# FileStudio — Full Technical Documentation & LLM Reference Manual > FileStudio is an independent, 100% client-side document and image utility suite crafted in India. Engineered specifically for privacy-conscious individuals, legal advocates, chartered accountants, healthcare providers, and software engineers who demand absolute confidentiality for sensitive files. - Website: https://filestudios.appzyra.com/ - Primary Positioning: 100% In-Browser • 0 Bytes to Cloud • DPDP Act 2023 & GDPR by Design • Crafted in India - Target Users: Advocates, Chartered Accountants (CAs), Doctors, Financial Analysts, Engineers, Privacy Advocates - Development Ethos: Independent indie software with zero venture capital pressure, zero data harvesting, zero behavioral profiling, and zero third-party telemetry. --- ## 1. Architectural Principles & Memory Invariants ### 1.1 Zero-Egress Invariant At no point during any tool workflow does FileStudio initiate an HTTP `POST`, `PUT`, `PATCH`, or `WebSocket` payload containing user document bytes, image buffers, or file metadata. All processing takes place entirely within the sandboxed JavaScript execution context (V8 / SpiderMonkey / JavaScriptCore) running on the user's local operating system. ### 1.2 Volatile V8 RAM Execution Model FileStudio operates strictly on an in-memory lifecycle: 1. **Local File Ingestion**: Files selected via `` or Drag-and-Drop are parsed as local `File` or `Blob` handles. The browser creates an in-memory `ArrayBuffer` using the asynchronous `FileReader.readAsArrayBuffer()` API. 2. **In-RAM Processing**: Pure JavaScript and WebAssembly (WASM) runtimes (`pdf-lib`, `pdfjs-dist`, `xlsx`, HTML5 Canvas 2D) manipulate raw byte streams, decrypt AES blocks, render vector paths, or transcode raster pixels directly in heap memory. 3. **Zero-Egress Export**: Processed output buffers are packaged into an immutable `new Blob([buffer], { type: mimeType })`. A local virtual reference is generated via `URL.createObjectURL(blob)`. 4. **Immediate Garbage Collection**: A synthetic HTML anchor (``) triggers browser-native file saving to the user's local disk. The virtual URL is immediately revoked via `URL.revokeObjectURL()`, and references to internal buffers are set to `null` to facilitate rapid garbage collection by the browser runtime. ### 1.3 Offline & Air-Gapped Operation Because all scripts, WebAssembly binaries, and styling dependencies are bundled into static assets, FileStudio functions with zero network connectivity. Users can load the application, physically disconnect Wi-Fi or Ethernet (or test in an air-gapped environment), and execute all 15 document workflows without interruption. --- ## 2. Complete Tool Reference Manual (15 Tools) ### Tool 1: Merge PDF (`#merge-pdf`) - **Purpose**: Combines multiple independent PDF documents into a single consolidated PDF file. - **Engine**: `pdf-lib` (pure client-side JavaScript PDF parser and serializer). - **Supported Inputs**: Standard PDF documents (`.pdf`, `application/pdf`). - **Output**: Single merged `.pdf` document. - **Features**: Drag-and-drop file reordering, individual page count inspection, metadata sanitization, preserved vector graphics and embedded fonts. - **Privacy Model**: Source document `ArrayBuffers` are combined into a new `PDFDocument` instance in RAM; original byte arrays are dereferenced upon download. ### Tool 2: Split PDF (`#split-pdf`) - **Purpose**: Extracts specific pages or page ranges from a master PDF into a new document. - **Engine**: `pdf-lib`. - **Supported Inputs**: `.pdf`. - **Output**: Sub-document `.pdf`. - **Range Syntax**: Single pages (`1, 4, 7`), sequential ranges (`3-8`), and mixed composite expressions (`1-3, 5, 9-12`). - **Features**: Real-time syntax validation, out-of-bounds page detection, zero quality degradation. ### Tool 3: Compress PDF (`#compress-pdf`) - **Purpose**: Reduces PDF storage footprint for portal uploads and email limits without transmitting files to remote compression servers. - **Engine**: Client-side canvas downsampling and `pdf-lib` object stream recompression. - **Modes**: Extreme Compression (low DPI rasterization for minimal file size), Recommended Compression (balanced vector clarity and image optimization), Less Compression (lossless structural compression). - **Features**: Live file size reduction percentage metric, original vs compressed byte display. ### Tool 4: Organize PDF (`#organize-pdf`) - **Purpose**: Reorders, rotates, and deletes individual pages within a multi-page PDF document. - **Engine**: `pdf-lib` + `pdfjs-dist` thumbnail renderer. - **Features**: Visual thumbnail grid for every page, drag-and-drop page reordering, per-page 90 degrees clockwise/counter-clockwise rotation, single-click page deletion, and clean PDF compilation. - **Privacy Model**: Source document `ArrayBuffers` are combined into a new `PDFDocument` instance in RAM; original byte arrays are dereferenced upon download. ### Tool 5: Rotate PDF (`#rotate-pdf`) - **Purpose**: Fixes upside-down or sideways pages by altering the PDF's internal `/Rotate` dictionary tags. - **Engine**: `pdf-lib`. - **Modes**: All pages simultaneously or specific even/odd page selections. - **Rotations**: 90 degrees Clockwise, 180 degrees Inversion, 270 degrees Counter-Clockwise. - **Preservation**: Lossless rotation with zero raster recompression; text layers and annotations remain 100% intact. ### Tool 6: Watermark PDF (`#watermark-pdf`) - **Purpose**: Stamps custom confidential markers, draft notices, or company logos across PDF pages. - **Engine**: `pdf-lib`. - **Types**: Text Watermark (custom string, font size, rotation angle, opacity slider 5%-100%) or Image Watermark (PNG/JPG logo overlay). - **Layering**: Foreground stamp or background underlay beneath existing text. - **Common Uses**: Stamping "CONFIDENTIAL", "DRAFT", "EVIDENCE COPY", or CA / Advocate firm seals. ### Tool 7: Page Numbers (`#page-numbers`) - **Purpose**: Inserts sequential page numbering or formal Bates indexing onto multi-page PDF files. - **Engine**: `pdf-lib`. - **Formats**: Simple numbers (`1, 2, 3`), "Page X of Y", Roman numerals (`i, ii, iii`), Bates numbering (`PREFIX-0001`). - **Customization**: 6-position grid alignment (Top/Bottom, Left/Center/Right), custom margin offsets, custom start page offset. ### Tool 8: PDF to JPG / PNG (`#pdf-to-jpg`) - **Purpose**: Renders PDF pages into crisp raster image files for portal uploads or image galleries. - **Engine**: `pdfjs-dist` (Mozilla's WebAssembly-accelerated PDF rendering engine) + HTML5 Canvas. - **Output Formats**: High-quality JPG (`image/jpeg`) or lossless PNG (`image/png`). - **Resolution Control**: 1x (72 DPI standard screen), 2x (150 DPI balanced), 3x (300 DPI print/archival grade). - **Download**: Individual image export or batch download. ### Tool 9: Image to PDF (`#image-to-pdf`) - **Purpose**: Packages multiple photos, scans, and graphic files into a single unified PDF booklet. - **Engine**: `pdf-lib` + Canvas. - **Supported Inputs**: JPG, JPEG, PNG, WebP. - **Layout Controls**: Page orientation (Portrait / Landscape / Match Image), Page size (A4, Letter, Auto), Margins (None, Narrow, Standard). - **Features**: Drag-to-reorder image sequence, orientation auto-detection. ### Tool 10: Excel to PDF (`#excel-to-pdf`) - **Purpose**: Converts spreadsheet workbooks into formatted, printable PDF tables. - **Engine**: SheetJS (`xlsx`) + `jspdf` / `jspdf-autotable`. - **Supported Inputs**: `.xlsx`, `.xls`, `.csv`. - **Features**: Multi-sheet workbook navigation, automated column auto-sizing, monochrome professional styling themes (Black, Zinc Dark, Clean Minimal), table header pagination. ### Tool 11: HTML to PDF (`#html-to-pdf`) - **Purpose**: Converts raw HTML markup and CSS styling into printable PDF documents. - **Engine**: Sandboxed client iframe + `html2canvas` + `jspdf`. - **Features**: Live dual-pane code editor, real-time preview, page size selection (A4 / Letter), orientation toggles. ### Tool 12: Protect PDF (`#protect-pdf`) - **Purpose**: Applies cryptographic password protection and user permissions to sensitive PDFs. - **Engine**: `pdf-lib` AES-256 standard security handler. - **Controls**: User password (required to view/open) and Owner/Permissions password (controls printing, copying, and modification). - **Security**: Passwords are processed strictly in client memory; keys are never transmitted or logged. ### Tool 13: Unlock PDF (`#unlock-pdf`) - **Purpose**: Strips password encryption and permission constraints from a known-password protected PDF. - **Engine**: `pdf-lib`. - **Requirement**: The user must provide the legitimate decrypt password. Decryption occurs entirely on the local device, yielding an unencrypted, shareable PDF. ### Tool 14: Image Compress (`#image-compress`) - **Purpose**: Downsizes image file sizes to meet strict government or enterprise portal thresholds (e.g. < 50 KB, < 100 KB). - **Engine**: HTML5 Canvas 2D + Browser native image decoding. - **Supported Inputs**: JPG, PNG, WebP. - **Modes**: Target KB Mode (automatically calculates quality step algorithm to reach exact desired size) and Quality Slider Mode (10% to 100%). ### Tool 15: Image Convert (`#image-convert`) - **Purpose**: Batch converts images between popular modern web and document formats. - **Engine**: Client Canvas `toBlob()` rasterization. - **Supported Conversions**: PNG to JPG, JPG to PNG, WebP to JPG/PNG, PNG/JPG to WebP. - **Features**: Batch conversion table, per-image format overrides, individual or bulk downloads. --- ## 3. Regulatory Compliance Deep Dive ### 3.1 Digital Personal Data Protection Act, 2023 (India DPDP Act) FileStudio is purposefully engineered to eliminate regulatory liability under India's DPDP Act: - **Section 4 (Grounds for Processing)**: FileStudio is not a "Data Fiduciary" or "Data Processor" under the statutory definitions because user personal data is never ingested, received, stored, or processed by FileStudio's computing infrastructure. - **Section 6 (Consent Architecture)**: Cloud converters often rely on ambiguous consent models to train AI or store uploaded files. FileStudio requires zero consent agreements because no personal data is transferred across any network boundary. - **Section 8(5) (Security Safeguards)**: The Act mandates robust safeguards against personal data breaches. By mathematically eliminating server-side file transmission, the risk of a centralized database breach, exfiltration, or ransomware incident is 0%. - **Indian Sensitive Documents**: Specially engineered to safely handle Aadhaar cards (zero UIDAI biometric exposure), PAN cards, Form 16 financial statements, Income Tax Return (ITR) filings, and Advocate Vakalatnamas. ### 3.2 EU General Data Protection Regulation (GDPR) - **Article 25 (Data Protection by Design and by Default)**: FileStudio exemplifies the highest standard of Privacy by Design. Privacy is not a legal policy disclaimer; it is an unalterable architectural invariant. - **Article 32 (Security of Processing)**: Processing confidentiality is guaranteed through complete isolation within the user's secure browser sandbox. --- ## 4. Independent Security Audit & Verification ### 4.1 Browser DevTools F12 Verification Protocol Any security auditor, developer, or enterprise compliance officer can independently verify FileStudio's zero-egress claim in under 60 seconds: 1. Open FileStudio in any modern browser (Chrome, Firefox, Brave, Safari, Edge). 2. Press `F12` (or `Cmd + Option + I` on macOS) to open Developer Tools. 3. Select the **Network** tab. 4. Filter by **Fetch/XHR**. 5. Drag and drop any document into a tool (e.g., Merge PDF, Compress PDF). 6. Click the action button and download the resulting file. 7. Observe the Network panel: **0 new network requests are logged during the entire operation.** ### 4.2 Automated Console Verification Script Paste this snippet into the DevTools Console to audit all outbound XHR and fetch activity: ```javascript const requests = window.performance.getEntriesByType('resource') .filter(r => r.initiatorType === 'fetch' || r.initiatorType === 'xmlhttprequest'); console.log('Outbound Data Requests Detected:', requests.length); console.table(requests.map(r => ({ URL: r.name, Duration: `${r.duration.toFixed(1)}ms` }))); ``` *Expected Output: `Outbound Data Requests Detected: 0` (outside of initial static bundle downloads).* --- ## 5. Comparative Benchmark: FileStudio vs Cloud Converters | Evaluation Dimension | FileStudio (Client-Side) | Traditional Cloud Converters | | :--- | :--- | :--- | | **Data Transmission** | Exactly 0 Bytes over network | 100% of document bytes sent to remote servers | | **Server Disk Retention** | None (0.00 ms) | Often 1-24 hours on external cloud disks | | **Server Log Exposure** | No logs, no telemetry, no IP recording | File names, IP addresses, timestamps logged | | **AI Scraping & Training** | Technically impossible (zero server access) | Frequent risk of unannounced model training | | **Network Reliance** | Works 100% offline & in air-gapped setups | Fails without high-speed internet upload | | **File Size Bottlenecks** | Limited only by local device RAM | Restrictive 10MB-50MB paywall caps | | **DPDP & GDPR Exposure** | Zero breach risk (no centralized data store) | Persistent third-party cloud breach vector | | **Cost & Monetization** | 100% Free Forever; Indie Software | Paid tiers, paywalls, mandatory email signups | --- ## 6. Technical Stack & Dependencies - **Framework**: React 18, Vite 6 - **Styling**: Tailwind CSS (Strict minimalist monochrome palette: `#000000`, `#09090b`, `#0e0e11`, `#ffffff`) - **Core Document Engines**: - `pdf-lib` (v1.17.1): PDF creation, merging, splitting, rotation, watermarking, encryption. - `pdfjs-dist` (v3.11.174): WebAssembly-powered canvas rendering for PDF-to-Image conversions. - `xlsx` (v0.18.5): In-memory spreadsheet parsing. - `jspdf` (v2.5.2) & `jspdf-autotable` (v3.8.4): Dynamic table document generation. - `html2canvas` (v1.4.1): DOM snapshot rasterization. - **Icons**: `lucide-react` - **Hosting**: Static edge CDN (Netlify / Vercel / Cloudflare Pages / GitHub Pages). No dynamic backend APIs. --- ## 7. Responsible Disclosure & Security Contacts - **Security Model**: Static Web Application (Zero backend attack surface). - **Vulnerability Reporting**: Security researchers may audit our static client bundles and report any security concerns directly via GitHub or our trust hub at https://filestudios.appzyra.com/security.