Public policy

Privacy Policy

Introduction

This Privacy Policy explains how TheOnlineToolset handles personal data when you visit the site or use its online tools. The service is designed to operate without user accounts and to minimize the personal data needed to provide a requested tool.

Who operates the service

TheOnlineToolset is operated by the person or entity responsible for this deployment. This operator is the controller of personal data described in this policy where applicable.

Scope

This policy covers the public website, browser-only tools, server-backed file tools, related technical operations, and privacy communications. Use of the service is also governed by the Terms of Service and Acceptable Use Policy. This policy does not govern third-party sites linked from the service or a third party’s own processing.

Information you provide

Depending on the tool, you may provide files, text, selected processing options, output names, or similar instructions. If you contact us by email or through the configured contact form, we receive the address, message, and other information you choose to send. The contact form does not accept attachments. The website does not currently provide an account system.

Please do not submit information that is unnecessary for the requested operation, and do not send passwords or complete sensitive files in support messages.

Uploaded and generated files

Browser-only tools perform their working operation on your device. Server-backed tools send the files and options you select to the service for processing and return a generated result. Uploaded files are processed automatically solely to perform the operation you request.

File contents are not sold, used to train artificial-intelligence models, or used to build advertising profiles. Uploaded file contents are not intentionally sent to analytics or advertising services.

Automated processing and limited human access

Normal file processing is automated. Files are not routinely accessed or manually reviewed, and human access is not part of normal processing. Exceptional access may occur only when reasonably necessary to investigate security or abuse, provide technical support you request, comply with law, or protect users, rights, or the service. Access does not mean that every issue can be investigated or that an expired anonymous file can be recovered.

Temporary retention and deletion

Uploaded and generated files are retained temporarily. Under the current standard configuration, a completed upload that is never submitted to a processing job normally expires after about 30 minutes; files attached to a job normally expire after processing is no longer active and the short configured upload window ends; generated downloads normally expire about 10 minutes after completion. Configuration can vary by tool or deployment.

Expiry is a target for making files and links unavailable and scheduling cleanup, not a promise of deletion at an exact second or irreversible erasure from physical media. Cleanup or exceptional recovery copies may persist longer because of active processing, interrupted operations, safe-state checks, storage or service failures, security investigations, legal obligations, maintenance, or disaster recovery. Files may also be deleted sooner because of storage limits, security concerns, maintenance, cancellation, or system cleanup.

The service is not a backup, archive, or permanent-storage provider. Download results promptly and keep your own original copies. More detail appears in the File Retention and Deletion policy.

Technical information collected automatically

The service and its infrastructure may process IP address, request date and time, requested route, response status, browser and device information, referring page, network and protocol information, security signals, and identifiers associated with an upload or processing job. Processing options, file type, size, and validation or status metadata may also be recorded where needed to perform and support a job.

Operational logs currently may include original filenames, identifiers, timestamps, file sizes, status details, and error categories. The application is not designed to write file contents into logs. Error records are filtered to reduce exposure of exception details, commands, credentials, and system locations, but unexpected user data may still appear in diagnostic records. Avoid sensitive filenames where possible.

IP addresses and abuse prevention

IP addresses are processed to route requests, enforce request and upload limits, prevent abuse, protect capacity, and investigate security events. Some short-lived operational records store the address; some controls use a derived identifier instead. Rate-limit records currently expire on short windows ranging from about one minute to one day, while security logs may follow separate schedules set by the operator or infrastructure providers.

Cookies and local storage

The current application uses a minimal, versioned local-storage record to remember privacy preferences. The record contains consent categories, a policy version, and decision timestamps; it does not contain uploaded filenames, file identifiers, tool outputs, profile data, or advertising identifiers. It normally expires after 180 days, and a material policy-version change can request a new choice. If you enable recent-tool history, a separate local-storage record records tool routes and timestamps.

The application code does not currently set first-party HTTP cookies, although optional third-party services may use cookies or similar technologies if enabled.

See the Cookie Policy or . Browser settings can also clear or block stored data.

Analytics

No analytics integration is currently active. It may become active only when explicitly configured and consented. Google Analytics 4 may be enabled as a consent-gated audience measurement service. When consented, Google may receive ordinary device/browser information, GA cookies, and approximate location inferred from network information to measure tool usage. Uploaded filenames, file contents, IDs, private URLs, and generated outputs are not sent. Analytics can be declined or withdrawn through Privacy choices and browser controls.

Advertising

Advertising is disabled by default. Development placeholders are neutral layout elements and do not load advertising services. If Google AdSense is later enabled only after configuration, legal-readiness, and consent controls are complete, Google and its partners may process device and browser information, IP-derived approximate location, cookies or similar identifiers, and ad interactions under their own terms and your applicable choices. Uploaded file contents must not be intentionally sent to advertising services.

You can review the Cookie Policy and .

How information is used

We use information to provide the selected tool, validate inputs, generate and deliver results, maintain availability, enforce limits, prevent fraud or abuse, troubleshoot failures, improve reliability and accessibility, respond to communications, comply with legal duties, and establish or defend legal claims. We do not use file contents for unrelated marketing.

Legal bases where applicable

Where the GDPR, UK GDPR, or similar laws require a legal basis, processing needed to provide a tool or respond to a request is generally based on taking steps at your request or performing our agreement with you. Security, abuse prevention, service improvement, and legal-claim processing may rely on legitimate interests, balanced against your rights. Legal compliance relies on applicable legal obligations. Optional analytics or advertising technologies rely on consent where consent is required. We may process information to protect vital interests or perform tasks in the public interest where those bases genuinely apply.

Service providers and processors

We may use contracted infrastructure, networking, security, content-delivery, email, diagnostics, and professional-service providers to operate the service. They may receive file data or technical request information only as needed for their role and subject to appropriate contractual or legal restrictions where required. Publicly loaded font, interface-library, and content-delivery resources can receive ordinary request information, including IP address and browser details.

The exact production-provider list, contracts, processing locations, subprocessors, backup practices, and log-retention settings are deployment decisions that the operator must verify and document before launch.

Disclosure required by law

We may preserve or disclose information when reasonably believed necessary to comply with valid legal process or applicable law, enforce terms, investigate abuse or security incidents, protect rights or safety, or establish and defend legal claims. We do not promise to notify a user when notice is prohibited or impracticable.

Security safeguards

The service uses safeguards intended to reduce risk, including input validation, access restrictions, traffic controls, temporary storage, expiring links, containment checks, and reduced-detail public errors. No transmission, storage, or processing system is completely secure. Files are not represented as end-to-end encrypted, and anonymous download links should be treated as confidential because a person with a valid link may be able to retrieve the result.

International data transfers

Depending on where you use the service and where the operator and providers process data, information may be transferred to a country with different privacy laws. Where legally required, the operator should use an approved transfer mechanism and supplementary safeguards. The operator must confirm actual processing locations before production.

Data retention

File retention is described above. Completed job and upload metadata commonly remains from minutes to approximately one day under current defaults, depending on the record and tool; active or recovery state can persist longer. Browser history and preference records remain until cleared. Correspondence, security events, infrastructure logs, backups, caches, and legal records follow separate periods based on operational need, contract, law, and the operator’s documented schedule. We retain personal data no longer than reasonably necessary for the stated purpose, subject to those constraints.

Your privacy rights

Depending on your location and applicable law, you may have rights to request access, correction, deletion, restriction, portability, or objection; withdraw consent; opt out of certain targeted advertising, sale, or sharing; and complain to a privacy regulator. Rights may be limited by law, security, the rights of others, or our inability to identify an anonymous job after expiry.

We may ask for information reasonably necessary to verify a request. Do not send the original sensitive file. Authorized agents may be required to show authority. We do not discriminate against users for exercising applicable privacy rights.

GDPR and UK GDPR rights

Where the GDPR or UK GDPR applies, you may exercise the rights described above and complain to the supervisory authority where you live or work or where an alleged infringement occurred. You may withdraw consent at any time without affecting processing already lawfully performed. Where processing relies on legitimate interests, you may object based on your particular situation.

California privacy rights

Where California law applies, residents may request information about categories and specific pieces of personal information collected, sources, purposes, and disclosure recipients, and may request correction or deletion. The service does not currently sell personal information or share it for cross-context behavioral advertising as those terms are defined by California law. If that practice changes, an applicable opt-out method and updated notice must be provided before activation.

The categories potentially processed are identifiers such as IP address, internet or electronic activity, user-provided file or communication information that may fall within customer-record categories, and inferences limited to security or service operation. We do not intentionally use or disclose sensitive personal information to infer characteristics about users.

Do Not Track and Global Privacy Control

Browsers do not provide a uniform Do Not Track standard, and the current site does not respond separately to Do Not Track signals. The preference controller treats a supported Global Privacy Control signal as an opt-out of optional analytics and advertising in this browser. Because no analytics is active and advertising is disabled by default, these categories do not currently initiate those integrations.

Children’s privacy

The service is not directed to children under 13, or a higher minimum age where local law requires it, and we do not knowingly collect personal data from children for account or marketing purposes. A parent or guardian who believes a child submitted personal data may contact us to request review and deletion where possible.

Third-party links

Links to third-party websites are provided for convenience. Their privacy, security, and content practices are governed by their own notices, not this policy.

Changes to this policy

We may update this policy when the service, providers, or legal requirements change. The effective date on this page will be revised. Material changes should receive additional notice where required.

Contact

Privacy requests and questions may be submitted through the contact information page or by email to [email protected]. Include enough information to understand the request, but do not attach passwords or full sensitive files.

See the Cookie Policy and Privacy Policy.