How ExportDecode works
Seven steps, no account, nothing uploaded. Here is exactly what happens when you analyze your data.
Step 1 — Request your data from the service
Every major service is legally required (in many countries) to give you a copy of your personal data. You request this from within your account settings, usually under a "Privacy", "Data & privacy" or "Your information" section. Each request is a one-time action; the service then prepares your archive.
How long does it take? Amazon is usually ready in minutes. Netflix takes a few hours. Spotify's extended streaming history can take up to 30 days. Google Takeout (for YouTube) typically takes minutes to a few hours.
→ See the full directory of data request links
Step 2 — Download your export
The service emails you when your export is ready. You download a ZIP file to your device. You do not need to open or unzip it — ExportDecode handles that in the next step.
Step 3 — Open ExportDecode and choose a tool
Open exportdecode.com in any modern browser and click the tool that matches your file. Each tool page includes step-by-step instructions and tells you exactly which file is expected.
Step 4 — Drop your file in
Drag the ZIP (or the specific file inside it) onto the drop area, or click "Choose file" to use the system file picker. ExportDecode accepts both ZIPs and the individual files inside them.
What happens at this point:
- Your browser reads the file from disk into memory — no network request is made.
- If it is a ZIP, the fflate library decompresses only the relevant entries, in memory.
- The raw text or JSON is passed to the parser for that tool.
- Nothing is written to cookies, localStorage or any server.
The app page ships with a Content-Security-Policy declared in a <meta http-equiv> tag in its own HTML, which includes connect-src 'none' and form-action 'none'. Your browser enforces that policy: the page is not permitted to make network requests (fetch, XMLHttpRequest, WebSocket) or submit forms. That limit is applied by the browser, not by our code alone — and you can check it yourself, as described in the privacy walkthrough.
Step 5 — ExportDecode parses and calculates locally
The parser reads the file and builds a structured dataset in memory. Then the analysis function calculates totals, rankings, time series and heatmaps from that dataset. Everything runs on your CPU, in your browser tab.
What "locally" means in practice:
- No request is sent over the network while the file is being read.
- Your file content does not appear in any server log, because it never reaches any server.
- The calculations run immediately — there is no queue and no waiting for a response from a server.
Step 6 — View results, charts and filters
After parsing you see a headline stat, a grid of key figures, and a series of charts and tables. Use the filter controls (year, profile, content type) to narrow the view. All filtering happens instantly in memory — no network round trip.
Step 7 — Export results or print
Click any "↓ Download" button to save a CSV export of the underlying data to your device. The file is created in your browser using a Blob URL and downloaded immediately without any network request. You can also print the page or save it as a PDF from your browser's Print menu.
Step 8 — Reset to remove the data
Click "Clear data & start over" to remove the loaded file from memory. Closing the tab achieves the same thing. There is nothing to delete from a server because nothing was sent there.
Three ways to verify this yourself
1. Go offline
Load the page in your browser, then switch on airplane mode or disconnect from your network. Now drop your file. The analysis runs exactly the same — because it has no internet dependency once the page is loaded.
2. Watch the Network tab
Open your browser's developer tools (usually F12), go to the Network tab, then drop your file. You will see the JavaScript running but no request that carries your file data leaves your device.
3. Read the Content-Security-Policy
View the source of the app page (exportdecode.com) — in your browser choose View page source — and search for Content-Security-Policy. You will find it inside a <meta http-equiv="Content-Security-Policy"> tag near the top of the document, not among the network response headers. It contains connect-src 'none', which tells your browser to refuse network requests (fetch, XHR, WebSocket) from the page, and form-action 'none', which blocks form posts.
What ExportDecode cannot do
- It cannot reach into your Amazon, Netflix or Spotify account directly — it only reads the file you give it.
- It cannot access data that was not included in your export (for example, Amazon digital purchases are in a separate file).
- It cannot account for data deleted by a service before your export was made.
- It cannot undelete YouTube history you turned off or that was auto-deleted.
- It does not give financial advice. Any spending figures are calculated from your file and may differ from official statements.