Privacy and data use
ToolTab requires no account. Most web tools process data in your browser, and tools that need a network connection identify the public services they contact. This version includes no advertising or client-side tracking scripts. Only aggregated Cloudflare HTTP request analytics are used to rank popular tools.
Processing in your browser
Unless a tool identifies a network destination, text, files, images, media, and generated results stay in the current browser session and are not sent to a ToolTab service. Tools release their temporary data when you reset them, replace a resource, or leave the page.
Network tools and public services
DNS, IP address, and network time tools contact the Cloudflare, Google Public DNS, AliDNS, GeoJS, ip.sb, or ipify endpoints listed on their pages. The selected provider receives the query and information normally included in a network request. First visits and updates also download application code and static assets.
Popular tool analytics
The ToolTab server queries aggregated Cloudflare HTTP request analytics from the past 30 days. It uses only /tools/<id> and /en-US/tools/<id> page paths to rank popular tools. No client-side tracking script is added, and the analytics do not include file contents, tool inputs, or results. The Cloudflare API token stays on the server and is never sent to browsers or included in public API examples.
Device permissions
Camera, microphone, and screen-sharing permissions are requested only when you start the relevant feature. Files are read only when you select, drop, or deliberately paste them. Copy actions write the selected result without reading existing clipboard contents. You can revoke permissions in your browser or operating system.
Local settings and offline cache
localStorage holds only the theme, palette, and selected tool preferences or recovery data, such as timers, calendar drafts, and ASCII, color, and unit settings. The relevant tools provide reset or clear controls. The URL and a language preference cookie determine the language. Offline caches contain application code and static assets, not imported files or results.
Downloads and temporary links
Downloads start only when you choose to download a file. Browser-generated object URLs support previews and downloads. These URLs are revoked when you replace a result, reset a tool, leave the page, or start a download. Your browser and operating system manage any files you save.
Public API and MCP
The deployed public HTTP API and remote MCP do not require Bearer authentication. They process only requests you explicitly submit and cannot read other browser tabs, local files, permissions, clipboard contents, or device state. Upload and download jobs may store temporary inputs or results for about one hour. The delete endpoint can remove them sooner.
Third-party links
Tool results, maps, specifications, and project resources may include links to third-party services. Your browser contacts a destination only when you open its link. That service’s privacy policy and request handling then apply.
Policy changes and contact
This notice is updated as features and data flows change. The current version is published on this page.