Automatic face blur that never uploads your photos
Detect faces locally, review every numbered region, add anything the detector missed, and export a privacy-ready image or batch. The detector, editor and exporter run on this device; your image pixels are never sent to a server.
Protect faces
Detect, review and obscure faces
All detections start selected. Click a box or checkbox to exclude it, move or resize any region, and add a manual region when the detector misses something.
On-device processing
🛡️
Drop photos here or click to select
JPEG, PNG, WebP, GIF, BMP, TIFF, HEIC or AVIF when supported by your browser
Select one image or a whole batch. SVG files are not accepted.
Preparing local detector…
Choose an image from the batch.
Drag a box to move it. Drag a handle to resize. Drag empty space to pan; use the wheel or zoom buttons.
Automatic detection with manual control
Face detection is a useful first pass, not proof that every person has been found. Small, rotated,
covered or partially visible faces can be missed, and a non-face can occasionally be marked. Review the
full image before export, especially when anonymity matters.
Fast scan checks the full photo once and keeps the interface responsive.
Thorough scan checks overlapping tiles and rotated views to improve the chance of finding small or sideways faces.
Manual regions let you cover anything automatic detection misses, including faces the model cannot recognize.
Face redaction is not a guarantee of anonymity. Clothing,
tattoos, surroundings, reflections, filenames and retained metadata may still identify someone.
What stays on your device
Your browser downloads a face-detection model, then runs it in a background Web Worker on this device.
Image pixels move only between memory owned by this tab. There is no upload endpoint, cloud inference or
account history, and MediaPipe telemetry is blocked inside the detector worker.
The model and processing runtime are hosted with the site and cached after first use. Once those assets
have loaded, disconnecting the network does not stop detection, editing or export.
Safer defaults for sharing
Strong pixelation with face-and-hair coverage is the default because a light blur may preserve recognizable
structure. Opaque shapes and overlays are stronger still. “Estimated head” is deliberately named: it expands
the box geometrically and is not hair segmentation.
Exports remove metadata by default, including GPS coordinates, camera identifiers and embedded thumbnails.
Compatible metadata can be retained for same-format JPEG, PNG and WebP exports, but doing so can reintroduce
identifying information and always requires an explicit opt-in.
Face blur questions
No. The detector is downloaded as a static model and runs in a Web Worker inside your browser. Your image pixels, filenames, detections and edited regions are not sent to LocalConverter, Google or another processing service.
Yes. Tiny, rotated, obscured and partially visible faces are difficult for every automatic detector. Thorough mode checks tiles and rotations, but you should still inspect the whole image and add manual regions where needed.
Strong pixelation or a fully opaque overlay generally removes more recognizable structure than a subtle blur. The safest choice depends on the image, so the tool previews every effect and asks you to review the result before export.
Yes by default. Canvas export discards metadata and the tool does not copy it back unless you explicitly enable compatible metadata preservation. That option may retain GPS, camera and author information, so leave it off for privacy-focused sharing.
Yes. Add a batch, let the browser scan each file sequentially, review flagged images, apply one effect configuration and export the results as a ZIP. Processing and ZIP creation both happen locally.