What 'no upload' means for background-removal privacy
A site can load code and model files from the network while still processing your image locally. The privacy question is whether the source image or derived image data is sent away for inference.
Published
Separate network access from image transfer
The phrase 'works locally' is often misunderstood as 'the page never uses the network.' A hosted web application normally downloads HTML, JavaScript, styles, runtime files, and other assets before it can do anything.
For background-removal privacy, the important boundary is the image. A local inference flow can download the model and still keep the selected image on the device.
bgcut.dev serves application, model, and ONNX Runtime files. It does not need to send your source image to a bgcut inference backend because there is no hosted inference backend in that flow.
Data created during a local job
The browser starts with the source image bytes, decodes them into pixels, prepares model input, receives a predicted matte, composites the result, and creates the exported image.
Those intermediate values can be as sensitive as the original file. A meaningful local-processing claim covers the source image, decoded pixels, mask, and result rather than only saying the original filename is not uploaded.
bgcut's public privacy contract says those values stay on the user's machine during hosted browser inference.
Verify with a disposable image
Open your browser's Network panel before selecting a test image. Clear existing requests, process the test image, and inspect the requests that occur during the run.
Model and runtime downloads are expected. An upload containing the source image or derived image bytes to a background-removal endpoint would contradict a local-inference claim.
This check is useful when evaluating any background-removal tool, not only bgcut. It turns a marketing statement into something you can inspect.
Local inference is one privacy boundary
Local inference removes the need to send the image to an inference provider. Other parts of the device and browser still matter, including extensions, endpoint management, shared accounts, local storage, screen capture, and the destination where you later upload the result.
Treat 'no upload' as a specific data-flow property, not a complete security guarantee.