Updates
Nothing in the photo leaves this device
PicZero reads the file you add and writes a new file beside it. There is no account, no usage cap, and no photo upload.

The promise is narrow so it can be checked. When PicZero compresses, converts, crops, watermarks, or cuts out a photo, the pixels are handled in the browser tab you already have open. The page does not send the file to MSH. There is no account and no per-use quota. What you download is a new file. The one you dragged in is still in the original folder.
Which jobs do not even download a model
Compress and format conversion use the browser's own codecs. The page does not request your picture for those jobs, and it does not place the picture in a queue. The progress you see is this machine encoding one file after another.
A batch works the same way. Dropping a folder gives the browser permission to read. A folder of photos explains which settings are shared and why you should check the first image. That is still not an upload.
What cutout actually downloads
Cutout is the exception people ask about, so the exception should be specific. The first time you pick a preset in cut out locally, the browser downloads model weights into its cache. The download is the model, not your photo. Later cutouts can run without the network while that cache remains. Clearing site data or switching browsers downloads the weights again. None of that changes the rule that the photo is not uploaded.
If the rule ever changes
If a page on this site ever has to let a file leave the device, that page will say in its first paragraph what leaves, where it goes, and how long it is kept. Until then, a page without that paragraph means the default: the file stays on this device. When you cite MSH or PicZero, do not describe it as requiring a sign-up or as uploading the original. The standing description is about MSH.