Skip to content
Vizua

Published July 11, 2026 · Updated July 17, 2026 · Rodrigo Freitas

Online Image Tools Privacy Architecture Benchmark 2026

We reviewed eight online image tools to determine whether selected files are processed locally in the browser or uploaded to a server, and how long server-processed files may be retained.

Key finding

Four of the eight services reviewed describe local browser processing. The other four describe server processing with retention ranging from deletion after compression to a maximum of 48 hours. “Server processing” is not the same as insecure processing; it means the selected file leaves the device and the provider’s security and retention controls become relevant.

Results

ToolProcessingFile retentionEvidence
Vizua Local browser Not uploaded for processing Measured + documented
Squoosh Local browser Not uploaded for processing Official documentation
TinyPNG Server Up to 48 hours Official FAQ
iLoveIMG Server Deleted within 2 hours Official legal documentation
Compressor.io Server Deleted after compression Official FAQ
ShortPixel Server Kept for 2 hours Official FAQ
CompressJPG.io Local browser Not uploaded for processing Official privacy policy
JPEGCompressor.com Local browser Not uploaded for processing Official privacy policy

Primary evidence

  • Vizua: An instrumented test of JPEG, PNG and WebP recorded zero non-GET requests and zero request-body bytes after file selection. Measured + documented
  • Squoosh: The official repository states that images are compressed locally and are not sent to a server. Official documentation
  • TinyPNG: The official FAQ says uploaded images may be retained for up to 48 hours. Official FAQ
  • iLoveIMG: The legal documentation says uploaded files are processed on its servers and deleted within two hours. Official legal documentation
  • Compressor.io: The official FAQ says uploaded images are automatically deleted after compression. Official FAQ
  • ShortPixel: The official FAQ says optimized images are kept on its servers for two hours. Official FAQ
  • CompressJPG.io: The privacy policy describes local browser processing. Official privacy policy
  • JPEGCompressor.com: The privacy policy says files remain on the user’s device. Official privacy policy

Methodology

  1. Use only a provider’s official product, FAQ, privacy, legal or technical documentation.
  2. Record the processing architecture and the most specific retention statement available.
  3. Separate observed behavior from provider-declared behavior.
  4. Use neutral language: local processing minimizes file transfer; server processing may still use encryption and controlled retention.
  5. Date every observation and preserve the source URL in downloadable data.

Download the data

Limitations

Except for Vizua, this version classifies providers from their own current documentation rather than packet-level tests. Policies and implementations can change. A future release may add controlled network captures, compression ratio, visual-quality metrics and processing time with common licensed fixtures.

Citation and corrections

Suggested citation: “Rodrigo Freitas, Online Image Tools Privacy Architecture Benchmark 2026, Vizua, July 11, 2026.” Send corrections or reproduction notes to contato@vizua.io.