Local-first: your file never leaves your device
The checker and every free tool run in your browser. How that is enforced, what does reach the internet (map tiles, and the forest map when you ask for it), and how to switch even that off.
Supplier plot files are personal and commercial data: producer names, the location of their land. Uploading them to check them is a risk you should not have to take. The checker does not ask you to.
How it works
The rules, the parser, the geometry and the report generator are all part of the page. When you open a file, it is read by your browser and checked in a background worker on your device. There is no server-side check to send it to.
How that is enforced
- The browser enforces it. The site's Content Security Policy lists the addresses the page may connect to: this site, the map tile providers, the EU's forest map server and the tree cover loss map server, nothing that accepts uploaded data. A script that tried to send your file anywhere else would be blocked by the browser.
- Tests enforce it. Automated tests load files, fix them, convert them and export them, while recording every network request, and fail if any request carries file content.
- Nothing is stored. The file is kept in the page's memory. Close the tab and it is gone.
What does reach the internet
The street and satellite maps are drawn from image tiles fetched from third-party tile servers (OpenFreeMap, and ESA WorldCover's Sentinel-2 mosaic served by VITO, and NASA's Blue Marble for the world view). A tile request contains no file content, but it does reveal which area of the world is on your screen. If that matters, choose the Plain basemap: it loads nothing at all.
The forest check and the Forest 2020 and Loss since 2021 map layers read two maps, and only when you ask: the European Commission's forest map from the Joint Research Centre's server, and the tree cover loss map from Global Forest Watch's tile server (run by the World Resources Institute). The check asks both for fixed squares of about 10 km around your plots, never the plots themselves, and the tests hold it to that. Like a tile, it reveals the area, not the file.
When you ask for the PDF check report, the page asks our server one question first: does your plan include it. The question carries your sign-in cookie and nothing else, no file content and no plot. The report itself is still made in your browser.
When you save something
With an account, a file reaches our servers in three cases only, and all are deliberate:
- You save it to a project. The first time, the app asks you to confirm. The file is encrypted before it is stored, in the EU, and you can delete it at any time.
- A supplier sends it to you through an upload link. The supplier checks it in their browser first; it is sent only when they press Send.
- Your software or AI assistant sends it to the API or the hosted MCP server, with your API key. It is processed in memory to answer that request and not stored or logged, unless the request saves it to a project.
The command-line tool and its local MCP server run on your own computer and send nothing, like the checker.
A report link shares the result of a check, not the file. The free checker works exactly as before: nothing on it uploads anything.