Home/Privacy

Privacy Policy

Last updated 28 July 2026

TinyWebTools is built so that most of what you do here never reaches a server at all. This page explains exactly what happens to your data, including the three places where something does leave your device.

The short version

  • We do not ask you to create an account, and there is nothing to sign up for.
  • We run no advertising, and nothing here profiles you or is sold on.
  • We do count visits, using analytics software we run on our own server. It is configured without cookies, so nothing is written to your device and the data never leaves our machine.
  • One optional extra, for recording how a page is used, does set a cookie. It stays switched off unless you agree, and refusing costs you nothing.
  • Eleven of our fourteen tools process your files entirely inside your browser. Nothing is uploaded.
  • Three tools need a server to work. They are named below, and what they send is described precisely.
  • We never sell or rent your data. We pass it on in exactly one case, described below: a web address given to Webpage to Markdown goes to a third-party fetching service when, and only when, the site has already refused our own request.

Tools that never send anything

These run completely in your browser using standard web APIs. Your file is read from disk into memory, processed, and handed back to you as a download. Closing the tab erases everything:

  • HEIC to JPG, Image Converter, Image to PDF
  • Merge PDF, Split PDF, Compress PDF
  • Remove EXIF Data, Video to GIF, Screen Recorder
  • Invoice Generator, 2FA Code Generator

The Screen Recorder is worth singling out. There is no server component to it whatsoever, so your recording could not be transmitted even in principle. It exists only in your browser's memory until you save it.

The three tools that use a server

Grammar Checker. The text you submit is sent to OpenRouter, which routes it to a language model to produce corrections. Your text is not written to any log or database on our server. It is handled in memory, passed on, and the result is returned to you. OpenRouter and the model provider it selects will handle your text under their own policies, so do not paste anything confidential.

Search. Your search query is sent to a third-party search API, which returns organic results that we render without advertising or trackers. Queries are not logged on our server.

Webpage to Markdown. The address you paste is fetched by our server, because a browser is not permitted to read a page from another site. The page is converted in memory and the result is returned to you. The address and the fetched page are never written to a log, a database or a cache. If you would rather nothing was fetched at all, use the tool's Paste HTML tab, which converts markup you already have without contacting anything.

Some sites refuse any request coming from a server, whatever it asks for. When that happens, and only then, the address is passed to scrape.do, a third-party fetching service, which retrieves the page and hands it back to us to convert. Two things follow from that, and we would rather state them plainly than bury them:

  • In that situation the address you typed is seen by scrape.do as well as by us, and is handled under their privacy policy rather than ours. The page content passes through them too.
  • It does not happen on an ordinary page. The fallback is only reached after a direct fetch has already been refused, and the result is labelled "fetched via scrape.do" on the page itself, so you can always tell which route was used.

Nothing about that step is stored by us either. If you would rather no third party ever saw the address, use the Paste HTML tab instead.

Each of those tool pages states this on the page itself. If a tool sends data anywhere, we say so where you use it, not only here.

What our server does record

Three things, all minimal:

  • Abuse prevention. The three server-backed tools keep a short-lived record of a one-way hash of your IP address together with request timestamps, purely to enforce a rate limit. It is stored in a temporary directory, holds no request content, and is not used for anything else.
  • Standard web server logs. Our host records ordinary access information such as IP address, timestamp and requested URL, as essentially every web server does. Our CDN provider, Cloudflare, also processes requests in order to serve the site.
  • Visit statistics. We use Cloudflare Web Analytics, which counts the page you viewed, the site or search engine that sent you, your approximate location, and your browser, device type and screen size. It is cookieless by design: nothing is written to your device, no identifier is assigned to you, and you are not followed between visits or across other sites. The figures we see are aggregate counts, never a profile of one person. The data is not shared or sold, and there is no advertising network involved, because Cloudflare does not run one. If your browser sends a Do Not Track signal, the script does not run at all.

We use this for one purpose: seeing which tools people actually need, so we build the right ones next.

The one thing we ask permission for

Counting visits tells us which page you used. It does not tell us where a layout confuses people. For that we would like to record how a page is used: where a cursor moves, what gets clicked, where people give up. That is done by Microsoft Clarity, it sets a cookie, and it is genuinely more intrusive than counting, so it is off until you say otherwise.

  • You are asked once, in a small bar at the bottom of the page. There is no pre-ticked box and no dark pattern: refusing is one click and we do not ask again.
  • If you refuse, or simply ignore it, nothing from Clarity ever loads. No cookie is set and no request is made to it.
  • If you accept, Clarity records the interaction on the page. It does not read the contents of any tool you use: your files, your text and your results never reach it, because they never leave your browser in the first place.
  • Everything else on this page still applies. Visit counting carries on cookie-free whatever you choose.

Storage in your own browser

We use your browser's local storage for two conveniences, both of which stay on your device and are never transmitted:

  • Your light or dark theme preference.
  • In the Invoice Generator only, and only if you tick the box, your own business details so you need not retype them. Your client's details and the invoice amounts are never saved.

Clearing your browser data removes both.

Children

These are general-purpose utilities not directed at children, and since we collect no personal information and offer no accounts, we do not knowingly hold data about anyone, including children.

Your rights

Regulations such as the GDPR and the CCPA give you rights to access, correct and delete personal data held about you. In our case there is very little to exercise those rights against, because we do not build profiles, do not use cookies, do not retain the content you process, and use visit statistics that assign you no identifier at all. If you believe we hold something about you, write to us and we will help. You can also stop the statistics entirely by turning on Do Not Track in your browser, which we honour.

Changes

If this policy changes in a way that affects what happens to your data, we will update the date at the top and describe the change here.

Contact

Questions about privacy can go to the address on our contact page.