Skip to main content
Product essentials

PhotoCraft Online Editorial Team

Is PhotoCraft Safe? Downloads, Files and Privacy

Check PhotoCraft's official release source, SHA-256 hashes, browser-local editing, third-party requests and the limits of an alpha image editor.

PhotoCraft is an open-source image editor, but you should still check where you download it, what version you use, and what happens to your files. Keep an original copy before editing, and do not treat every site or installer with the same name as official. PhotoCraft Online is an independent site that hosts the web editor; it is not the upstream project's official website. For the project identity and naming boundaries, start with What is PhotoCraft?.

This guide covers PhotoCraft v0.5.0, with sources checked on 10 October 2026. It gives practical checks you can repeat before using the editor; it is not a security certification. The upstream security policy treats imported document formats and automation input as potential attack surfaces.

Which PhotoCraft is this?

The name can appear on unrelated services. The open-source editor used here is maintained in the storytold/photocraft GitHub repository. Follow the repository's links to establish the official project identity; a similar domain name or search advertisement does not demonstrate affiliation.

This site is responsible for its pages, hosting choices and privacy policy. Upstream develops the editor. Adobe and Photoshop names identify compatibility and comparison topics; neither PhotoCraft nor this site is an Adobe product. If you want the official desktop application, use our download guide to reach the upstream release, not an attachment in a forum or an unsolicited message.

How do I verify a desktop download?

Use the pinned v0.5.0 release, choose the correct operating system and architecture, and download SHA256SUMS.txt from that same release. Match the exact filename, not just the version number.

  1. Check the final URL and repository owner before downloading.
  2. Select the expected package for your OS and architecture. Avoid a repackaged installer that offers unrelated software.
  3. Compute the local file's SHA-256 and compare all hexadecimal characters with the corresponding checksum entry.
  4. Keep normal operating-system signature and malware checks enabled. A warning is a reason to investigate provenance rather than blindly bypass protection.
  5. Keep the version and checksum record if you need to report a reproducible issue later.
PlatformBuilt-in checksum example
Windows PowerShellGet-FileHash -Algorithm SHA256 .\downloaded-file.zip
macOS Terminalshasum -a 256 downloaded-file.dmg
Linux Terminalsha256sum downloaded-file.AppImage

Replace the example filename with the actual download. A matching checksum confirms that your file matches the checksum source; it does not prove the software contains no vulnerabilities. The release and checksum must come from a trusted source together. The upstream download documentation explains release assets, hashes and signing information; that description is not an independent signature audit by this site.

Which web editor package is hosted here?

The hosted runtime is the unchanged official photocraft-web-0.5.0.zip package with SHA-256 855da01e7ce518049c6f3a090f1218864f7b780811e340db409e5c3cef93cd6d. Its licenses remain with the runtime. This artifact verification links the deployed program to the pinned official release; it is not an independent code-security audit.

On 10 October 2026, we checked basic PNG editing and download on macOS 26.2 (25C56) in a Chromium browser, plus visibility and reordering for two synthetic PSD raster layers. PSD save/reopen and Photoshop acceptance were not tested. We have not inspected every possible network request body; the privacy notes below describe the basic editing flow and the limits you should still consider.

Are my images uploaded during basic editing?

For basic editing, this site loads a WebAssembly editor. When you open a local image, the browser gives the file to the editor running in that tab, and Save/Export downloads a new file back to your device. We currently do not provide cloud save, a basic-editing upload workflow or an AI workflow that sends images to an inference service.

Local processing does not mean the browser never uses the network. It downloads the website and runtime. This site uses Plausible Analytics and Google Analytics 4 to measure page visits; Google Analytics uses first-party analytics cookies. Neither analytics tool sends your editor image files. Fonts, documentation and links you choose to open can also make network requests. The web hosting guide describes the static package, local preferences and download behavior. See our privacy policy for the website layer.

If confidentiality is critical, test with a synthetic image first and inspect the browser Network panel on the exact deployed version you plan to use. Compare requests before and after opening the image, and look at destinations and payloads. That check only covers the workflow and build you tested; it cannot cover future integrations or every possible command.

Does local editing protect against file loss?

Local editing reduces the need to send an image to an application server. It does not create a backup. Unsaved changes may be lost when a tab closes, the browser crashes or the page refreshes. Download a new editable copy and a final viewing image, then reopen them before ending the session.

Browser storage used for preferences is not a promise that project contents are recoverable. Clearing site data can reset editor preferences and related site state. For a client PSD, retain the original plus the creator's flattened reference, and apply the compatibility checks before replacing any production asset.

Can a PSD itself be unsafe?

Complex document parsers can face excessive dimensions, decompression load, malformed metadata or deeply nested data. A file with a small download size can still demand substantial memory. Browser isolation is useful, but it is not a guarantee that every malformed file is harmless or that the graphics driver cannot fail. Use a maintained browser and avoid untrusted documents with no clear provenance.

Desktop automation exposes a different set of permissions from this basic web editor. You do not need to enable a desktop control server to use this website. The security documentation separates implemented protections from remaining hardening work.

What should I do if I suspect a security issue?

For a site-specific issue, check the contact page for the current feedback channel and include only the affected page/version and a minimal description. Do not send passwords, secret tokens, private PSDs or weaponized files. For an engine vulnerability, follow the upstream reporting policy; coordinate a private transfer method before sharing sensitive details.

For ordinary loading and export faults, use troubleshooting. For a first non-sensitive sample, open the editor. Keeping a copy, checking the download and verifying the output are useful safeguards even when the software source is legitimate.