Pasting JSON into a web page to format it means handing over whatever that JSON contains, and it is frequently more sensitive than the person pasting it realises: an API response with a customer record, a configuration file with an internal hostname, a payload copied straight out of production logs. The question worth asking before pasting is not whether the page looks trustworthy, but whether it sends the text anywhere at all.
Several formatter sites now advertise that nothing is uploaded, which is a welcome change from a few years ago, but a claim printed on a page is not evidence. The only way to know is to watch what the page actually does. Open your browser's developer tools, switch to the Network tab, clear it, then paste the JSON and press format. If a request fires carrying your text in its body, query string or headers, the formatting happened on a server somewhere, whatever the page claims. If the tab stays empty, the work happened in the page itself.
This check takes under a minute and it is more reliable than reading a privacy policy, because a policy describes intent while the network tab shows what the code actually does. It is also worth repeating occasionally rather than trusting a result from months ago: a site can add a feature, an analytics script or a third-party widget that introduces a new request path without changing its stated promises.
A formatter that genuinely runs locally has a second, quieter advantage: it keeps working on a slow or interrupted connection, because there is no round trip waiting to complete. If formatting a large document feels instant rather than pausing for a moment first, that responsiveness is itself a reasonably good sign, though it is not a substitute for actually checking the network tab once.
Treat the absence of a network request as confirmation for that session, not a permanent guarantee about every future visit. Sites change. The fifteen-second check costs nothing and settles the question directly, which is a better habit than trusting a badge.