Last reviewed: September 7, 2026
PrivaCanvas uses the following third-party components for on-device face detection. They are distributed under the Apache License 2.0.
The runtime and WASM files are served by PrivaCanvas. MediaPipe states that task inputs are processed on-device and are not sent to Google. The library contains performance and utilization metrics code; PrivaCanvas blocks third-party application data connections using Content Security Policy.
The active full-range BlazeFace model and the retained short-range model are licensed under Apache License 2.0 according to their official model cards.
PrivaCanvas uses these models only to locate faces for redaction. It does not perform identity recognition, surveillance, face matching, or sensitive attribute inference.
Detailed file hashes and distribution records are maintained in the project's THIRD_PARTY_NOTICES.md file.
exifr loads only after you select an image and reads that local file in the browser. PrivaCanvas does not upload the image or metadata. The editor reports only whether broad categories such as location or camera information were found; it does not display or record their values.
fflate is dynamically loaded only when you choose Download all as ZIP. PrivaCanvas does not upload the selected images, generated PNG files, or ZIP archive.