All tools

> safe

Why this is safe

Your data is nobody’s business. Not even mine.

The tools upload nothing, not to any cloud and not to my server either. PDFs, invoices, letters, images and codes are created in your tab.

bnkz.de tool Cloud no upload Your browser tab </> your file computes new PDF
  • 0files uploaded
  • 0cookies set
  • 0ads and third-party trackers

> safe --verbose

The detailed explanation: everything in detail, for you to verify

This page is the short version. In the detailed one, which is available in German only, I show you the path of your file, how an invoice, a photo and a QR code are created in your tab, a live self-test that triggers the block, and an honest look at the limits.

In detail (in German)
details > safe --verbose Data flow Self-test Documents Limits

01Where your file stays

The tool comes to you

A typical online tool sends your file to someone else’s computer, processes it there and sends the result back. Here it is built the other way around: Only the tool comes from the server. Your file stays where it is.

TypicalOnline tool with upload

your device file goes up result server

Your file is on someone else’s computer. You have to take it on trust that it is deleted there afterward.

BNKZTool in the browser

your device tool no upload bnkz.de

Your file and the result stay on your device. When you close the tab, none of it is left in the browser.

The building blocks are here tooThe libraries for PDF and QR codes are stored as a copy on bnkz.de. Nothing is loaded from Google, a font service or an ad network. So nobody there can recognize you either.
In detail (in German): The path of your file from the file dialog to the download

02What is created in your browser

The document is created in your tab

Your browser has long been a full-fledged computer: It writes PDFs, processes images, encrypts files and typesets letters. It only needs the program code, and it gets that from here. This is how every tool works:

  1. Your file or your entriesFile · form
  2. In the memory of your browserArrayBuffer
  3. The tool computespdf-lib · Canvas · WebCrypto
  4. A new file is creatednew Blob()
  5. You download itblob: address

This is created directly in your browser:

  • PDFs
  • Invoices
  • Letters
  • Images
  • QR codes and barcodes
  • ZIP archives
  • Calendar files
  1. No service that accepts filesbnkz.de consists of ready-made pages, style sheets and program code. There is no account, no database with your files or entries, and no program on the server that accepts files.
  2. Nothing is left behindThe site stores nothing of yours in your browser: no cookie, no local storage, no database. If you want to keep details for next time, for example for the next invoice, you save them as a file yourself.

This design supports more than a hundred tools, most of them in German only so far. Text recognition from scans would need a server or a very large recognition model, so it is not offered here.

In detail (in German): How an invoice, a photo and a QR code are created in your tab

A design I am proud of.
And tools I am glad to pass on: free, for everyone.

03What the browser forbids

The rule is written into every page

Every page comes with a Content Security Policy: a list of prohibitions that is enforced by your browser, not by the page. Even against my own code.

fetch() XHR WebSocket sendBeacon EventSource CSP net this page connect-src 'none'
  • connect-src 'none'No fetch, no XMLHttpRequest, no WebSocket, no EventSource, no sendBeacon. The usual ways to send data in the background are blocked, even to bnkz.de itself.
  • script-src 'self'Only program code from here. No outside script, no ad code, no tracking script from a third party.
  • img-src 'self' blob: data:Images only from here or from the memory of your browser. That way the preview shows your own file without sending it anywhere. No tracking pixel from a third party either.
  • form-actionForms do not send anywhere. The only exception is the “Suggest a tool” form, and that sends only to bnkz.de.

The rule blocks the usual ways, not every conceivable one. In the detailed explanation (in German), I list honestly which ways stay open. You can find the line itself by right-clicking the page and choosing “View page source”. It is right at the top, in the head.

> safe --selftestFor nerds: Trigger the block yourself (in German)The live self-test tries to send five times. The radar shows you every attempt that your browser blocks. In detail (in German): All rules line by line, in the exact wording

What is never sent
cannot be read by anyone along the way.

04If you do send something

Only the “Suggest a tool” form

The only thing here that deliberately transmits content is the “Suggest a tool” form, and only once you press Send: what you write into it, plus two invisible fields against spam bots. Your suggestion reaches me as an email. The email address is optional. It is there so that I can reply.

Send form email to me

05Check it yourself

Four steps, two minutes

Elements Console Network method:POST 0 requests list stays empty
  1. Press F12In Chrome, Edge and Firefox this opens the developer tools. On a Mac: Cmd + Option + I.
  2. Go to “Network”This tab lists the requests this page makes, as long as the tab is open. Leave it open.
  3. Use a toolDrag a PDF in, merge it, download the result.
  4. Look at the listYour file is not in it. Apart from the page itself you only see an anonymous page counter without a cookie (p.php). Details are in the privacy policy. Tip: Type method:POST into the filter field, and the list stays empty.
In detail (in German): Checking entirely without me, with the console, the source code and curl

06What is not in my hands

This is part of the picture too

For you to open a page, a computer has to deliver it. In doing so it sees your IP address, as with any website, and the hosting provider keeps the usual server logs. I have no control over these logs, which is why I say it here and not in the fine print.

host Server log IP address date, time requested address not in my hands

And to be honest: You can check that the code today sends no files and, except in the “Suggest a tool” form, no entries of yours. What I upload tomorrow, I cannot prove to you. That is why the check with F12 is better proof than any promise from me. You can repeat it any day.

Who is behind this site is stated in the legal notice (Impressum). What applies legally is in the privacy policy (Datenschutzerklärung).

In detail (in German): The limits, from the hosting provider to what I upload