Legal

Privacy Policy

This policy separates the content you process inside a tool from the limited information involved in delivering, securing, advertising, and supporting the website.

Zero data collection for tool content

PrivateToolbox follows a zero data collection policy for the files, text, passwords, patterns, captions, source details, and other content entered into its browser tools. We do not collect, store, upload, or transmit that tool content to our servers. We do not create user profiles from tool inputs, sell those inputs, use them to train models, or retain a recoverable history. The available tools do not require an account, so there is no PrivateToolbox account record tied to a processed file or generated result.

This commitment applies to the processing content itself. It does not mean that a website can operate without any technical requests. Loading a page requires a hosting provider to deliver files to your browser, and advertising or your email application may operate under separate rules described below. The important distinction is that the photo, PDF, draft, JSON, regular expression sample, password, caption, or citation details placed in a tool are not included in those ordinary page-delivery requests by PrivateToolbox.

Client-side processing architecture

Our client-side architecture is designed so supported work occurs within the web browser on your device. JavaScript can read a file that you deliberately select, calculate text statistics, generate random characters, parse JSON, evaluate a regular expression, draw a QR code, or assemble a citation without sending the working content to PrivateToolbox. Temporary values exist in browser memory while the page is open. Generated downloads may use a temporary local object URL that points to data already held by your browser rather than a remote storage location.

Closing or refreshing a page normally clears the tool’s working state, although browser features such as form restoration, clipboard history, extensions, backups, or shared-device monitoring are outside our control. Downloaded results remain wherever you save them. Client-side processing reduces an unnecessary transfer; it does not secure an infected device, protect a public QR code, encrypt Base64, or replace specialist redaction and compliance review. Keep originals, inspect results, and follow any workplace or legal policy that applies to the material.

Technical website records

Hosting, content-delivery, abuse-prevention, and security systems may process limited request information needed to deliver and protect the website. Depending on the provider, this can include network address, approximate region, request time, requested page, browser or device information, response status, and security signals. Such records are operational data, not copies of the content placed inside a client-side tool. They may be retained for limited periods under the provider’s security and reliability practices.

We do not use those records to reconstruct tool content. We also do not operate a user-account analytics profile. Network operators, employers, internet providers, browser vendors, and device administrators may have their own visibility into website visits. Private browsing mode and local browser settings are controlled by the browser, not by this policy.

AdSense cookie disclosure

PrivateToolbox may use Google AdSense to display advertising. AdSense and its advertising partners may use cookies, local storage, device identifiers, IP-derived location, and similar technologies to deliver, measure, limit, or personalize ads, subject to applicable consent requirements and Google’s own policies. These technologies may recognize a browser across visits or sites. They do not receive the files or text processed inside PrivateToolbox tools from us.

Where required, visitors should be offered consent choices before non-essential advertising storage is used. Browser controls, device settings, and Google advertising settings may also allow people to manage or limit personalized advertising. Blocking cookies can change ad behavior but should not prevent the core client-side tools from operating. Third-party advertisements and linked destinations are governed by their own privacy notices; review them before providing information or making a purchase.

Contact messages

If you email us or use the contact form, your mail application sends the information you choose to include. That may include your name, email address, subject, message, and ordinary mail-routing metadata. We use it to understand and respond to the request, prevent abuse, and maintain a reasonable correspondence record. Do not attach confidential source files, passwords, access tokens, government identifiers, or sensitive personal records. A non-sensitive description or reduced example is usually enough to investigate a tool problem.

The website contact form does not silently submit to a PrivateToolbox database. It validates the fields on the page and opens a pre-addressed message in the visitor’s chosen email application. Delivery, drafts, sent mail, and retention are then controlled by the visitor’s and recipient’s email providers.

GDPR and CCPA

Privacy laws such as the European Union and United Kingdom GDPR and the California Consumer Privacy Act provide rights that can include access, correction, deletion, restriction, objection, portability, and information about categories of personal information or sharing. The exact rights and exceptions depend on location and context. Because PrivateToolbox does not collect or store tool content or require accounts, we generally cannot retrieve content that never reached us. We can address identifiable correspondence we hold when a valid request gives us enough information to locate it.

PrivateToolbox does not sell tool content or use it for cross-context behavioral advertising. Advertising partners may independently process device or advertising information as described in the AdSense disclosure and their policies. Where legally required, consent and opt-out mechanisms should govern that processing. To ask a privacy question or exercise an applicable right regarding information held directly by PrivateToolbox, email hello@privatetoolbox.net. We may need to verify that a requester is entitled to act on the relevant correspondence without requesting more information than reasonably necessary.

Children, retention, and changes

PrivateToolbox is a general-audience utility service and is not directed to children under the minimum age for independent online consent in their jurisdiction. We do not knowingly request children’s personal information. Parents or guardians who believe a child sent identifying information through email may contact us for review.

Tool content has no PrivateToolbox server retention period because it is not uploaded. Operational security records, advertising information, and email correspondence follow the retention practices described by the relevant provider or the period reasonably needed for security, support, legal obligations, and dispute handling. We may update this policy when tools, advertising practices, providers, or laws change. Material revisions will be posted on this page with a new effective date.

Contact

Questions about this policy may be sent to hello@privatetoolbox.net. Describe the issue without including the private file or content you processed. We aim to respond within 24–48 hours, although complex legal requests may require additional verification and time.

Effective September 13, 2026.