Privacy Policy
Our Privacy Commitment
At tolio, we believe privacy is a fundamental right. This policy outlines our approach to data handling in plain, transparent language. Unlike most websites, our answer to most data privacy questions is simple: we do not collect anything. Every tool on this platform is designed to run entirely on your device using client-side processing, meaning your data never leaves your browser. There are no servers processing your inputs, no databases storing your activity, and no third-party services analyzing your behavior.
Information We Collect
We collect no personal information. tolio does not require registration, does not ask for your name, email address, or any other personal identifier. We do not maintain user accounts, and we have no way to associate tool usage with any individual person.
The platform uses Google Analytics 4 (GA4) as a privacy-preserving analytics service. GA4 is configured with IP anonymization enabled. This means your IP address is truncated (made anonymous) before any data is logged or stored, and it is never shared with Google as a full IP address. Google Analytics collects non-personal information such as the pages you visit, the type of browser and device you use, and general geographic region (country/city level) -- all without identifying you personally. We use this anonymous, aggregated data to understand which tools and features are most useful so we can improve the experience for everyone. GA4 data is retained for 14 months and then automatically deleted.
We do not use Mixpanel, Hotjar, Facebook Pixel, or any other analytics or tracking service. We do not track page views, session durations, click patterns, mouse movements, scroll depth, or any other user behavior metrics beyond what GA4 provides in its standard anonymized reports. Our hosting provider may record standard server logs (such as the date and time of a page request and the requested URL) for operational purposes such as error detection and abuse prevention, but these logs are not used for profiling, advertising, or any form of user tracking.
We do not use fingerprinting techniques, canvas fingerprinting, or any other method to identify or track users across sessions or across different websites. There are no tracking pixels, web beacons, or embedded third-party content that could exfiltrate data about your visit.
Local Storage and Cookies
tolio does not use cookies for tracking, advertising, or analytics purposes. The only browser storage mechanism we use is the localStorage API, and it is used exclusively for one purpose: saving your theme preference (light mode or dark mode). When you toggle the theme using the button in the header, your choice is stored locally on your device using localStorage. This data is never transmitted to any server, is not accessible by any third party, and is not used for any purpose other than remembering your theme preference across page loads and visits.
You can clear this data at any time through your browser's settings or by clearing your site data. Doing so will simply reset your theme preference to the system default. No functionality of the tools themselves will be affected because all tool processing is stateless and session-based — nothing persists after you leave or refresh the page except your theme choice.
How Your Data Is Processed
All tool functionality is implemented using client-side JavaScript that executes within your browser's sandboxed environment. When you paste text into a tool — whether it is a JSON document, a URL, a block of code, or any other content — the processing happens locally using your device's CPU and memory. No data is transmitted over the network to any server for processing.
This architecture means that your content — including sensitive data such as API keys, passwords, personal documents, or proprietary code — never leaves your device. There are no API endpoints that receive your input, no databases that store your activity history, and no server logs that record the content you processed. The only network requests made by the site are for loading the page itself (HTML, CSS, JavaScript files, and static assets) from our hosting provider or CDN.
Because all processing is local, there is no data retention period to define — we simply never have access to your data in the first place. Your information exists only in your browser's memory during your session and is discarded the moment you close the page or navigate away.
Third-Party Services and Embedded Content
tolio does not embed content from third-party services. There are no social media share buttons, no comment systems, no external font services that track usage, and no embedded videos or widgets that communicate with external servers. The site loads its own assets from its own hosting infrastructure.
The only external dependency is our hosting provider and CDN, which serve the static files that make up the website. These providers may have their own logging practices (such as standard HTTP request logs) but they do not have access to the content you process within any tool. We use standard HTTPS encryption for all connections to ensure that the page assets you download are authentic and have not been tampered with in transit.
Children's Privacy
tolio is a general-purpose tool website and is not directed at children under the age of 13. We do not knowingly collect any personal information from children. Since we do not collect any data from any user — regardless of age — there is no risk of inadvertent data collection from minors. Nevertheless, if you are a parent or guardian and have concerns about your child's use of this website, please contact us.
Changes to This Policy
We may update this privacy policy from time to time to reflect changes in our practices or for legal compliance. When we make changes, we will update the "Last updated" date at the top of this page. We encourage users to review this policy periodically to stay informed about how we are protecting your privacy. Since our approach to privacy is fundamentally minimal — we collect nothing — any future changes are likely to maintain or strengthen this commitment rather than weaken it.
Your Rights
Under data protection regulations such as the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA), you have rights regarding your personal data. Since we collect no personal data, most of these rights are inherently satisfied: there is no data for us to delete, export, or correct. However, if you have any questions or concerns about your privacy while using tolio, please reach out to us and we will address them promptly.
Because we do not collect, process, or store any personal data, we are not required to appoint a Data Protection Officer. If you wish to make a complaint about our privacy practices, you may contact us directly or reach out to your local data protection authority.
Contact
If you have questions about this policy or our data practices, contact us. We are happy to provide clarification about any aspect of how tolio handles — or more accurately, does not handle — your data.