differs, and users should check the specific tool before relying on it.

Background removal models

The background-removal feature can fetch first-party MODNet or U2NetP model files from flamepdf.com. This model download is a network request and may use bandwidth or browser cache. The image is then evaluated locally in the browser using the downloaded model; the image pixels are not sent to a third-party model service by this workflow.

What still connects to the network

The site requests HTML, JavaScript, styles, workers, fonts, and other resources. Hosting and security infrastructure may process standard request data such as IP address, browser details, and timestamps. Optional analytics or advertising may also generate requests according to the live deployment and your consent choices.

Technical limitations and boundaries

Local processing avoids uploading supported files to a FlamePDF conversion server for that operation, but it does not remove every security or privacy risk. The browser, device, installed extensions, website code, optional network-connected features, and the downloaded output remain part of the trust boundary.

Memory and file-size limits

Processing uses browser memory and temporary working data. Some tools may decompress files, render pages into pixel buffers, or hold more than one copy at a time, so memory use can exceed the source file size. There is no single reliable 1.5–2 GB browser limit: practical limits vary with the browser, operating system, available device memory, file format, tool, and other open tabs. Large files or batches can slow down, fail, or exhaust browser memory. Try fewer files or pages, close unused tabs, or use desktop software for jobs that exceed the device’s capacity.

Browser compatibility

Use a current browser with JavaScript enabled. Some tools require WebAssembly; some image and PDF paths use OffscreenCanvas when available and provide a regular Canvas fallback in supported workflows. Requirements and fallback behavior differ by tool, so an older browser may not support every operation. Check the individual tool and update your browser if a feature is unavailable.

Temporary browser data

A browser can hold file data in memory while a tool runs and cache site resources. Exported files are saved when you choose to download or save them, and your browser or operating system controls those files. Clear browser site data and downloads from your device when needed.

Content Security Policy and verification

The policy shown on this page was checked against the production flamepdf.com response on October 2, 2026; the returned Content-Security-Policy header matched this value. This is a point-in-time check, so verify again after deployments or policy changes. The connect-src directive limits script-initiated connections to the listed sources, which include specific third-party advertising, analytics, and resource/model hosts. This is not cryptographic proof that files can never leave the device: CSP does not replace reviewing application code, allowed destinations, and observed network requests.

How to audit file-processing network requests in Chrome DevTools

Open DevTools with F12, choose Network, enable Preserve log, clear the request list, and then select a file in the tool. Review requests that begin after file selection; open an unfamiliar request and inspect its Headers and Payload. File processing can still load ordinary site resources, and the Network panel may show ads, analytics, or model downloads separately from file contents.

This optional console observer lists resource timing entries created after it is installed. It does not expose request bodies, cover every browser networking mechanism, or prove that no data was transmitted. Use the Network panel to inspect request details and treat this snippet as a navigation aid only.

(() => {
  window.__flamePdfResourceAudit?.disconnect();
  const observer = new PerformanceObserver((list) => {
    for (const entry of list.getEntries()) {
      console.log("[resource observed]", {
        url: entry.name,
        initiator: entry.initiatorType,
        startTimeMs: Math.round(entry.startTime),
      });
    }
  });
  window.__flamePdfResourceAudit = observer;
  observer.observe({ type: "resource" });
  console.info("Resource observer active. Select a file and review newly observed resources.");
  return observer;
})();

Content-Security-Policy configured for this build

The policy below is configured for this build. Verify the actual Content-Security-Policy response header after deployment, because hosting settings can change the live policy.

Content-Security-Policy: default-src 'self'; script-src 'self' 'unsafe-inline' 'wasm-unsafe-eval' https://pagead2.googlesyndication.com https://googleads.g.doubleclick.net https://static.cloudflareinsights.com https://ep2.adtrafficquality.google; worker-src 'self' blob:; connect-src 'self' blob: https://pagead2.googlesyndication.com https://googleads.g.doubleclick.net https://cloudflareinsights.com https://ep1.adtrafficquality.google; frame-src 'self' https://googleads.g.doubleclick.net https://tpc.googlesyndication.com https://ep2.adtrafficquality.google https://www.google.com/recaptcha/; style-src 'self' 'unsafe-inline'; img-src 'self' data: blob: https://pagead2.googlesyndication.com https://googleads.g.doubleclick.net https://ep1.adtrafficquality.google; font-src 'self' data:; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'none'

On Windows PowerShell, check the current production response with curl.exe -sS -D - -o NUL https://flamepdf.com/ and compare the Content-Security-Policy line.