Privacy
The short version: there are no tracking cookies, no advertising, no third-party scripts, and no account. Most tools never send your file anywhere at all.
Last updated 21 September 2026
Files you process
641 of the tools on this site run entirely inside your browser. The file or text you give them is read by JavaScript on your own device, the result is produced there, and nothing is transmitted. You can verify this by opening your browser’s network panel while the tool runs, or by disconnecting from the internet after the page has loaded - the tool keeps working.
A smaller number of tools need software that cannot run in a browser: video and audio conversion, Office document conversion, and a few PDF operations that need a full PDF engine. Those tools say so on the page, above the button. For them, the file is uploaded over HTTPS, stored under a random name that is not guessable, processed by an isolated worker with no network access, and deleted as soon as you download the result - and in any case automatically within an hour. The file is never opened by a person, never indexed, and never used for anything other than producing your result.
What is measured
The site counts page views and tool runs so the project knows which tools are worth maintaining. Those counters are stored as daily totals: one row per page per day, one row per tool per day. There is no per-visitor record, no session identifier, no cookie and no device fingerprint, which means there is no way to reconstruct an individual’s activity even from full database access.
Alongside the count, two coarse values are kept: a device class (mobile, tablet or desktop, derived from window width) and the host of the referring site when you arrive from an external link. The referring path and any query string are discarded.
Site search
What people type into the site search is recorded in aggregate, because queries that return nothing are the clearest signal of a missing tool. Before anything is stored, the query is discarded entirely if it contains an @ sign, a run of six or more digits, or any long token-like string - the shapes that email addresses, phone numbers, order references and API keys take when they are pasted into a search box by mistake.
Cookies
The public site sets no cookies. Your theme choice and your recently used tools are stored in your browser’s local storage, which never leaves the device and is never sent in a request. Clearing site data removes them.
The administration area, which is not part of the public site, sets one strictly necessary session cookie after a successful sign-in. It is HttpOnly, Secure and SameSite=Lax.
Donations
If you choose to support the project, the payment is handled entirely by the payment provider. This site never sees or stores a card number. What is stored is the provider’s own transaction reference, the amount, the currency, the status, and the display name and message you chose to leave.
Third parties
There are no analytics providers, no advertising networks, no social widgets, no externally hosted fonts and no content delivery networks serving third-party JavaScript. Every asset the site loads comes from its own origin, which is enforced by a Content-Security-Policy on every response.
Your rights and contact
Because the site holds no personal data tied to you, there is generally nothing to export or erase on request. If you have made a donation and want the display name removed from the supporter record, or you have any other question about this page, use the contact route published at /.well-known/security.txt.