We don't collect personal data. We have no third-party analytics or trackers installed. All processing of the data you enter into any tool happens in your browser. No Google Analytics, no Meta Pixel, no third-party cookies. That's the whole thing.
No personal data: no names, no emails, no IP addresses tied to your activity, no content you enter into any of our tools.
We do collect anonymous aggregate usage counts, a number tracking how many times each tool has been used. These counts are stored in a SQLite file on our server. They are not tied to any individual user or session. They help us understand which tools are popular so we can prioritize improvements.
We use a small first-party cookie to remember basic UI preferences (such as theme). It contains no identifiers and can be deleted at any time from your browser settings.
Nobody outside the team. We don't share data with third parties.
When you enter text into any of our tools (JSON formatter, Base64 encoder, regex tester, etc.), that text never touches our server. Processing runs entirely in your browser. The only server-side call we make is an optional anonymous counter increment, a single integer that contains no input data.
None. We self-host all fonts (Inter Variable, served from our own domain) so no font request reaches Google or any other CDN. Cloudflare Insights' anonymous performance beacon is the only third-party script in our CSP allow-list, and it does not collect personal identifiers.
Because we don't collect personal data, the typical data rights (access, deletion, portability) have nothing to act on. The only exception: if you have opted into our newsletter or submitted feedback/reviews with an email address, that email (plus anything you wrote) is stored. You can request a copy or deletion at any time using the form below.
We comply with GDPR, CCPA, and similar regulations by the simplest means possible: we do not collect personal data in the first place. For the edge cases where you've handed us data voluntarily (newsletter signup, feedback form), we support the standard data-subject rights listed above.
The site is served over HTTPS. Our admin panel uses strong password hashing (Argon2id) with optional TOTP second factor, and is rate-limited. No system is perfectly secure, but we take reasonable precautions.
If we ever change this policy, we will update the "Last updated" date at the top of this page and announce material changes via a banner on the homepage for at least 30 days.
Privacy questions: privacy@zipkit.dev