Enforced by your browser, not just promised
Every page under /tools is sent with a Content-Security-Policy header. It tells your browser to refuse any network request to another website, along with form submissions and embedded frames. (Markdown pages may also load images; see below.) Even if a bug or a compromised script tried to send your input somewhere, your browser would block it.
The one exception: anonymous analytics
The site uses Vercel Analytics and Speed Insights. They send which page you opened and how fast it loaded to /_vercel/insights and /_vercel/speed-insights on this same domain. They never see or send anything you type, paste or open in a tool.
Images in Markdown: enforced by our code
The Markdown Previewer and Visual Markdown Editor are the one place where the policy allows images from other websites, because you can choose to show them. Until you tick “Load remote images”, our code swaps them for a placeholder, so this part is enforced by our code rather than your browser. Loading an image tells the website hosting it your IP address and that you opened the document; it never sends your text. The setting lasts until you close the tab.
Nothing is stored, except your Markdown draft
The tools don’t save your input anywhere, not on a server and not in your browser. Close the tab and it’s gone. The one exception is the Markdown tools, which keep your draft in this browser’s local storage so it’s still there when you come back. It never leaves your device, and “Clear draft” deletes it. Tokens and secrets are never stored.
Check it yourself
- Open your browser’s developer tools (F12, or ⌥⌘I on a Mac) and go to the Network tab.
- Use any tool: paste text, hash a file, generate UUIDs.
- Watch the list. Apart from the page itself and requests to
/_vercel/…, nothing appears. - To see the policy, click the page’s own request and look for
content-security-policyunder Response Headers.