Your Image Never Leaves Your Device
Start from this page and your photo is processed entirely on your own device. Nothing is sent to us, and we keep nothing. The HD download you receive was made right there on your device. Free, no signup, no account.
Open the editorMost background removers — including the well-known incumbent — process every image on the vendor's servers. Your photo is uploaded, segmented in a vendor-controlled inference cluster, and downloaded back as a cutout. That round-trip is the right architecture for some use cases, but it makes the privacy story difficult: you are trusting the vendor's data-handling policy, log-retention practices, and breach posture every time you remove a background. remove-bg.io takes a different default. The cutout model loads once into your browser cache, the segmentation runs on your machine, and the result never traverses our network. This page documents exactly how that works, when the default path is bypassed, and what we explicitly don't do.
How the on-device path actually works
Three steps, all local to your browser, in the order they execute on first upload:
What we explicitly don't do
Privacy by negation — listing the things this page does not do, in plain English:
When the backend IS used (and why)
When you start from this page, your device does the work by default — but not in every case. Two situations send your image to our servers instead:
On the suspect-fallback path the source image is uploaded, but the backend discards it after the response is returned. We do not log the source image, hash it, or aggregate it with other uploads.
GDPR, CCPA, and data-residency questions
Private mode makes most of the standard data-protection questions trivial — there is nothing to share, store, or transfer cross-border for the cutout itself. The relevant facts:
Why on-device beats cloud for free-tool privacy
Almost every free background remover on the market today sends your photo to the vendor's servers. Your image is uploaded, processed there, returned as a cutout, and a record of the request is kept in their logs. Even when the privacy policy promises the upload is deleted afterwards, you are trusting that it was — not checking. Private mode removes the trust requirement entirely: your photo stays on your device, so there is no policy to audit and no log entry to hope was deleted. Ordinary laptops have been fast enough to do this work locally for years, so we made it the default — which means the privacy claim is a property of how the tool works, and something you can confirm for yourself rather than take on faith.
The costs of this approach are ours, not yours: we pay to deliver the tool, the first visit takes about a second to get ready, and because your photo stays with you we never see the results and can't tune quality from what people actually make. The benefit is that you can hand this page to a privacy-conscious client, a compliance team reviewing tooling, or a journalist investigating why background removers have become a route for image data to leak — and the answer is short, concrete, and checkable rather than something they have to take on trust. In normal use your photo never leaves your device: watch your browser's own network activity while you make a cutout and you will see the page's own files load and the usual anonymous usage events — that a cutout happened, and the file's size and type, never its contents — but the photo itself is never among them. There is no retention window to read and no policy you have to believe, because the image was never ours to keep; the two cases where the fallback does send it are set out in full earlier on this page.
For sellers, freelancers, and creators who routinely handle sensitive client material — product prototypes under NDA, unreleased fashion looks, medical or dental photography, identification documents, draft brand assets, internal pitch decks, prerelease product shots — private mode is not a marketing line, it is how this page works. There is no setting to misconfigure and no policy to take on trust, because on this path your photo never reaches us. It opens on your device, the cutout is computed there, and the file you download is the one your own machine produced. That is the inverse of the usual free-tool bargain: instead of handing your image to a company and trusting its data policy, you never hand it over at all. In practice that changes what you can use it for rather than how it feels to use: the steps are the same, and the difference is that there is nothing to ask your legal or security team about afterwards. It also means the answer to "where did that file go?" is simply that it did not go anywhere. For work covered by an NDA, a client agreement, or an internal handling rule, that is usually the difference between a tool you can use today and one you have to get approved first.
When the cloud-API path is genuinely better
Private mode is not always the right pick. Three honest cases where a hosted-API tool would serve you better:
If none of those three apply, private mode is genuinely the simplest privacy story available in this category. See /vs/remove-bg/ for the side-by-side.
Related pages on this site
Three follow-up pages that go deeper on adjacent questions:
Privacy FAQ
Open the editor — your image stays where it belongs
Free, no signup, no account. In private mode, your photo never leaves your device.
Open the editorLast verified: