How PassportPhotoBox Protects Your Photos
How browser storage and selected remote processing affect photo security, plus safe device use and vulnerability reporting.
What the public product does locally
Core editing tools work in the browser and can keep a session in browser storage. That design can reduce unnecessary transfer for ordinary crop, resize and file preparation, but it does not make every feature local. Downloaded exports and working sessions remain private only to the extent that the device, browser profile and folders are protected by the user.
Remote processing is explicit
Creative generation and the backup process for background removal can send an image to a remote processing route only when that feature is chosen or when the browser process does not finish. The site should not describe a remote route as processing that happens only on your device. If a remote transfer would be unsuitable for the file, use an editor control that runs on your device or do not use that feature.
Safe use on your device
Use a current browser and an operating system account that only you or trusted people can access. Avoid public computers for passport photos, identity documents and signatures. If a shared computer is unavoidable, clear PassportPhotoBox site data and remove the downloaded export before you leave.
Responsible disclosure
Use the Security topic on the contact page to report a suspected vulnerability. Include the page, observable behaviour and safe reproduction details, but do not publish credentials, personal data or a working exploit. A dedicated security email should be published only after it is actively monitored.