Privacy Policy

Everything here runs in your browser, so almost nothing leaves your machine. The few exceptions, including EU-hosted analytics, are documented in plain language.

Effective date: August 23, 2026

Overview

CapyToolkit is a collection of browser-based utility tools. Our tools process data on your device, so nothing you input into a tool is transmitted to any server, unless the tool is listed in the "Tools that contact our servers" section below. Nothing is uploaded in the background while you use a tool.

We do not require an account, and we do not offer one. There is no login, registration, or user profile system.

Who we are

The controller responsible for the processing described in this policy is CapyToolkit (capytoolkit.com). For any privacy question or request, write to [email protected].

Data we do not collect

Because tool processing happens in your browser, we never receive:

  • Files you upload or drop into tools
  • Text, code, or any content you paste or type into tools
  • Tool outputs or results
  • Passwords, hashes, or any sensitive input

Analytics

We use PostHog, a product analytics platform hosted in the European Union, to understand how visitors use the site. Analytics runs in two modes, depending on your choice in the cookie banner.

Before you choose, or if you press "Reject": PostHog measures traffic without identifying you or writing analytics data to your browser. No cookies are used in this mode. Visits are counted using an irreversible hash that PostHog's servers compute fresh each day from technical request data such as your IP address and browser user agent, so visits cannot be linked across days and no persistent identifier about you is created. Interaction events such as button clicks are also counted in this mode, always without identifiers or device storage. Features that need stored data, such as session replay, are disabled.

If you press "Accept": PostHog additionally stores first-party data in your browser (a distinct ID and a session ID) to recognize returning visits, and derives approximate location at country level from your IP address. Session recording and heatmap features may also operate in this mode; we configure them to avoid capturing sensitive content, but if you interact with a form field that contains personal information, we recommend exercising caution.

In both modes, everything you type into a tool stays in your browser unless the tool is listed under "Tools that contact our servers" below. We do not run advertising networks and we do not track you across other websites. PostHog processes analytics data on our behalf as a processor under a data processing agreement and its own Privacy Policy.

The anonymous counting described above is based on our legitimate interest in understanding how the site is used (Article 6(1)(f) GDPR). Pressing "Reject" does not switch this counting off, because the mode processes no stored identifiers and cannot single anyone out. What Reject controls is everything else: stored IDs, return-visit recognition, richer event detail, and features that need stored data such as session replay. We also record your banner choice itself as an event, so we can demonstrate which choice you made and when.

Cookies and local storage

The site uses the following browser storage:

  • Your banner choice (capy_cookie_ok cookie, 14 days, plus PostHog's own consent status flag in local storage): records whether you pressed "Accept" or "Reject" so the banner does not reappear and your choice is honoured on every visit. Before you answer the banner, the flag already holds the default off state; it never contains visit data. This storage exists only to remember your consent status, so it is exempt from the consent requirement itself.
  • Theme preference (dark or light mode, kept in localStorage): functional, contains no personal information, and never leaves your browser.
  • Offline cache progress (capy_offline_warm_state key in localStorage): a checklist of site pages your browser has already saved for offline use, so the download resumes where it stopped instead of starting over. Functional, contains no personal information.
  • Install prompt frequency capping (capy_pwa_prompt cookie, 7 days): written only if you press "Accept". It prevents the app install prompt from reappearing after you dismiss or use it. If you have not accepted, the prompt may reappear as you move between pages.
  • Microsoft Store session marker (capy_ms_store_session in session storage): written only if you press "Accept" and arrived from the Microsoft Store listing. It lets us count openings coming from the store for the duration of your visit.
  • PostHog analytics storage (distinct ID and session ID): written only after you press "Accept", and removed when you switch back to "Reject" via Cookie settings.

No analytics data is written before you answer the banner; the only analytics-related entry present beforehand is the consent status flag above, which holds no visit data. If you reject, analytics continues only in the storage-free aggregate mode described in the Analytics section above.

Tools that contact our servers

Most CapyToolkit tools run entirely in your browser. The following features send data off your device when you use them:

  • SSL Certificate Inspector: the domain name you enter is sent to our certificate lookup service (cert-tool.capytoolkit.com) to fetch the certificate. Cloudflare Turnstile runs an invisible bot check first.
  • Contact form: your name, email address, and message are sent to our form service (forms.capytoolkit.com), which delivers them to us by email through Brevo. Cloudflare Turnstile runs an invisible bot check on submission.
  • IndexNow Submitter: the URLs or sitemap address you enter are sent to our submission service (indexnow.capytoolkit.com), which forwards them to search engines using your IndexNow key.
  • P2P / WebRTC tester: connection tests negotiate with public STUN servers run by Google and Cloudflare. During this handshake those servers see your IP address and network type. That is how WebRTC works; no connection data is stored by us.

Two tools load optional code libraries from public CDNs while you use them: the webcam test and the Passport & Visa Photo Cropper can load the MediaPipe face landmark model, and the OCR redactor loads the jsPDF library for PDF export. These requests reveal your IP address to the CDN, as any web request does, but no image, document, or camera data is uploaded.

Third-party services

Cloudflare: the site is served through Cloudflare's CDN and security layer. Cloudflare processes request metadata such as your IP address to deliver pages, cache content, and protect against abuse. This processing is covered by the Cloudflare Data Processing Addendum, which is incorporated into our agreement with Cloudflare.

Brevo and Cloudflare Turnstile: used by the contact form, as described in the Contact form submissions section below.

Amazon: some outbound links are affiliate links. See the Affiliate & Advertising Disclosure policy for details on what a partner site may track after you leave CapyToolkit.

PostHog analytics is hosted in the European Union and Brevo operates in the EU. Cloudflare's global network processes data under its Data Processing Addendum and transfer safeguards.

Contact form submissions

If you use the contact form on this site, we collect your name, email address, and the content of your message. This information is used solely to respond to your enquiry. We do not add you to any mailing list, and we will only contact you in relation to your submission.

Form submissions are processed through Brevo, a transactional email service. Brevo receives your name, email address, and message content in order to deliver your submission to us. Brevo operates under its own Privacy Policy.

We also use Cloudflare Turnstile for bot protection. Turnstile runs a lightweight, invisible check when you submit the contact form, and when you use the SSL Certificate Inspector to fetch a certificate from a domain. No personal data is shared with Cloudflare beyond what is technically necessary for this check. Cloudflare operates under its own Privacy Policy.

Data retention

We do not store personal data on our own servers. Analytics events collected via PostHog are kept for as long as our analytics project remains active, and operational logs on the platform are kept for 14 days. Aggregate cookieless counts are handled the same way as other analytics events. Cloudflare keeps zone and security logs according to its standard retention periods. We do not sell, rent, or share analytics data with third parties. You can ask us to have analytics data deleted by writing to the contact address below.

European Union (GDPR) notice

Because we process a limited amount of personal data (specifically your IP address for security and basic analytics, and your details if you choose to use our contact form), the GDPR requires us to inform you of your rights. You have the right to request access to, correction of, or deletion of any data you submit to us via our contact form. To exercise these rights, email [email protected]. You also have the legal right to lodge a complaint with a supervisory authority, such as the Polish Personal Data Protection Office (UODO).

Children's privacy

CapyToolkit is not directed at children under 13. We do not knowingly collect personal data from children.

Changes to this policy

We may update this policy as the site evolves. The effective date at the top of this page reflects the date of the most recent revision. Continued use of the site after changes constitutes acceptance of the updated policy.

Contact

Questions about this policy can be sent to [email protected].