Blog

Personal data rules before using a browser upload tool

A practical privacy pass for files, screenshots, receipts, and forms before they enter any web utility.

Published: 2026-08-10 · Updated: 2026-09-16

Personal data rules before using a browser upload tool illustration
A practical privacy pass for files, screenshots, receipts, and forms before they enter any web utility.

Key points

  • Scan visible names and numbers
  • Remove screenshots that reveal accounts
  • Use trusted networks for sensitive uploads

Once a file is uploaded, whatever was in it has been shared, including the parts you did not think about. The visible content is usually fine; it is the corner of the screenshot, the fourth column of the spreadsheet, and the invisible fields inside the file that produce the surprises. This is a reading pass over your own material before it leaves the device, and it takes a minute per file.

Read the file as a stranger would

Open it and go looking specifically for identifiers rather than for content: full names, dates of birth, account and card numbers, addresses, phone numbers, employee or student numbers, registration plates, signatures. Read the headers and footers, which is where document templates put the name of the organisation and often the name of the person who created the file, and go through the opening and closing pages properly rather than skimming.

Then look at what identifies other people. A group photo, a message thread showing somebody else contact details, a shared document with a list of names in the sidebar. You can consent to sharing your own information and you cannot consent on behalf of the third party whose details happen to be in the same file, which is the case that most often causes trouble afterwards.

Personal data rules before using a browser upload tool illustration
Read the file as a stranger would

Handle the things that carry data without showing it

Barcodes and QR codes are readable text in an image, and cropping a receipt or a ticket while leaving the code intact hands over the reference number you were trying to hide. Cover codes with a solid block, treating them exactly as you would treat the number printed beside them. The same applies to a partially visible code, since these formats carry error correction and can often be reconstructed from a fragment.

Photographs taken on a phone frequently carry the time and the precise location at which they were shot, so a picture of a document shared to prove something also states where you were. Where the tool or the platform does not strip that, take a screenshot of the photo and upload the screenshot, which drops the original camera fields. Documents carry their own hidden fields: author, organisation, revision history, and sometimes earlier text in comments or tracked changes that never appeared in the final version.

Check the formats with places to hide things

Spreadsheets are the worst offenders. Hidden rows and columns, additional sheets, filtered-out data, cell comments, and the source range behind a chart all travel with the file even when the visible view shows only a summary. Before sharing, unhide everything, clear filters, look at every tab, and if only the summary matters, copy the values into a fresh file rather than deleting from the original.

In documents, check for content that is present but not obvious: text in a colour matching the background, a cropped image where the cropped part is still stored, a comment thread, or a redaction applied as a drawn rectangle over live text that can be moved aside or selected through. Real redaction removes the underlying content; a black shape on top of it is a cover, not a deletion. The reliable approach is to export a flattened copy and verify that the covered text can no longer be selected.

Decide whether this file should go into a web tool at all

Some files should be handled on your own machine. An identity document, a medical record, a full bank statement, a signed contract with counterparties named: for these, the right answer is software installed locally, not a page in a browser, regardless of how good the page looks. This is a small category, which is what makes the rule easy to keep.

When such a file does have to be uploaded, because a form requires it, upload it to the destination itself rather than passing it through an intermediate tool first, and do it on a network you control. Send the minimum: the single page that was asked for rather than the whole statement, with the unrelated lines removed. Afterwards, delete the trimmed working copies you made, since those are now the least protected version of the file on your device.

Before you commit

  • Scan visible names and numbers
  • Remove screenshots that reveal accounts
  • Use trusted networks for sensitive uploads

Read the file as a stranger, block out codes and strip camera fields, unhide everything in spreadsheets and flatten documents, and keep the small category of genuinely sensitive files off web tools entirely. Every item here has produced a real leak for somebody, and all of them are caught by one careful minute before the upload rather than an apology after it.

Related posts

ASKRS SHOPExplore products at ASKRS SHOP