Your document stays yours
Watermarkit is designed so document contents never need to leave your browser.
Local-only processing
Files are decoded, previewed, watermarked, and exported in browser memory. Watermarkit has no document upload endpoint, account system, database, remote storage, analytics, or session replay in the editor.
Memory and cleanup
Document bytes, file names, previews, and outputs are not written to localStorage, sessionStorage, IndexedDB, cookies, logs, or URLs. Temporary object URLs are revoked when files are removed, the workflow is reset, or the editor is closed. The browser may still manage memory and downloads according to its own behavior.
Metadata
Exports are newly encoded files, which removes most original image metadata such as EXIF GPS and camera details. We do not promise perfect metadata removal across every browser and format.
Dependencies and network boundaries
PDF, QR, and archive libraries ship with the application bundle. They do not receive document contents. Hosting infrastructure will still receive ordinary page requests, but document processing creates no upload request.
Your responsibility
Review the output before sharing it and disclose only what is necessary. Anyone with access to your device, downloads folder, browser extensions, or operating system may be outside Watermarkit’s protection boundary.