LOCAL FIRST

Privacy & file processing.

Updated 11 October 2026. This describes PSDFlow local processing and the connected account services.

See the service scope and terms, or choose a PSD tool.

Your files stay on your device

PSD files, font files, replacement text and output images are processed in browser memory by a dedicated Worker. The tool does not send them to a server or write changes to your original PSD. Download saves a PNG through your browser. Closing the page releases its working document; keep the original file and any results you need.

Local processing still needs website resources

Your browser downloads HTML, scripts, images, local font assets and the WebAssembly engine. Trying an example downloads that public PSD from this site. The tool does not load third-party analytics or font services. Account and sign-in screens load the official Google Identity Services script to display the optional Google button. Cloudflare serves the website and may process ordinary request data such as an IP address. Account and payment requests use HTTPS.

Accounts, payments and task identifiers

Email registration and sign-in use the shared Auth service with a PSDFlow-specific account scope. Passwords, verification codes and Google credentials are sent only for authentication; the product does not log them. Access and refresh tokens stay encrypted in the product database and are represented by a Secure, HttpOnly session cookie in your browser. Google sign-in is optional and new accounts require your agreement to these terms.

The Commerce service stores orders, payment events, subscriptions, entitlements, usage and redemption records. Checkout is hosted by the payment provider. PSDFlow does not receive card details. The product database stores the verified account ID, product scope, a SHA-256 fingerprint of the original PSD, task and delivery status, and checkout identifiers. The fingerprint lets the same free task be recognized across sign-ins; it does not contain the PSD bytes, filename, font or replacement text.

Task events

Task-view, selection, open, applied-edit, ready-PNG, download-click and fixed failure-code events are held in page memory only. They contain a task number, task type, example flag, step and coarse elapsed-time band. They do not contain filenames, text, font names, file bytes, images or raw error messages. These in-memory UI events are not sent anywhere or used to identify you across visits. Separate server logs contain necessary task/checkout identifiers, operation status and fixed failure codes; they exclude passwords, tokens, file contents, fonts and replacement text.

Example activity is marked separately from your own file activity. A download click means a click, not proof that the file reached your disk. Closing the page clears the event record. Aggregated traffic and task analytics are not connected.

Public examples and links

Example PSDs and PNGs are public assets with their sources and licenses listed alongside them. External links lead to other sites with their own policies. For account or privacy questions, contact thunderlake.zz@gmail.com. Any hosting or analytics changes will be documented before public launch.