Cropping is implemented entirely with the Canvas API. The key function is ctx.drawImage(), which — when given the right arguments — draws only a specific region of the source image onto the canvas.
The full signature looks like this: ctx.drawImage(image, sx, sy, sw, sh, dx, dy, dw, dh). The first four numeric arguments describe the crop region on the source image: sx, sy is the top-left corner of the region, and sw, sh is its width and height. The last four (dx, dy, dw, dh) describe where and how large to draw it on the canvas. In plain terms: "copy this rectangle from the source and paste it onto the canvas."
As you drag the crop handle, those coordinates update in real time. When you hit "Crop & Download," those values are passed directly to drawImage(), the result is exported as a PNG, and your browser downloads it.
The entire process stays in your browser — no image data is ever sent to a server.