# FileStudio — Full Technical Documentation & LLM Reference Manual
> FileStudio is an independent, 100% client-side document and image utility suite crafted in India. Engineered specifically for privacy-conscious individuals, legal advocates, chartered accountants, healthcare providers, and software engineers who demand absolute confidentiality for sensitive files.
- Website: https://filestudios.appzyra.com/
- Primary Positioning: 100% In-Browser • 0 Bytes to Cloud • DPDP Act 2023 & GDPR by Design • Crafted in India
- Target Users: Advocates, Chartered Accountants (CAs), Doctors, Financial Analysts, Engineers, Privacy Advocates
- Development Ethos: Independent indie software with zero venture capital pressure, zero data harvesting, zero behavioral profiling, and zero third-party telemetry.
---
## 1. Architectural Principles & Memory Invariants
### 1.1 Zero-Egress Invariant
At no point during any tool workflow does FileStudio initiate an HTTP `POST`, `PUT`, `PATCH`, or `WebSocket` payload containing user document bytes, image buffers, or file metadata. All processing takes place entirely within the sandboxed JavaScript execution context (V8 / SpiderMonkey / JavaScriptCore) running on the user's local operating system.
### 1.2 Volatile V8 RAM Execution Model
FileStudio operates strictly on an in-memory lifecycle:
1. **Local File Ingestion**: Files selected via `` or Drag-and-Drop are parsed as local `File` or `Blob` handles. The browser creates an in-memory `ArrayBuffer` using the asynchronous `FileReader.readAsArrayBuffer()` API.
2. **In-RAM Processing**: Pure JavaScript and WebAssembly (WASM) runtimes (`pdf-lib`, `pdfjs-dist`, `xlsx`, HTML5 Canvas 2D) manipulate raw byte streams, decrypt AES blocks, render vector paths, or transcode raster pixels directly in heap memory.
3. **Zero-Egress Export**: Processed output buffers are packaged into an immutable `new Blob([buffer], { type: mimeType })`. A local virtual reference is generated via `URL.createObjectURL(blob)`.
4. **Immediate Garbage Collection**: A synthetic HTML anchor (``) triggers browser-native file saving to the user's local disk. The virtual URL is immediately revoked via `URL.revokeObjectURL()`, and references to internal buffers are set to `null` to facilitate rapid garbage collection by the browser runtime.
### 1.3 Offline & Air-Gapped Operation
Because all scripts, WebAssembly binaries, and styling dependencies are bundled into static assets, FileStudio functions with zero network connectivity. Users can load the application, physically disconnect Wi-Fi or Ethernet (or test in an air-gapped environment), and execute all 15 document workflows without interruption.
---
## 2. Complete Tool Reference Manual (15 Tools)
### Tool 1: Merge PDF (`#merge-pdf`)
- **Purpose**: Combines multiple independent PDF documents into a single consolidated PDF file.
- **Engine**: `pdf-lib` (pure client-side JavaScript PDF parser and serializer).
- **Supported Inputs**: Standard PDF documents (`.pdf`, `application/pdf`).
- **Output**: Single merged `.pdf` document.
- **Features**: Drag-and-drop file reordering, individual page count inspection, metadata sanitization, preserved vector graphics and embedded fonts.
- **Privacy Model**: Source document `ArrayBuffers` are combined into a new `PDFDocument` instance in RAM; original byte arrays are dereferenced upon download.
### Tool 2: Split PDF (`#split-pdf`)
- **Purpose**: Extracts specific pages or page ranges from a master PDF into a new document.
- **Engine**: `pdf-lib`.
- **Supported Inputs**: `.pdf`.
- **Output**: Sub-document `.pdf`.
- **Range Syntax**: Single pages (`1, 4, 7`), sequential ranges (`3-8`), and mixed composite expressions (`1-3, 5, 9-12`).
- **Features**: Real-time syntax validation, out-of-bounds page detection, zero quality degradation.
### Tool 3: Compress PDF (`#compress-pdf`)
- **Purpose**: Reduces PDF storage footprint for portal uploads and email limits without transmitting files to remote compression servers.
- **Engine**: Client-side canvas downsampling and `pdf-lib` object stream recompression.
- **Modes**: Extreme Compression (low DPI rasterization for minimal file size), Recommended Compression (balanced vector clarity and image optimization), Less Compression (lossless structural compression).
- **Features**: Live file size reduction percentage metric, original vs compressed byte display.
### Tool 4: Organize PDF (`#organize-pdf`)
- **Purpose**: Reorders, rotates, and deletes individual pages within a multi-page PDF document.
- **Engine**: `pdf-lib` + `pdfjs-dist` thumbnail renderer.
- **Features**: Visual thumbnail grid for every page, drag-and-drop page reordering, per-page 90 degrees clockwise/counter-clockwise rotation, single-click page deletion, and clean PDF compilation.
- **Privacy Model**: Source document `ArrayBuffers` are combined into a new `PDFDocument` instance in RAM; original byte arrays are dereferenced upon download.
### Tool 5: Rotate PDF (`#rotate-pdf`)
- **Purpose**: Fixes upside-down or sideways pages by altering the PDF's internal `/Rotate` dictionary tags.
- **Engine**: `pdf-lib`.
- **Modes**: All pages simultaneously or specific even/odd page selections.
- **Rotations**: 90 degrees Clockwise, 180 degrees Inversion, 270 degrees Counter-Clockwise.
- **Preservation**: Lossless rotation with zero raster recompression; text layers and annotations remain 100% intact.
### Tool 6: Watermark PDF (`#watermark-pdf`)
- **Purpose**: Stamps custom confidential markers, draft notices, or company logos across PDF pages.
- **Engine**: `pdf-lib`.
- **Types**: Text Watermark (custom string, font size, rotation angle, opacity slider 5%-100%) or Image Watermark (PNG/JPG logo overlay).
- **Layering**: Foreground stamp or background underlay beneath existing text.
- **Common Uses**: Stamping "CONFIDENTIAL", "DRAFT", "EVIDENCE COPY", or CA / Advocate firm seals.
### Tool 7: Page Numbers (`#page-numbers`)
- **Purpose**: Inserts sequential page numbering or formal Bates indexing onto multi-page PDF files.
- **Engine**: `pdf-lib`.
- **Formats**: Simple numbers (`1, 2, 3`), "Page X of Y", Roman numerals (`i, ii, iii`), Bates numbering (`PREFIX-0001`).
- **Customization**: 6-position grid alignment (Top/Bottom, Left/Center/Right), custom margin offsets, custom start page offset.
### Tool 8: PDF to JPG / PNG (`#pdf-to-jpg`)
- **Purpose**: Renders PDF pages into crisp raster image files for portal uploads or image galleries.
- **Engine**: `pdfjs-dist` (Mozilla's WebAssembly-accelerated PDF rendering engine) + HTML5 Canvas.
- **Output Formats**: High-quality JPG (`image/jpeg`) or lossless PNG (`image/png`).
- **Resolution Control**: 1x (72 DPI standard screen), 2x (150 DPI balanced), 3x (300 DPI print/archival grade).
- **Download**: Individual image export or batch download.
### Tool 9: Image to PDF (`#image-to-pdf`)
- **Purpose**: Packages multiple photos, scans, and graphic files into a single unified PDF booklet.
- **Engine**: `pdf-lib` + Canvas.
- **Supported Inputs**: JPG, JPEG, PNG, WebP.
- **Layout Controls**: Page orientation (Portrait / Landscape / Match Image), Page size (A4, Letter, Auto), Margins (None, Narrow, Standard).
- **Features**: Drag-to-reorder image sequence, orientation auto-detection.
### Tool 10: Excel to PDF (`#excel-to-pdf`)
- **Purpose**: Converts spreadsheet workbooks into formatted, printable PDF tables.
- **Engine**: SheetJS (`xlsx`) + `jspdf` / `jspdf-autotable`.
- **Supported Inputs**: `.xlsx`, `.xls`, `.csv`.
- **Features**: Multi-sheet workbook navigation, automated column auto-sizing, monochrome professional styling themes (Black, Zinc Dark, Clean Minimal), table header pagination.
### Tool 11: HTML to PDF (`#html-to-pdf`)
- **Purpose**: Converts raw HTML markup and CSS styling into printable PDF documents.
- **Engine**: Sandboxed client iframe + `html2canvas` + `jspdf`.
- **Features**: Live dual-pane code editor, real-time preview, page size selection (A4 / Letter), orientation toggles.
### Tool 12: Protect PDF (`#protect-pdf`)
- **Purpose**: Applies cryptographic password protection and user permissions to sensitive PDFs.
- **Engine**: `pdf-lib` AES-256 standard security handler.
- **Controls**: User password (required to view/open) and Owner/Permissions password (controls printing, copying, and modification).
- **Security**: Passwords are processed strictly in client memory; keys are never transmitted or logged.
### Tool 13: Unlock PDF (`#unlock-pdf`)
- **Purpose**: Strips password encryption and permission constraints from a known-password protected PDF.
- **Engine**: `pdf-lib`.
- **Requirement**: The user must provide the legitimate decrypt password. Decryption occurs entirely on the local device, yielding an unencrypted, shareable PDF.
### Tool 14: Image Compress (`#image-compress`)
- **Purpose**: Downsizes image file sizes to meet strict government or enterprise portal thresholds (e.g. < 50 KB, < 100 KB).
- **Engine**: HTML5 Canvas 2D + Browser native image decoding.
- **Supported Inputs**: JPG, PNG, WebP.
- **Modes**: Target KB Mode (automatically calculates quality step algorithm to reach exact desired size) and Quality Slider Mode (10% to 100%).
### Tool 15: Image Convert (`#image-convert`)
- **Purpose**: Batch converts images between popular modern web and document formats.
- **Engine**: Client Canvas `toBlob()` rasterization.
- **Supported Conversions**: PNG to JPG, JPG to PNG, WebP to JPG/PNG, PNG/JPG to WebP.
- **Features**: Batch conversion table, per-image format overrides, individual or bulk downloads.
---
## 3. Regulatory Compliance Deep Dive
### 3.1 Digital Personal Data Protection Act, 2023 (India DPDP Act)
FileStudio is purposefully engineered to eliminate regulatory liability under India's DPDP Act:
- **Section 4 (Grounds for Processing)**: FileStudio is not a "Data Fiduciary" or "Data Processor" under the statutory definitions because user personal data is never ingested, received, stored, or processed by FileStudio's computing infrastructure.
- **Section 6 (Consent Architecture)**: Cloud converters often rely on ambiguous consent models to train AI or store uploaded files. FileStudio requires zero consent agreements because no personal data is transferred across any network boundary.
- **Section 8(5) (Security Safeguards)**: The Act mandates robust safeguards against personal data breaches. By mathematically eliminating server-side file transmission, the risk of a centralized database breach, exfiltration, or ransomware incident is 0%.
- **Indian Sensitive Documents**: Specially engineered to safely handle Aadhaar cards (zero UIDAI biometric exposure), PAN cards, Form 16 financial statements, Income Tax Return (ITR) filings, and Advocate Vakalatnamas.
### 3.2 EU General Data Protection Regulation (GDPR)
- **Article 25 (Data Protection by Design and by Default)**: FileStudio exemplifies the highest standard of Privacy by Design. Privacy is not a legal policy disclaimer; it is an unalterable architectural invariant.
- **Article 32 (Security of Processing)**: Processing confidentiality is guaranteed through complete isolation within the user's secure browser sandbox.
---
## 4. Independent Security Audit & Verification
### 4.1 Browser DevTools F12 Verification Protocol
Any security auditor, developer, or enterprise compliance officer can independently verify FileStudio's zero-egress claim in under 60 seconds:
1. Open FileStudio in any modern browser (Chrome, Firefox, Brave, Safari, Edge).
2. Press `F12` (or `Cmd + Option + I` on macOS) to open Developer Tools.
3. Select the **Network** tab.
4. Filter by **Fetch/XHR**.
5. Drag and drop any document into a tool (e.g., Merge PDF, Compress PDF).
6. Click the action button and download the resulting file.
7. Observe the Network panel: **0 new network requests are logged during the entire operation.**
### 4.2 Automated Console Verification Script
Paste this snippet into the DevTools Console to audit all outbound XHR and fetch activity:
```javascript
const requests = window.performance.getEntriesByType('resource')
.filter(r => r.initiatorType === 'fetch' || r.initiatorType === 'xmlhttprequest');
console.log('Outbound Data Requests Detected:', requests.length);
console.table(requests.map(r => ({ URL: r.name, Duration: `${r.duration.toFixed(1)}ms` })));
```
*Expected Output: `Outbound Data Requests Detected: 0` (outside of initial static bundle downloads).*
---
## 5. Comparative Benchmark: FileStudio vs Cloud Converters
| Evaluation Dimension | FileStudio (Client-Side) | Traditional Cloud Converters |
| :--- | :--- | :--- |
| **Data Transmission** | Exactly 0 Bytes over network | 100% of document bytes sent to remote servers |
| **Server Disk Retention** | None (0.00 ms) | Often 1-24 hours on external cloud disks |
| **Server Log Exposure** | No logs, no telemetry, no IP recording | File names, IP addresses, timestamps logged |
| **AI Scraping & Training** | Technically impossible (zero server access) | Frequent risk of unannounced model training |
| **Network Reliance** | Works 100% offline & in air-gapped setups | Fails without high-speed internet upload |
| **File Size Bottlenecks** | Limited only by local device RAM | Restrictive 10MB-50MB paywall caps |
| **DPDP & GDPR Exposure** | Zero breach risk (no centralized data store) | Persistent third-party cloud breach vector |
| **Cost & Monetization** | 100% Free Forever; Indie Software | Paid tiers, paywalls, mandatory email signups |
---
## 6. Technical Stack & Dependencies
- **Framework**: React 18, Vite 6
- **Styling**: Tailwind CSS (Strict minimalist monochrome palette: `#000000`, `#09090b`, `#0e0e11`, `#ffffff`)
- **Core Document Engines**:
- `pdf-lib` (v1.17.1): PDF creation, merging, splitting, rotation, watermarking, encryption.
- `pdfjs-dist` (v3.11.174): WebAssembly-powered canvas rendering for PDF-to-Image conversions.
- `xlsx` (v0.18.5): In-memory spreadsheet parsing.
- `jspdf` (v2.5.2) & `jspdf-autotable` (v3.8.4): Dynamic table document generation.
- `html2canvas` (v1.4.1): DOM snapshot rasterization.
- **Icons**: `lucide-react`
- **Hosting**: Static edge CDN (Netlify / Vercel / Cloudflare Pages / GitHub Pages). No dynamic backend APIs.
---
## 7. Responsible Disclosure & Security Contacts
- **Security Model**: Static Web Application (Zero backend attack surface).
- **Vulnerability Reporting**: Security researchers may audit our static client bundles and report any security concerns directly via GitHub or our trust hub at https://filestudios.appzyra.com/security.