Privacy
Your files stay on your device
A tool that finds what your files give away should not be one more place they go. hexscope reads a file in your browser, makes its clean copy there, and sends it nowhere. You do not have to take that on trust: here is how to check.
1 What happens to a file you open
- Your browser reads it into this tab. The parser, compiled from hexscope's Rust code to WebAssembly, takes it apart in a background thread of the same tab.
- The clean copy is made there too, and your browser saves it or hands it to the share sheet, as it would any download.
- When you close the tab, it is gone. Nothing of it is kept: the list of files opened lives in the tab's memory only.
There are no accounts, no cookies, no analytics and no ads. The site is a set of static files; like any website, its host sees that a browser asked for the page, and never what is opened with it.
2 Check it yourself
- Watch the network. Open your browser's developer tools (F12, or ⌥⌘I on a Mac), choose Network, then open a file. Nothing is sent: the only requests are for hexscope's own parts, the first time they are needed.
- Go offline. After one visit, turn off Wi-Fi and open a file. It works, clean copy and all — which it could not if the file went anywhere.
- Read the page's own rules. Every page is served with a Content-Security-Policy that lets it talk to its own site only (
connect-src 'self') and submit no forms (form-action 'none'). Your browser enforces it: even a mistake in hexscope could not send a file to another site.
3 Or do without the website
hexscope is open source: you can read the code that reads your file, build the site yourself, or use the command-line tool, which does the same on your own computer and a whole folder at a time.
hexscope finds what it knows how to read: where a photo was taken, who wrote a document, the text under a PDF's black boxes. It is not a virus scanner, and a clean copy removes what hexscope can name — it says what it could not remove.
Check a file Nothing leaves your browser.