stayput-mcp
Stayput
Your files stay put.
Free, open-source image and PDF tools that run entirely in your browser. Nothing is uploaded, there are no accounts or limits, and it works offline.
Open stayput.dev · Tools · Verify the claim · How it works · MCP server · Privacy
Convert HEIC photos from an iPhone, merge, split, sign and compress PDFs, shrink images and strip GPS and EXIF data. Every tool is a static page and a bit of JavaScript and WebAssembly that does the work in your tab. There is no server that could receive your files.
Open the network tab. It stays empty.
That is the whole pitch, and you can check it in three ways:
Watch the network. Open your browser's developer tools (F12, or Cmd-Option-I on a Mac), pick the Network tab, open any tool and drop a file. You will see requests for the page's own code, the site's own decoder files on the pages that need them, and one anonymous page count. You will never see a request carrying your file, because there is nowhere for it to go. Every tool page also counts its own requests after you add files and shows you the list.
Turn the network off. Load a tool, switch to airplane mode, and use it. It keeps working, because after one visit the site is cached by a service worker and the work happens in your tab.
Read the code. This repository is the site. It builds to static HTML, CSS and JavaScript with no backend; the deploy has no server-side code at all. The privacy page lists every request the site makes.
Related MCP server: mcp-pdf-utils
Tools
Images | PDFs |
HEIC to JPG or PNG (batch, keep or drop EXIF) | |
Convert images (PNG, JPG, WebP, AVIF, JPEG XL, HEIC, SVG in; JPG, PNG, WebP out) | |
Compress PDF (lossless cleanup, image recompression, or flatten) | |
Remove EXIF and GPS data (lossless, no re-encode) | |
Crop image (ratios, exact pixels, circle) | |
EXIF viewer (location, camera, date and every field) | |
Video to GIF (MP4, MOV, WebM; trim, size, frame rate) | |
Blur or pixelate image (faces, plates, text; blur, pixelate or black box) | Sign PDF (draw or type, place on any page) |
Rotate or flip image (quarter turns, mirror, batch) | |
Video or audio to MP3 (MP4, MOV, M4A, WAV; or to WAV) | PDF to Word or text (paragraphs and headings, not layout) |
Image to text (OCR) (photos, screenshots, scans; copy or .txt) | Unlock PDF (remove a password you know, or print/copy restrictions) |
Password protect PDF (AES-256) |
Plus dedicated pages for the jobs people search for: image conversions such as HEIC to PNG, PNG to JPG, WebP to PNG, AVIF to JPG and JXL to PNG; tool presets such as JPG to PDF, PDF to JPG, Combine PDF, Resize image, Crop to circle and Remove location from photos; and guides that answer the question behind the tool ("is it safe to merge PDFs online?", "how do I remove location data from photos?").
MCP server
Stayput also ships as a local Model Context Protocol server, stayput-mcp, so an LLM client can call the same PDF and photo tools as tool calls, still with no network access and no uploads:
{ "mcpServers": { "stayput": { "command": "npx", "args": ["-y", "stayput-mcp"] } } }See mcp/README.md for the full tool list, or stayput.dev/mcp.
How it works
The site is a static Astro build: one page per tool, a shared tool shell, and a TypeScript module per tool that does the work in the tab. The MCP server (above) is the one part of this repo that does run as a local process; everything else described below is the browser-only website.
HEIC decoding: heic-to, a WebAssembly build of libheif, served by the site itself from
/vendor/(copied out of node_modules at build time byscripts/vendor.mjs). The request fetches only the decoder; no image data is sent.PDF editing: pdf-lib for merge, split, rotate, reorder, page numbers (standard fonts, nothing embedded), signature stamps, image embedding and rewriting image streams.
PDF to Word: pdf.js reads the positioned text runs;
src/lib/pdftext.tsrebuilds lines, paragraphs and headings andsrc/lib/docx.tswrites a minimal Office Open XML document with fflate. Text and structure only, no layout.PDF rendering: pdf.js (legacy build for wide browser support) on a dedicated web worker.
Image resize and encode: the canvas API, with stepped downscaling for sharp results.
Encrypted PDFs: many PDFs carry "owner" encryption with an empty user password (statements, forms with printing restrictions). pdf-lib cannot read those streams, so every PDF tool first checks the trailer for
/Encryptand, when found, runs qpdf compiled to WebAssembly (@neslinesli93/qpdf-wasm, served from/vendor/and loaded only when needed) to strip the encryption in the tab. Files with a user password prompt for it once; outputs are written without encryption. Seesrc/lib/unlock.ts.JPEG XL and AVIF decoding: the browser's own decoder when it has one (AVIF everywhere, JXL in Safari); otherwise the jSquash WebAssembly builds of libjxl and libavif, served from
/vendor/like the HEIC decoder. Tool pages that accept these formats ask the service worker to cache the decoders they may need (only JXL/AVIF decoders the browser lacks) and mark<html data-decoders="cached">when they are in, so they work offline after one visit; the service worker does not precache them for every visitor because together they are about 6 MB. Seesrc/lib/vendor.ts.Signatures: drawn on a canvas with pointer events (pressure-aware for pens) or typed in the self-hosted Caveat font, cropped to a transparent PNG and placed at preview coordinates mapped into PDF user space, page rotation included.
EXIF removal: a hand-written, lossless segment and chunk editor for JPEG, PNG and WebP in
src/lib/exif.ts. It deletes only the metadata segments and writes the untouched image data back, so the pixels are identical and the file only gets smaller. It also extracts EXIF from HEIC containers so "keep metadata" works on HEIC conversions.TIFF input: UTIF.js (
src/lib/tiff.ts), bundled and loaded only when a TIFF is dropped, since only Safari decodes TIFF natively. Images to PDF turns every page of a multi-page TIFF into a PDF page.Zip downloads: fflate in the tab when there is more than one output.
Offline: a service worker generated at build time (
src/pages/sw.js.ts) caches every tool page, andscripts/postbuild.mjswrites the list of hashed assets and fonts into it so all tool code (including the on-demand pdf-lib and pdf.js chunks) is cached on the first visit. Pages are network-first so deploys show up immediately; assets are cache-first because their names are content-hashed, and assets from earlier deploys are pruned on activation.Security headers: the site ships a strict Content-Security-Policy. Scripts may load only from the site itself and the self-hosted analytics host; no third-party CDN is involved.
connect-srcis limited the same way, so even a bug could not send a file elsewhere.Analytics: a self-hosted, cookie-free Umami counter records page views and three anonymous events (visit start, files added, tool run) with coarse buckets: tool, outcome, file count, size and duration ranges, the entry page and previous page on the site, a named referrer, the previous tool in the tab, and days-since-last-visit ranges computed from a note kept in the browser's own storage. No identifier, and never file names, types or contents. Every property is listed in
src/lib/analytics.tsand on /privacy, andtests/analytics.spec.tsfails if an event gains an unlisted property or names a file. It honours Do Not Track. The numbers are kept private and used only to decide what to build next.
There is no backend and no cookies. See /privacy for the full statement.
Development
Requirements: Node 22+.
npm install
npm run dev # http://localhost:4321
npm run build # static output in dist/
npm run check-links # fail on any broken internal link in dist/ (--external also checks outbound links)
node scripts/serve.mjs # serve dist/ locally with clean URLs and the production headers
npm run check # Astro and TypeScript checksTests
End-to-end tests drive every tool in headless Chromium with generated fixtures (JPEG with EXIF and GPS, PNG, WebP, HEIC, multi-page PDFs, plus static encrypted and offset-box PDFs under tests/fixtures/static), then check the downloaded outputs. One test also asserts the privacy claim directly: after files are added, no request leaves the page except the stubbed analytics call. The local server (scripts/serve.mjs) applies the site's production headers, so tests run under the production Content-Security-Policy and a violation shows up as a console error.
pip install pillow pillow-heif # once, for fixture generation
python3 tests/fixtures/make-fixtures.py && node tests/fixtures/make-pdf.mjs
npx playwright install chromium # once
npm run build && npm testSet PLAYWRIGHT_CHROMIUM_PATH=/path/to/chrome to use a preinstalled browser.
Social images
public/og.png and public/og/<slug>.png are rendered from the page copy by node scripts/make-og.mjs (headless Chromium). Re-run it after changing a tool's heading or tagline and commit the result.
Adding a tool
Add an entry to
src/data/tools.ts(slug, SEO copy, steps, FAQ) and a paragraph tosrc/data/engine.tssaying what actually runs in the tab. These feed the home page, footer, sitemap, service worker, structured data and social image.Create
src/pages/tools/<slug>.astrousingToolLayoutand put the option controls in theoptionsslot.Create
src/tools/<slug>.ts, callcreateShell({ process })fromsrc/lib/shell.ts, and return the output files.Add a test to
tests/tools.spec.ts, then runnode scripts/make-og.mjs.
A format-pair landing page ("WebP to PNG") is just an entry in src/data/pairs.ts; the page, its social image and its sitemap entry are generated. A preset landing page for any other tool ("JPG to PDF", "Combine PDF") is an entry in src/data/presets.ts naming the base tool and its option defaults; the base tool's option controls live in src/components/options/ so the tool page and its presets share one copy. A guide is an entry in src/data/guides.ts (sections, FAQ, the tools it points to); copy supports [text](/path) links and **bold**. Run node scripts/make-og.mjs after adding any of these.
See CONTRIBUTING.md for the ground rules, the main one being that no change may make a file leave the browser.
Support
Stayput is free and will stay free. There are no ads, no accounts and no paid tier. If it saved you a subscription and you want to say thanks, the repository has a GitHub Sponsors link; sponsorship covers the domain and nothing else.
License
MIT. See LICENSE. Third-party libraries keep their own licenses: heic-to (LGPL-3.0, loaded as a separate module at runtime), qpdf (Apache-2.0, loaded as a separate module at runtime), @jsquash/jxl and @jsquash/avif (Apache-2.0, loaded as separate modules at runtime), pdf-lib (MIT), pdf.js (Apache-2.0), fflate (MIT), UTIF.js and pako (MIT), Astro (MIT). The Caveat font in public/fonts is under the SIL Open Font License 1.1 (see public/fonts/OFL-Caveat.txt).
Related MCP Connectors
Privacy-first PDF tools over MCP: merge, split, rotate, delete, compress, protect, inspect.
Split, merge and compress PDF files locally - private by design, no uploads.
HTML and CSS to PDF MCP server with page headers, footers and page numbers. No headless browser.
Document conversion MCP server: PDF to Markdown, image OCR, spreadsheet parsing.
Related MCP Servers
- AlicenseAqualityDmaintenanceAbout MCP server for image conversion, resizing, and merging — runs locally, no uploads511 npm1MIT
- AlicenseAqualityDmaintenanceAn MCP server for local PDF manipulation including merging, splitting, rotating, watermarking, and text extraction. It works with various MCP-compatible clients and processes PDFs entirely on-device without cloud services.117 npmMIT
- AlicenseNot gradedqualityAmaintenanceA local MCP server that lets Claude, Cursor, Codex, or any MCP client work with Office documents on your Mac: evaluate spreadsheet formulas, read/write XLSX and PPTX, extract structured DOCX content, and merge/split/protect PDFs. 100% local, no network calls, no account. 14 tools.MIT
- AlicenseNot gradedqualityCmaintenanceA local MCP server that drives PDFium and pypdf to perform comprehensive PDF operations including inspection, assembly, page editing, watermarking, rendering, extraction, form filling, encryption, compression, attachments, bookmarks, and metadata management.MIT