Privacy Policy
Last updated: 4 October 2026
All 70 tools on this site run inside your browser. Whatever you paste into a tool is processed by JavaScript on the page you already have open, and is never sent to us, because there is nothing here to send it to.
Who we are
These tools are operated by UtilFoundry ("we", "us"), an independent project. You can reach us at support@utilfoundry.com about anything on this page.
Your input never leaves your browser
This is a structural fact about the app, not a policy we could quietly change:
- The application has no upload endpoint. There is no API route, no server action and no form that posts your input anywhere.
- Formatting, validating, encoding, decoding, diffing, parsing and generating all happen in the page. The libraries that do it are downloaded to your browser and run there.
- The page is served with a Content Security Policy whose
connect-srcallows only this site andadmin.utilfoundry.com— the feedback and visit signal described below. It cannot reach anywhere else, even if something on the page tried to. - A page you already have open keeps working with the network disconnected, which is the plainest demonstration that nothing is being sent.
No account. An optional feedback button, and one anonymous visit signal.
There is no sign-up, so we collect no name or email address. No third-party analytics, advertising or tracking script runs here — nothing from Google, Meta, an ad network or a data broker. Two things we built ourselves run only against our own admin.utilfoundry.com, never a third party:
- The "Give feedback" button is entirely voluntary. If you open it and press Submit, we store what you typed — your message, an optional star rating, and which tool you were on if you leave "include tool details" checked. Nothing is sent unless you press Submit, and none of it is the JSON, YAML or other input you were formatting.
- An anonymous visit signal is sent for each page you view: which page, and a coarse location (country, region, city) resolved from your IP address by an offline lookup table we run ourselves. Your IP address itself is never stored.
admin.utilfoundry.comsets one cookie — a random id, not your identity — so a repeat visit can be told from a new one; this site itself does not set or read that cookie.
What is stored on your device
A theme cookie, sidebar preferences and optional workspaces, all kept on your device:
uf-themeis a cookie, not local storage, holding your chosen colour theme. It is readable on every utilfoundry.com subdomain, which is the point - a theme chosen here or in another UtilFoundry app carries over to the other - and holds nothing that identifies you.utilfoundry-dev-sidebar-prefsholds the sidebar's lists: the tools you starred as favorites, the last eight tools you opened (recorded as you open them) and the categories you collapsed. It names tools and categories only, never anything you typed into a tool.utilfoundry-workspacesis an IndexedDB database on this device. Manual saves are written only when you press Save workspace. If you enable Remember work on this device for a tool, its editor input and non-secret options are also saved as an automatic draft. Saving is off by default. Workspaces expire seven days after their last save; expired records are removed when the app next checks storage. Limits are 30 workspaces and 100 MB of payload per origin, with a 32 MB limit per workspace. Your browser can impose a lower limit or remove site data. Nothing is uploaded or synced. Export and import remain available for copies you manage yourself. The oldutilfoundry-dev-workspacesave can be recovered through Saved workspaces; it is removed only after successful migration or when you clear saved Developer work.
On a shared or public computer, treat a saved workspace the way you would treat any other file you left behind: use Clear all saved Developer work or clear site data before you walk away. Resetting tool options does not delete saved workspaces. Disabling autosave removes that tool's automatic draft, but does not remove manual saves. Browser storage is not an encrypted vault; sensitive tools disable saving, and detectable credentials pause it, but pattern checks do not catch every secret.
Sensitive input
Some tools here handle material that is sensitive by nature — tokens, keys, certificates, card data and payment protocol payloads. Running a tool checks your input for patterns that look like such material and shows a warning. That check is a courtesy reminder computed in your browser: it is not a data loss control, it does not catch everything, and nothing about it is reported to us. Use masked test data.
Server records
Our servers deliver the page and its assets, and nothing else. The front end is not configured to write access logs, so there is no stored record tying an IP address to your use of a tool. No request carries your input, so no log could contain it.
Your rights
Indian data protection law, and the GDPR where it applies to you, give you rights to access, correct and erase personal data held about you. We hold none: there is no account, no profile and no server-side record of your activity here. If you think otherwise, write to support@utilfoundry.com and we will answer. The same address is our grievance contact, and you may also complain to your data protection authority.
Children
This site is not directed at children, and we do not knowingly collect data from them.
Changes to this policy
If this policy changes in a way that matters, the date at the top of the page changes with it.
Contact
Questions about this policy go to support@utilfoundry.com.