Tools Pack

Privacy Policy

Last updated: September 6, 2026

Tools Pack (the "Service") is built with privacy in mind. Most tools run entirely in your browser; files do not leave your device unless clearly stated. We collect the minimum technical data necessary to operate and improve the Service.

Information We Collect

  • No personal data via forms: We do not ask for names, emails, or login. The "Request a New Tool" form accepts only tool details. Please do not include personal information in free‑form text.
  • Error reporting and product logs (production only): We use Sentry to receive a minimal, sanitized subset of client‑side error events and structured Sentry Logs for tool usage. Error reports may include an error message, a sanitized stack trace, the page path, and your browser user‑agent. Product logs may include only the tool name, action, destination, recommendation placement, conversion state, and aggregate counts or file sizes. We add no user or session identifiers.
  • Cookieless analytics: We use Vercel Analytics for aggregate visitor and page metrics. Tool usage is measured through the sanitized Sentry Logs described above.
  • Files and conversions: Conversions are performed client‑side whenever possible. Uploaded files are processed in your browser memory and are not transmitted to our servers, except where a specific tool explicitly states otherwise.

Product Analytics Boundaries

  • Limited event data: Product events may contain a page path, tool name, action, destination, recommendation placement, conversion state, and aggregate counts or file sizes.
  • Excluded content: We do not send filenames, file contents, entered timestamps, entered URLs, form text, query strings, account identifiers, user or session identifiers, request bodies, cookies, headers, or other user-provided values to product analytics.
  • Same-tab attribution: When you follow a recommendation to another tool, a short-lived sessionStorage marker records only the source, destination, placement, and whether conversion had finished. It is removed after the next real tool action or when the tab session ends.
  • Network layer: Analytics providers may process ordinary request information such as IP address, user agent, referrer, and time while delivering and aggregating an event. We do not add those values to the product-event payload.

Sentry Boundaries

  • No PII: We configure Sentry to avoid personal data (sendDefaultPii = false). We do not attach user profiles, IDs, emails, request bodies, cookies, or headers.
  • Sanitization: Request URLs are reduced to path‑only (no query strings). Headers, cookies, and body payloads are removed before sending.
  • Limited scope: Performance tracing and session replay are disabled. Routine product events are sent as structured Sentry Logs and retained as breadcrumbs for error context; only warnings and errors may create Sentry message events. We ignore common frontend error noise to minimize collection.
  • No file contents: We do not send or store file contents from your conversions. Client‑side processing keeps data on your device.
  • Network layer: Our providers may process IP addresses transiently to deliver the service; we do not access or store these addresses.

Cookies

We do not set analytics cookies or advertising cookies. Vercel Analytics operates without analytics cookies. The short-lived sessionStorage marker described above is not a cookie and is limited to the current browser tab.

How We Use Data

  • Maintain site reliability and debug errors.
  • Plan improvements based on aggregate, non‑personal usage insights.

Lawful Basis

We process minimal technical data under our legitimate interest to maintain and improve the Service, balanced against your privacy rights.

Data Sharing

  • Sentry (error tracking and product logs): Receives sanitized error events and structured tool-usage events from the client in production.
  • Vercel (hosting & analytics): Hosts the Service and provides cookie‑less analytics.

Data Retention

Error events and product logs are retained according to Sentry’s configured retention. Aggregate analytics are retained according to the retention settings of Vercel Analytics. We do not keep separate personal records from these analytics events.

Your Rights

Because we do not collect personal identifiers, we cannot reliably associate a particular error event with a specific individual. You may contact us to ask questions or request that we reduce or disable future error reporting from your device; we will provide reasonable options (e.g., a Do‑Not‑Track preference) if available.

Security

We take reasonable measures to secure the Service. Client‑side processing reduces transmission of files and data.

International Transfers

Our providers (Sentry and Vercel) may process data in the United States, the European Union, or other locations, subject to their infrastructure, safeguards, and policies.

Children’s Privacy

The Service is not directed to children under 13. We do not knowingly collect personal information from children.

Changes to This Policy

We may update this Privacy Policy from time to time. We will post the effective date at the top of the page. Your continued use of the Service constitutes acceptance of the updated policy.

Contact

For privacy questions, contact us at toolspack@proton.me.