// legal/

Privacy policy.

Last updated: September 7, 2026

Summary

Nearly every tool runs in your browser, and the files you put through those never leave your device. A named few do not work that way, and each of those says so on its own page before you type anything into it. An account is a separate matter again, and it does hold personal data. This policy covers all of it, along with cookies, analytics and advertising, and it tells you how to delete an account yourself.

Data Controller

ToolForte is operated by Toine.com B.V., registered with the Dutch Chamber of Commerce (KVK) under number 87544903. That company is the controller for the personal data described here. Write to contact@toolforte.com for any privacy question or request, or use the contact page.

What data we collect

Most of our tools process your files locally using JavaScript and WebAssembly, and nothing is uploaded. The exceptions are listed in the next section. If you create an account, we do hold personal data about you, which is set out in the account section below. We also count page views ourselves, and our website uses cookies for analytics and advertising purposes as described here.

What does not stay on your device

These are the parts of ToolForte that do not run entirely on your device. Each one is disclosed on the page where it happens, before the action, and this is the complete list: The page Where your data goes lists them one by one.

  • 12 tool pages send what you type to our servers. Four check a website you name, and our server fetches that page for you. Eight are the AI writing tools, where your text goes to our server and on to the model provider that generates the answer, currently Google (Gemini), under that provider's API terms; it is not used to train a model. We record that the call happened, for your usage history, and not what was in it.
  • 5 tool pages send your request straight from your browser to an outside company, without it passing through us: the currency converter, the DNS lookup, the domain checker, the WHOIS lookup and the IP address lookup. We never see what you looked up, and we cannot describe what those services keep, so each page names the service and links to its own policy. Not reaching us is not the same as not leaving your machine.
  • The render API and its MCP tools run headless Chrome on our servers. What you send is processed there, and the file it produces is stored in a private bucket and handed back as a signed link that expires after 24 hours. A daily job deletes the files themselves. This is the one place a document you gave us is written to disk at all, and it is not reachable by anyone without the signed link.
  • 30 tool pages remember your work between visits. That is done by your own browser on that one device, not by us: it is not on your other devices, and we cannot recover it for you.

Our own visit counting

Separately from Google Analytics, we count page views and tool openings ourselves. Each event records the path you were on, which tool it was, a random session id, and the host of the site that referred you if it was not us. It does not record an IP address, a raw browser string, or anything you typed into a tool. If you accept cookies the session id is kept for the length of your visit so page views join up; if you decline or have not answered, an id is generated in memory for that page load only and nothing is written to your device.

A workflow whose every step is pure computation runs in your browser, and what you put in and what comes back never reach us. One thing is sent when such a run finishes: that it happened, which ready-made workflow it came from if it came from one, how many steps it had, whether it finished or stopped at a failing step, and how long it took. Never an input, never an output, never anything written into the steps themselves, and never the workflow's name or id. We would rather list those fields than call it anonymous usage data, which names a category instead of a list. The same sentence appears next to the run button, so it is readable at the point of the decision rather than only here.

The AI tools and the render tools have a small free daily allowance for visitors who are not signed in. To make that allowance hold we have to recognise the same visitor twice on one day, and for that we store a one-way fingerprint of your network address: your IP address with a secret only our server knows, run through SHA-256. The result cannot be turned back into an address, it is never shown to anyone, and the row holding it says nothing beyond which kind of action was counted and how often. These rows are deleted after two days, because a yesterday's counter answers no question. Your IP address itself is never written down.

Accounts, and deleting one

An account is optional and the browser tools work without one. If you have one, this is what it holds:

  • Your email address, and the plan, credit balance and settings on the account.
  • API keys, stored as a hash rather than as the key itself, and a log of the requests made with them.
  • Saved workflows, their run history, and anything an AI assistant stored in agent memory on your behalf.
  • Payment records. Card details are handled by Stripe and we never see them.
  • Usage and traffic counts. These never include an IP address or a raw browser string.

You can delete your account yourself from your account page. It is not a request we process by hand: it runs when you confirm it, it cannot be undone, and if you have a subscription it is cancelled with Stripe first. These lists are rendered from the same code that performs the deletion, so they describe what actually happens rather than what we intend to happen.

Deleted
  • Your email address, plan, credit balance and account settings
  • Every API key you created, and every request made with one of them
  • Everything your AI assistant stored in agent memory
  • Your saved workflows, the folders you filed them in, and their full run history, previews included
  • Your favourite tools
  • Any message you sent us through the contact form while signed in, including the name and address you put on it
  • Your sign in credentials, including any GitHub or Google connection
Kept, with your user id removed

Billing records: what you paid, what you spent it on, and when. Your user id is removed from them, so they no longer point at you.

Bookkeeping law requires a financial record to be kept for 7 years, so this is the one thing we cannot delete on request. The GDPR says the same: the right to erasure does not cover data we are legally obliged to retain.

Usage and traffic counts. Your user id and API key id are removed from them.

These rows never held an IP address or a browser string, and once the identifiers are gone they are aggregate numbers rather than data about you. Deleting them would corrupt historical totals without making you any more anonymous than removing the identifier already does.

Stripe's own record of any payment you made, including the invoices and the email address on them.

Stripe processes payments for us and keeps its own books for the same 7 year reason. We cancel your subscription and stop being able to charge you, but we cannot erase an invoice from their ledger, and we would rather say so than imply otherwise.

Cookies

Our website uses cookies that fall into the following categories. The banner asks about analytics and advertising separately, and the footer's "Cookie settings" link lets you change your answer at any time. None of the tools need a cookie: a tool runs in your browser and keeps its state in memory or in this browser's local storage, so declining every category changes nothing about what any tool does.

Essential Cookies

These are necessary for the website to function: your theme preference (light/dark mode) and the cookie choice itself. They do not collect personal data and are not offered as a choice, because the site does not work without them.

Analytics Cookies

We use Google Analytics to understand how visitors use our website. Google Analytics uses cookies to collect anonymized data such as page views, session duration, and device information. IP addresses are anonymized before processing.

Advertising Cookies

Google AdSense and its partners may place cookies on your device to display advertisements. Without your consent AdSense runs in its consent-mode denied state, which serves non-personalised advertising without storing an advertising cookie. You choose on your first visit and can change the answer from the footer.

Google AdSense

ToolForte uses Google AdSense to display advertisements. You can opt out of personalized advertising via Google Ad Settings or the Network Advertising Initiative opt-out page.

Google Analytics

We use Google Analytics to collect aggregate, anonymized statistics about how our website is used. IP addresses are anonymized before any processing. You can opt out via the Google Analytics Opt-out Browser Add-on.

Your Rights (GDPR)

If you are located in the European Economic Area, you have the following rights under the GDPR:

  • Right to access: request a copy of the personal data we hold about you
  • Right to rectification: request correction of inaccurate data
  • Right to erasure: delete your account and its data yourself, without asking us
  • Right to restrict processing: request that we limit how we use your data
  • Right to data portability: request your data in a portable format
  • Right to object: object to our processing of your personal data

The right to erasure does not need a request. If you have an account, you can delete it yourself from your account page, and it runs immediately rather than going into a queue. What survives it, and on what basis, is set out in the section above.

To exercise any of the other rights, write to contact@toolforte.com. We will respond within 30 days. If you are not satisfied with our answer you can complain to the Dutch data protection authority, the Autoriteit Persoonsgegevens.

Your Rights (CCPA)

If you are a California resident, you have rights under the CCPA including right to know, right to delete, right to opt-out of sale (we do not sell data), and right to non-discrimination. The right to delete is the same self-service deletion described above. Write to contact@toolforte.com to exercise the others.

Data breaches

If a breach of security leads to the loss, disclosure or alteration of personal data, we report it to the Autoriteit Persoonsgegevens within 72 hours of learning about it, as the GDPR requires, and we tell the people affected directly and without undue delay when the breach is likely to put them at risk.

Data Protection Officer

ToolForte is operated by Toine.com B.V. is not required to appoint a Data Protection Officer under Article 37 of the GDPR: it does not process personal data on a large scale, and its core activity is not monitoring people. Privacy questions and requests go to contact@toolforte.com and are answered by the company's director.

Children's Privacy

ToolForte is not directed at children. Under Dutch law a child needs a parent's consent to give an online service personal data until the age of 16, so an account is for people of 16 and over. We do not knowingly collect personal data from anyone younger, and we delete it when we learn of it.

Data Retention

A file you put through a browser tool is never stored on our servers, because it is never sent to one. Where a tool does send something to us, listed in the exceptions above, we process it and do not keep the content: what remains is the record that a call happened, for your usage history. The single exception to that is the render API, whose output file is kept for 24 hours behind a signed link and then deleted. Account data is kept for as long as the account exists and goes when you delete it. Agent memory is deleted automatically once it passes your plan's retention window, whether you delete the account or not. Analytics data collected through Google Analytics is retained for 14 months by Google and then deleted.

The one exception is billing records. Bookkeeping law requires a financial record to be kept for 7 years, so those survive an account deletion with your user id removed from them. That is the same statement as the one in the account deletion section above, because both are rendered from the same place in our code and cannot drift apart.

Chrome Extensions

This privacy policy also applies to all Chrome extensions published by ToolForte. The extensions do not collect or store personal data, and they carry no analytics or advertising code. A small number of features cannot be completed on the device alone and call an outside service to finish the job; each extension's Chrome Web Store listing states the permissions it asks for and why. The extensions are built and released separately from this website, so treat the store listing as the authority on any individual one.

External Links

Our website may contain links to external websites. We are not responsible for the privacy policies or content of those websites.

Changes to This Policy

We may update this privacy policy from time to time. When we make changes, we will update the date at the top of this page.

Contact

Questions about this privacy policy? Contact us at contact@toolforte.com or visit our contact page.