Back to blog
By Khalid DanishyarAbout 2 min readprivacyjupyterguide

What Actually Happens When You Upload an .ipynb on Jupy Tools

An honest split: converters process a file for the current request; the viewer and diff stay in your browser. What we do not do, and how to treat secrets.

How Jupyter notebook conversion and in-browser viewing differ on Jupy Tools

Privacy copy on converter sites is often wrong in both directions: either “nothing ever leaves your machine” when a download clearly required a server, or “we might keep files” with no detail. Here is the split Jupy Tools actually uses.

Two kinds of tools

Viewer and diff — /ipynb-viewer and /ipynb-diff read the notebook in your browser. You do not need a conversion API to scroll cells or compare two files. Close the tab on a lab PC when you are done.

Converters and most utilities — Word, PDF, HTML, Markdown, ZIP, merge, split, repair, compress, and similar downloads go through our conversion API so we can produce the file you asked for. The upload is processed for that request. We do not keep a notebook library of customer files. Responses use Cache-Control: no-store.

If an older paragraph on the site said a converter “never leaves your laptop,” that was a mistake. This article is the source of truth.

What “processed for this request” means in practice

  1. You choose a tool and a file.
  2. The browser sends the bytes (and the options you toggled) to produce the download.
  3. The server runs the conversion, returns the result, and does not store the notebook as an archive you could log in and retrieve later.
  4. Guest conversions are credit-limited per day. That limit is about abuse, not about keeping your homework.

We still see the bytes while the request is alive. That is unavoidable for a server conversion. If the notebook is medical, legal, or contains live credentials, do not upload it. Use local Jupyter, nbconvert, or an offline toolchain.

What we do not do

  • We do not sell notebook contents.
  • We do not train models on your uploads as a product feature.
  • We do not require an account for the standard conversion path.
  • We do not promise that a shared computer’s browser cache is empty — that is your machine.

Advertising (when enabled) is separate: cookies and ads follow the consent banner and the privacy policy. Ads are not fed your .ipynb.

How to reduce risk anyway

  1. Strip outputs before sharing: Git hygiene guide.
  2. Search the notebook for keys and tokens.
  3. Prefer the viewer when you only need to read.
  4. Prefer local nbconvert when policy forbids any upload.
  5. After a conversion on a borrowed laptop, download, then close the tab.
FAQ

FAQ: uploads and privacy

No durable archive. Converter uploads exist to produce that response. Downloads are sent with Cache-Control: no-store. Still treat any internet service as a judgment call for highly sensitive files.

The notebook viewer and the notebook diff read files in your browser. Close the tab on a shared computer when you finish.

No. Strip outputs and secrets first. Conversion is not a vault.