SSkrubly
en▼Open a tool
← All articles

October 3, 2026 · 8 min read

Free File Tools: What to Verify Before You Upload Anything

Padlock icons prove nothing. Here are the signals that do, the test that settles it in two minutes, and the same checklist turned on Skrubly itself.

A checklist being applied to a free online file tool

Free file tools are a crowded corner of the internet, and almost everything that looks reassuring is decoration. Padlock icons. The word "secure". A confident banner promising files are deleted after an hour. All of it is text somebody typed. Here is a checklist built only out of things you can verify, in order of how much they tell you.

1. Find out whether the file is uploaded at all

First question, because it makes most of the others moot. If the file never leaves your device, retention policies and breach risk simply do not apply to it. Two ways to find out, neither needing any technical background.

This is the strongest item on the list by miles, because it is a measurement, not a promise. Any site can claim anything. Not every site keeps working with the plug pulled.

2. Read how precisely the site describes itself

What you readWhat it tells you
"Processed in your browser, never uploaded"A specific, falsifiable claim. Go and test it.
"Secure" and "private", no mechanism namedNothing. That is a feeling, not an architecture.
"Encrypted connection"Only that the upload is protected in transit. Says nothing about what happens on arrival.
"Files deleted after 1 hour"Honest about uploading. Now it is down to trusting the operator.
"We collect nothing" / "100% anonymous"A red flag. Every website processes some technical data. Overclaiming makes the rest unreliable.
No statement at all about where files goAssume uploaded, and assume nobody thought about it.

Precision is the tell. A site that says which tools are local and which are not is making a claim it has to stand behind. A site that just says private, secure and safe, with no mechanism anywhere, is writing copy.

3. Check who is behind it

4. Watch the behaviour, not the branding

5. Match the tool to the stakes

The sensible position is not "never upload anything". It is noticing which pile a file is in. For a meme, use whatever works. For a passport scan, a signed contract, a medical letter, a photo of a child, or anything your employer treats as confidential, hold out for a tool that never receives the file — or use desktop software you already have.

Clean a file locally, then kill your wi-fi and do it again.

Open the Metadata Cleaner

The checklist, turned on Skrubly

Publishing a checklist and dodging it would be poor form. So, point by point.

We are not going to tell you this is the safest tool on the internet, or make claims about anyone else's. Structurally, an upload-based tool has to put your file on a computer you do not control, for a period its policy defines — which may be entirely fine. Read the policy of whatever you use. Then pull the plug and watch, because that is the part nobody can write their way around.

The architecture behind all of this, explained properly.

Browser-based vs upload-based