Privacy and Data Processing

Data handling depends on the tool you use. This page explains browser-local processing, network requests, saved preferences, account sync and usage analytics.

Local-first tools

Tools marked LOCAL ONLY perform their stated transformation in your browser. Examples include JSON inspection, code generation, JSONPath, JSON Diff, cron preview, ENV parsing, mock-data generation, local log analysis, Docker Compose checks, and HMAC JWT operations.

For these pages, the tool code is designed not to submit pasted content, selected files, signing secrets, or generated output to KivTools. Your browser may still retain data in its own form history or clipboard according to its settings.

Tools that may make a network request

Some utilities necessarily work with a URL, remote host, public lookup, or external browser capability. Those pages can send the value you provide to the endpoint required to deliver that feature. Read the notice on the specific page before entering credentials, private endpoints, personal data, or production secrets.

Do not paste confidential credentials, private keys, customer data, or production tokens into a tool unless the page clearly says it is processing the content locally and that behavior fits your risk requirements.

Browser preferences

The global tool finder stores recent tools, pinned tools, and a light/dark preference in this browser's local storage. They stay on this device unless you sign in and choose to synchronize the corresponding workspace preference.

Downloading a generated fixture or copying tool output is initiated by your browser. KivTools does not need an account for these local flows.

Usage analytics

KivTools uses Google Analytics 4 to measure page visits and understand which public tools are useful. Google Analytics receives standard page-view, referrer, browser, device, and language metadata under Google's own data-handling terms.

KivTools does not add pasted text, selected files, code, secrets, generated output, custom website shortcuts, or workspace contents to Google Analytics events.

Optional account sync

KivTools works without an account. If you create one, the server stores your email address, a one-way password hash, account timestamps, and the workspace preferences you choose to sync: favorite tool identifiers, custom group names and order, custom shortcut names, web addresses and cached-icon references, theme, language, homepage settings, and—only when enabled—recent tool identifiers.

Tool inputs, pasted code, selected files, secrets, generated output, and clipboard contents are never included in workspace sync.

When you use “Fetch details” for a website shortcut, the KivTools server requests only the public page and favicon needed to detect its display name and icon. Private, local, reserved-network, and non-standard-port targets are blocked; response sizes and redirects are limited. The page body is not added to your workspace, and accepted favicon bytes are cached behind a same-origin KivTools URL.

Signing out ends the account session but does not erase browser-local preferences; use your browser's site-data controls to remove those.

Use the page-level disclosure as the source of truth

KivTools is a utility site, not a secure secret vault. The data handling note shown on the tool you are using is the most specific description of that tool's behavior.

Recent tools: