Cloud vs. local: the decision that decides everything
Two tools can both extract and group faces. One uploads them; the other doesn’t. That single difference changes everything about trust, control, and defensibility.
A copy on a server you can’t control
When a face tool uploads case media to the cloud, the first thing that happens is a copy. The faces — usually the surrounding source files too — leave your machine and land in an operator’s storage. You can still verify the hash on your side, but you can no longer audit the lifecycle on theirs: retention, access, backup, and deletion are all defined by terms you did not choose.
Even a well-run vendor is only as trustworthy as the organization enforcing its own contract to itself. A single subpoena, a single leaked key, or a single misconfigured bucket is enough for that copy to become a leak. The point is not that every cloud tool will betray you; the point is that the copy exists in a location you cannot reason about, and that is a problem for a case.
The three leaks a cloud tool creates
A cloud face tool tends to leak in three predictable ways. Accounts tie your identity to every case you open: which file, when, and which face you paused on. Telemetry accumulates small usage signals — feature adoption, crash reports, session length — into a profile of your work you never requested. Case-media egress moves the source files, or the face crops derived from them, across a network boundary you did not design.
Each of these is defensible in a consumer photo app. None of them is defensible in a case. An account tied to a case is a subpoena. Telemetry tied to a case is evidence the case was reviewed. Egress tied to a case is a copy of the case itself, on infra you did not provision and cannot recover.
The local tool already exists
DawaImg runs the whole workflow on your machine. Free, on Windows or macOS.
What local-only buys you operationally
A local-only tool removes all three leaks at once. DawaImg, in v39.0, has no accounts, no telemetry, and no case-media egress. Open a case, review the faces, close the tool — the machine’s reporting surface is unchanged, and the case media stays exactly where it started. Nothing in the pipeline requires a network call.
In the offline ~1,000,000-file run on v39.0 — roughly 5–6 hours on a modern laptop — the pipeline grouped ~2,000 faces with ~98% face-recall and only 2 false positives, both wood-derived (wood-grain misfires). A clean, defensible surface: the reviewer’s machine is the perimeter, and the only copy of a case is the one you hold.
The honest tradeoffs of going local
Local-only is not free of tradeoffs. You install the binary, you choose when to adopt v39.0 or the next release, and your CPU and GPU do the work. A ~1,000,000-file case runs offline for ~5–6 hours, and re-running on a different machine is real work. The tool is free, but your time and hardware are not.
For a case workflow, that is a feature, not a bug. There is no remote copy to subpoena, no operator to leak to, no account to freeze. Defensible, end-to-end, means the machine you are sitting at, the media you already have, and a result you can demonstrate from source. Free, offline, on your machine — that is the trade, and it is the one worth making.