Security and architecture
How this site works, what it does not do, and how you can verify both.
The browser-only model
Every tool on this site runs entirely in your browser. There is no server that receives your input, no queue that processes your files, and no database that stores your data. When you type into a textarea or drop a file, the JavaScript loaded by that page reads the value and computes the result locally, in the same browser tab you are looking at right now.
You can verify this yourself. Open any tool page, open your browser's developer tools (usually F12), switch to the Network tab, and use the tool. After the page finishes loading, no request that carries your input will fire. Nothing you type or paste is sent anywhere.
One exception, noted for accuracy: the Diceware tool fetches its static word list from this domain on first use. That request contains no user data - it is the equivalent of loading an image from the same site.
No uploads, ever
Even the tools that work with files - hashing, encoding, compression, archive creation - read the file directly from your disk using the browser's File API and process it in memory. The file is never transmitted. The "drop a file here" area on those pages is a local file picker, not an upload form.
This means a 2 GB file stays local. You can drag it into the SHA-256 File tool, hash it, close the tab, and nothing was sent anywhere. Test it with your network disconnected: every tool still works.
Analytics, advertising, and accounts
Analytics. The site uses Google Analytics 4 (GA4) to measure page views. GA4 is loaded from Google's servers and sets two cookies on your device. It does not receive any tool input. See the privacy policy for details and how to opt out.
The fonts used on this site are self-hosted and served from this domain.
There are no user accounts. You cannot log in because there is nothing to log in to. The only things stored directly on your device are preferences you explicitly set (theme choice, the "Remember Input" toggle on individual tools), and those live in localStorage - not on any server.
What the hosting provider sees
This site is served by Cloudflare Pages. Like every web host, Cloudflare's edge servers log standard request data when your browser requests a page: the IP address, the user agent, the timestamp, and the URL. This is a hosting-level fact, not a feature of the site itself. Cloudflare's own privacy policy describes what they do with those logs.
The site does not have access to those logs. There is no dashboard where the author can see who visited or what they searched for.
Every tool is tested
All Tooleux tools are verified by an automated test suite that runs before every deployment. The suite loads every page, exercises the example input, and asserts that the tool produces output rather than an error. Tools that implement published standards - SHA-256, Argon2id, AES-GCM, PBKDF2 - are checked against known-answer test vectors.
You can see the test results yourself on the verification page. It runs the same known-answer tests in your browser and displays a pass/fail table.
Dependencies and libraries
The cryptographic primitives are not hand-rolled. They come from established, audited open-source libraries: @noble/hashes for SHA family and BLAKE, hash-wasm for MD5 and Whirlpool, @noble/ciphers for AES and ChaCha20, jose for JWT and JWE, and the Web Crypto API for RSA, ECDSA, Ed25519, and HMAC.
If you find a tool that produces a different result than a reference implementation, that is a bug and worth reporting. See the contact page.
How to audit this site yourself
- Open any tool page.
- Open DevTools (F12).
- Switch to the Network tab and clear it.
- Use the tool. Paste text, drop a file, click buttons.
- Observe: no request carrying your input fires. The result is computed entirely in the tab.
If you ever see a request carrying your input after the page has loaded, that is a critical bug and you should report it immediately.