Privacy Policy
Effective date: October 5, 2026
ToolSnack (“the service”) keeps the data it handles to a minimum. There are no accounts, and most tools process what you enter only inside your browser. This policy explains the little that is processed elsewhere.
1. Why we process data
- To receive and answer questions, bug reports and tool suggestions
- To provide the tool that needs a server (server time check) and to prevent abuse (rate limiting)
- To keep the service running and secure (access logs)
- With your permission, to count page views and tool interactions and use configured analytics services
We do not use personal data for advertising, marketing or profiling.
2. What we process
| Where | Data | When |
|---|---|---|
| Contact and tool-suggestion form | Your message, your email address (only if you enter one), the address of the page you sent it from, a hashed IP value, the time received | When you send the form |
| Server-based tool (server time check) | The target address you enter, request metadata, a hashed IP value | When you run the tool |
| Rate limiting | A hashed IP value (salted SHA-256), a request count, a time window | When you use either feature above |
| Server access logs | IP address, time, requested URL, browser information | When you visit the site or API (recorded automatically by the web server and CDN) |
| Optional aggregate analytics | Page path and language, date, event type (page view, tool interaction, copy or download), coarse referral source and device category, and a random browser identifier on page views only | After the operator enables analytics and you explicitly allow it |
- We never store your raw IP address in our database, only a salted hash that cannot be reversed.
- Your email address is optional and only used to reply. You can send the form without one.
- Tools that process files and input in your browser (images, PDFs, text and so on) do not send that content to a server.
- The server time tool makes a request to the address you enter and reads the date in the response. We do not store the result or the address in our database, but the requested URL may appear in server access logs.
- The speech-to-text tool uses the speech recognition built into your browser, and that recognition is handled by the browser maker’s service: Google for Chrome on computers and Android, Microsoft for Edge, and Apple for Safari and for every browser on iPhone and iPad, including Chrome and Edge there (on the device or on Apple’s servers, depending on the device, language and settings). That processing follows each company’s own privacy policy and is not a transfer by us to a third party. Neither the audio nor the transcript reaches our server.
3. How long we keep it
| Data | Retention |
|---|---|
| Rate-limit records | About 1 day. Records older than a day are deleted automatically on the next request. |
| Messages and suggestions (including email and hashed IP) | Deleted within 1 year of receipt, or immediately on your request. |
| Server access logs | Rotated and deleted by the server log rotation, in about 14 days. |
| Daily aggregate analytics | Reports cover the most recent 90 days. We retain counts by date, page path and browser identifier hash, without the original identifier or individual visit timestamps. Older data is deleted when events are collected, reports are read or the cleanup command runs. |
4. What is stored in your browser
The service stores the items below on your device. Tool drafts are not sent to our servers. If you allow analytics, external services may also use cookies or browser storage (section 10). You can clear stored data with your browser’s site-data controls.
Cookies
| Name | Purpose | Lifetime |
|---|---|---|
lang |
Remembers the language you chose so the start page can send you there | 1 year |
Browser storage (localStorage)
| Key | Tool | What is stored |
|---|---|---|
theme |
Whole site | Your light or dark choice |
toolsnack:analytics-consent:v1 |
Whole site | Your analytics choice and its time; the choice expires after 180 days |
toolsnack:analytics-visitor:v1 |
Optional internal analytics | A random browser identifier and creation time, created only after consent; expires 90 days after creation and is replaced or removed on next use |
toolsnack:character-counter:draft |
Character counter | The text you are writing (only if you turn on “keep a draft in this browser”) |
toolsnack:character-counter:draft-optin |
Character counter | Whether you turned the draft option on |
toolsnack:markdown-preview:draft |
Markdown preview | The text you are writing (only if you turn the draft option on) |
toolsnack:markdown-preview:draft-optin |
Markdown preview | Whether you turned the draft option on |
toolsnack.gpa-calculator.v1 |
GPA calculator | Your courses, credits and scale settings |
toolsnack.wheel.lists |
Wheel spinner | The lists you saved |
toolsnack:seat-arrangement:v1 |
Seating chart | Names, rows and seats, locked and empty seats (only after you press “Save in this browser”) |
toolsnack.lunch.recent |
Lunch menu picker | Recently picked menus |
toolsnack.lunch.excluded |
Lunch menu picker | Menus you excluded |
toolsnack.lunch.recentCount |
Lunch menu picker | How many recent menus to avoid |
toolsnack:online-timer:v1 |
Online timer | Duration, volume and notification settings |
toolsnack:pomodoro-timer:v1 |
Pomodoro timer | Focus and break settings, progress, sound and notification settings |
toolsnack:stopwatch:v1 |
Stopwatch | The running time and lap records |
toolsnack:world-clock:v1 |
World clock | The cities you chose and working hours |
toolsnack:special-characters:recent |
Special characters | Recently used characters |
toolsnack:period-calendar:v1 |
Period calendar | The period start dates you saved |
toolsnack:baby-feeding-timer:v1 |
Baby feeding timer | Feeding records (start and end times, side, amount) and a feed in progress |
toolsnack:eye-20-20-20-timer:v1 |
20-20-20 eye break timer | Work and break lengths, progress, sound and notification settings |
toolsnack:eye-chart-test:v1 |
Eye chart test | Screen size calibration and viewing distance |
toolsnack:nickname-generator:favorites |
Nickname generator | Nicknames you saved as favorites |
toolsnack:emoji-picker:v1 |
Emoji Search | Recently used emoji and the chosen skin tone |
toolsnack:typing-speed-test:v1 |
Typing speed test | Best and last five speeds per language (the text you type is not stored) |
toolsnack:reaction-time-test:v1 |
Reaction time test | Best and last five 5-try averages |
Some share links put your input after the # in the address. Browsers do not send anything after the # to a server.
5. Sharing with third parties
If you allow optional external analytics, enabled providers may process information directly from your browser (section 10). We may also provide information in response to a lawful request. See section 2 for the browser’s speech-recognition processing.
6. Service providers
To deliver pages and run the servers we rely on outside infrastructure. These providers may automatically process connection data as part of running their service.
- Page delivery (HTML, CSS, JavaScript): a cloud hosting and CDN provider (Cloudflare)
- API and database: a server rented and operated for the service
7. Deletion
When retention ends or the purpose is fulfilled, we delete the data without delay. Data in the database is deleted in a way that cannot be recovered.
8. Your rights
You can ask at any time to see, correct, delete or stop the processing of your personal data. To have a message you sent removed, use the contact page and include the email address you entered and what you want removed. We act on it after confirming it is you. Because IP addresses are stored only as irreversible hashes, we may not be able to find the records of a specific visitor.
9. Security measures
- We store only a salted SHA-256 hash, never the raw IP address.
- Connections to the site and API are encrypted with HTTPS.
- Access to the database and servers is limited to the operator, and credentials and secrets are not kept in the source code.
- We keep what we process to the minimum. There are no sign-ups or logins.
10. Advertising and analytics
Analytics is disabled by default. Even when the operator enables it, aggregate events and external analytics scripts run only after you select Allow analytics. Reading the configuration does not require analytics consent. All tools remain available when you decline.
Our own statistics count page views and tool interactions per day for the most recent 90 days. Older data is deleted when events are collected, reports are read or the cleanup command runs. Interactions do not represent successful calculations or unique visitors. Analytics payloads do not include inputs, files, raw IP addresses, search terms, URL query strings or fragments, or referring page paths. Referral information is reduced to broad categories such as search engine, AI service, social or direct. Rate limiting uses a salted IP hash.
With consent to internal analytics, we store a random UUID in this browser to distinguish repeat visits. It is a pseudonymous browser identifier, not a real-name identifier. It is sent only with page views. The server stores a keyed hash (HMAC) and counts by date and page path, never the original identifier. The browser identifier expires 90 days after creation; repeat visits do not extend its lifetime. Declining, withdrawing or sending DNT/GPC removes it from browser storage, and withdrawal is reflected in other open tabs.
Unique visitors means consenting browsers, not people. Another device or browser, clearing site data, or identifier expiry can count as a separate visitor. If storage is unavailable, we count page views without creating an identifier. Historical totals are not backfilled with unique visitor counts; reports indicate when only some page views support visitor measurement.
The operator can configure Google Analytics 4 or Google Tag Manager, Microsoft Clarity and additional analytics scripts. Analytics preferences lists the configured services and script names. External services may process IP addresses when connecting, browser and device information, page usage and cookies. Retention depends on each provider’s policy and settings. Google Tag Manager loads configured tags; processing depends on those tags. The operator must not install tags that collect tool inputs or files. We mask page and tool content for Clarity and deny advertising storage. External scripts do not load on addresses containing a query string or fragment.
Your choice is stored in this browser for 180 days. Use Analytics preferences in the footer to decline or withdraw consent. Do Not Track (DNT) and Global Privacy Control (GPC) signals override a saved grant. Withdrawal stops our events, sends denial signals to Google and Clarity, and reloads the page to unload running external code. Removing the browser identifier does not erase existing server counts before their retention period ends; without the identifier, locating a particular browser’s hash is difficult. You can also remove existing external-service cookies through browser site-data controls.
A refusal is also kept under the same key in sessionStorage for this tab’s lifetime, so withdrawal remains effective if persistent storage becomes unavailable.
We ask again when the enabled analytics services, their identifiers, custom script contents or the scope of internal measurement change. Internal analytics grants given before browser visitor measurement and earlier grants without an integration fingerprint require a fresh choice; a saved refusal remains in effect.
11. Contact
- Person responsible for privacy: the operator (reachable through the contact page)
- How to reach us: the contact form
12. Changes to this policy
When we change this policy we will post the changes and the effective date on this page. For changes that are less favorable to you, we will post a notice here at least 7 days before they take effect.
- Posted and effective: October 5, 2026