AI
Toolbox

Privacy Policy

This policy explains how AI Toolbox handles data. Last updated: July 17, 2026.

Operator and contact channel

AI Toolbox is operated by its maintainers. Privacy questions or data requests can be submitted through the GitHub issue tracker. Reports are public, so do not include passwords, identity numbers, private keys, message content, or other sensitive data.

Tool input

  • Browser-only tools process input locally and do not upload that content to our server.
  • AI tools send content you deliberately submit to our server and then to the OpenAI API or an explicitly configured compatible model provider. Our application code does not intentionally retain prompts or results. The model provider may temporarily retain API requests for security and abuse monitoring under its own policy.
  • Burn-after-reading notes are encrypted in your browser. The server temporarily stores ciphertext for no more than five minutes and deletes it after the first successful view. The access code is not stored on the server.

Operational and security data

  • To enforce usage limits and prevent abuse, the server uses an IP address and a random 16-character anonymous device identifier generated by your browser. It does not read Canvas, screen, hardware, or other browser-fingerprint signals. Burst counters normally last 60 seconds, AI daily counters no longer than about 24 hours, and burn-note abuse counters about five minutes.
  • The anonymous device identifier, recent-tools list, and homepage temporary-storage keepalive timestamps remain in localStorage until you clear site data. Keepalive requests do not include your input content.

Service providers

Vercel provides hosting, cookie-free Web Analytics, and Speed Insights; Cloudflare Turnstile processes browser-environment signals to validate AI requests; the OpenAI API or an explicitly configured compatible provider processes AI requests. Vercel analytics retention depends on the site plan, and other providers retain necessary technical and security data under their policies. Sensitive-tool pages do not load site analytics or performance monitoring. See the Vercel Analytics notice, Cloudflare Turnstile documentation, and OpenAI data-use notice.

Purposes and legal bases

We process only what is necessary to provide the requested tool result, secure the service, prevent abuse, and understand anonymous page usage. Where applicable, processing is based on fulfilling your deliberate request, legitimate interests in service security, or consent where required. We do not sell personal information or use tool input for targeted advertising.

Your choices and rights

Do not submit sensitive information that is not needed for the task. You may disable browser storage, clear site data, stop using a tool, and request access, correction, deletion, restriction, or objection where applicable. Because the site has no accounts and rate-limit identifiers are short-lived counters, we may be unable to reconnect anonymous or expired records to a person. Where local law permits, you may also complain to your data-protection authority. We will update this page and its date when this policy changes materially.