Privacy and security
Your video or audio stays on your device
The subtitle generator reads your file and makes the subtitles inside your browser tab. The site has no way to receive the file: there is no upload endpoint, and the page may connect only to this site. Below is what your browser downloads, what it keeps, what the host still sees, and how to check it yourself.
- The video or audio file you add
- The sound the page reads from it
- The language and model you choose
- The subtitles and your edits
- The SRT and VTT files you download
- The video or audio
- Its file name
- Its metadata, such as the recording date or location
- The subtitles made from it, and your edits
- The language you pick
What runs where
The engine, the part that turns speech into subtitles, runs inside your browser tab. It is a WebAssembly program and an open-source speech recognition model, both downloaded from this site when you add your first file. The page hands your file to the engine inside the tab, the engine hands back the subtitles, and you save them as a file on your device. What runs in your browser, step by step, is on the how it works page.
What your browser downloads, and nothing else
Opening the subtitle generator downloads the page itself, its styles, its scripts, and a few images, all from this site. When you add your first file, the page also downloads, from this site: the engine (about 1.5 to 1.6 MB, or 3.4 MB for its WebGPU build when your browser offers a usable graphics card), the media reader that reads your file's sound (about 0.3 MB), the model you picked (about 60 MB for the smaller one or about 264 MB for the larger one, in parts of at most 20 MiB), and a voice detector of under 1 MB that finds the stretches with speech. There are no fonts or scripts from other sites, no analytics, and no ads.
What stays in your browser afterwards
The model and the voice detector. Each downloaded part is checked against its SHA-256 fingerprint, and the verified parts stay in your browser's Cache Storage for this site (a store named transcription-models-v1) when the browser has room for them, so later files and later visits skip the download. The engine files sit in your browser's ordinary cache, like the page's scripts. None of these hold anything from your videos, recordings, or subtitles. To remove them, clear this site's data in your browser; the next file then downloads them again.
Your file and your subtitles are never stored. While you work, the preview plays your file from a temporary blob: link inside the open tab. The browser drops that link and the subtitles when you close the tab or press Start over. Apart from the model and the detector, the page's scripts store nothing: no cookies, no localStorage or sessionStorage, and no IndexedDB.
The page can read only the file you give it
You hand the page a file by choosing it or dropping it on the drop area. A web page cannot browse your folders: the browser gives it the one file you picked and nothing else. The page checks that the file is a video or audio file and refuses anything else with a message. The camera and the microphone are switched off for the page (see the headers below), so it works on files only, never on live sound.
What the browser enforces
The site sends security headers with every page, and your browser enforces them no matter what the page's scripts try to do. In plain language:
| Header | What it does |
|---|---|
Content-Security-Policy: connect-src 'self' | The page's scripts may connect only to this site. The browser blocks a request to any other server. |
Content-Security-Policy: form-action 'self' | A form on the page can submit only to this site. |
Content-Security-Policy: script-src 'self' 'wasm-unsafe-eval' | Only scripts served by this site run. The second value lets the browser compile WebAssembly, the format the transcription engine is built in. |
Content-Security-Policy: media-src 'self' blob: | Video and audio play only from this site or from inside your tab. The preview plays your own file from a blob: link that exists only in the open tab. |
Permissions-Policy: camera=(), microphone=(), geolocation=() | The camera, the microphone, and location are switched off for the page. It cannot even ask for them: the tool takes files, never live sound. |
Content-Security-Policy: frame-ancestors 'none' and X-Frame-Options: DENY | No other site can show this page inside a frame, which blocks clickjacking (a fake page laid over the real one). |
Cross-Origin-Opener-Policy and Cross-Origin-Embedder-Policy | They isolate the tab from other sites. Browsers require this isolation before a page may share memory between threads, which the engine's WebAssembly version is designed to use. |
Behind the headers, the site is a set of static files on a content delivery network. No server program of ours runs behind it, so there is no endpoint that could accept a file even if the page tried to send one.
Check it yourself
Your browser's developer tools list every request a page makes, so you can check this on your own computer (Chrome's Network panel guide explains the panel):
- Open the subtitle generator on a computer and press F12 (or Cmd+Option+I on a Mac) to open developer tools, then choose the Network tab. In Safari, first turn on the developer features in Settings, Advanced.
- Reload the page. You should see the page, its styles, scripts, and images, all from subtitle-generator.online.
- Add a short video or audio file. The first time, new rows appear for the engine, the media reader, and the parts of the model, all from subtitle-generator.online. On a later visit the model's parts come from your browser's storage, so only a few small files that list them are requested again. Let the run finish and download the SRT: the file is made in your tab and saved from a blob: link, not fetched from any server.
- Check the Method column (if it is hidden, right-click a column header to show it). Every row should read GET or HEAD, and every address should be subtitle-generator.online. Rows starting with blob: or data: are links inside your tab, not network transfers.
An upload looks different: a request with the POST or PUT method whose size is about the size of your file, often to another domain. If you ever see one when you add a file here, something is wrong, and we want to hear about it at support@subtitle-generator.online.
What our automated test checks
An automated browser test loads a built copy of the site in Chromium, the engine behind Chrome and Edge, with the site's own security headers, and adds real files. Every change to the site runs it. Among its checks:
- Every request the page makes goes to this site, and every one is a GET or HEAD request with no body, so nothing is uploaded.
- Opening the page downloads no engine and no model: they come from this site only once you add a file.
- A short recording is turned into subtitles inside the tab, on the engine's WebAssembly build, from a WAV file, an MP4 video, and a WebM file, and the words come out as expected.
- The SRT and VTT files the page saves hold exactly the cues shown on the page, edits included, and nothing else.
- Cancel stops a run, and the next file uses the model the browser already keeps, with no new download.
- With the site's own security headers in force, the browser reports no blocked request and no policy violation.
How to check any subtitle tool the same way
The same Network tab test works on any web tool that says it does not upload your file. Open its page, clear the list, add a short test clip, and look for a POST or PUT request about the size of the clip, or a request to a domain other than the tool's own. Also look at what else loads: analytics, ad, and font requests to other domains are not your file, but each one tells another company that you visited. A tool that runs a model in your browser downloads that model first, so a large GET on the first run is expected; an upload goes the other way.
What "no upload" does not cover
- The host sees ordinary requests. Like any website's host, the hosting and delivery provider processes standard request data, such as your IP address and browser details, to serve the files and protect the site. Those requests contain nothing from your file.
- The page needs a connection to load. There is no offline mode.
- Extensions can see the page. An extension you allowed to read and change websites sees what this page shows. For a sensitive recording, use a browser profile without extensions.
- Downloads are ordinary files. Once you save a subtitle file, it follows your device's rules: a synced folder, a backup, or an email attachment takes it wherever those go.
- Your device is your own. Malware, or other people with access to your computer, are outside what any web page can control.
Privacy and trust guide
Continue exploring this topic
Related topics: Making subtitles
Make subtitles without an upload
Nothing you add leaves your device. Open the page, add a file, and watch the Network tab while it works.