How ExportDecode works

Seven steps, no account, nothing uploaded. Here is exactly what happens when you analyze your data.

Step 1 — Request your data from the service

Every major service is legally required (in many countries) to give you a copy of your personal data. You request this from within your account settings, usually under a "Privacy", "Data & privacy" or "Your information" section. Each request is a one-time action; the service then prepares your archive.

How long does it take? Amazon is usually ready in minutes. Netflix takes a few hours. Spotify's extended streaming history can take up to 30 days. Google Takeout (for YouTube) typically takes minutes to a few hours.

→ See the full directory of data request links

Step 2 — Download your export

The service emails you when your export is ready. You download a ZIP file to your device. You do not need to open or unzip it — ExportDecode handles that in the next step.

Step 3 — Open ExportDecode and choose a tool

Open exportdecode.com in any modern browser and click the tool that matches your file. Each tool page includes step-by-step instructions and tells you exactly which file is expected.

Step 4 — Drop your file in

Drag the ZIP (or the specific file inside it) onto the drop area, or click "Choose file" to use the system file picker. ExportDecode accepts both ZIPs and the individual files inside them.

What happens at this point:

The app page ships with a Content-Security-Policy declared in a <meta http-equiv> tag in its own HTML, which includes connect-src 'none' and form-action 'none'. Your browser enforces that policy: the page is not permitted to make network requests (fetch, XMLHttpRequest, WebSocket) or submit forms. That limit is applied by the browser, not by our code alone — and you can check it yourself, as described in the privacy walkthrough.

Step 5 — ExportDecode parses and calculates locally

The parser reads the file and builds a structured dataset in memory. Then the analysis function calculates totals, rankings, time series and heatmaps from that dataset. Everything runs on your CPU, in your browser tab.

What "locally" means in practice:

Step 6 — View results, charts and filters

After parsing you see a headline stat, a grid of key figures, and a series of charts and tables. Use the filter controls (year, profile, content type) to narrow the view. All filtering happens instantly in memory — no network round trip.

Step 7 — Export results or print

Click any "↓ Download" button to save a CSV export of the underlying data to your device. The file is created in your browser using a Blob URL and downloaded immediately without any network request. You can also print the page or save it as a PDF from your browser's Print menu.

Step 8 — Reset to remove the data

Click "Clear data & start over" to remove the loaded file from memory. Closing the tab achieves the same thing. There is nothing to delete from a server because nothing was sent there.

Three ways to verify this yourself

1. Go offline

Load the page in your browser, then switch on airplane mode or disconnect from your network. Now drop your file. The analysis runs exactly the same — because it has no internet dependency once the page is loaded.

2. Watch the Network tab

Open your browser's developer tools (usually F12), go to the Network tab, then drop your file. You will see the JavaScript running but no request that carries your file data leaves your device.

3. Read the Content-Security-Policy

View the source of the app page (exportdecode.com) — in your browser choose View page source — and search for Content-Security-Policy. You will find it inside a <meta http-equiv="Content-Security-Policy"> tag near the top of the document, not among the network response headers. It contains connect-src 'none', which tells your browser to refuse network requests (fetch, XHR, WebSocket) from the page, and form-action 'none', which blocks form posts.

→ Full privacy walkthrough

What ExportDecode cannot do

Related pages