Skip to main content
ToolBox

Privacy Policy

This Privacy Policy explains how we collect, use, and protect information when you use our tools and website. It also describes your rights and how to contact us.

Last updated: 2026-10-05

1. Summary at a glance

ToolBox is designed with a privacy-first approach. Most of our image, PDF, and developer tools run locally in your browser and do not upload files to our servers. For features that do reach our servers (for example, contact forms and basic analytics), we collect only the minimum information required.

2. Who we are

The website loveutool.com (hereinafter referred to as “the Website”, “we”, “us”, or “our”) is operated by ToolBox Team. If you have any questions about this Privacy Policy, contact details are listed in the Contact us section below.

3. Information we collect

We may collect the following categories of information:

  • Information you choose to provide: For example your name, email address, or other details when you submit the contact form or send us an email.
  • Log data (automatic, minimal): Standard information such as your IP address, browser type, referring pages, and timestamps, as generated by most web servers and CDN logs. This data is used for security and abuse prevention and is typically discarded after 30 days or as required by law.
  • Privacy-respecting analytics (if enabled): Aggregated, anonymous usage metrics (for example, which tools are most popular) so we can decide what to improve next. We do not use analytics data for advertising or tracking across websites.
  • Client-side preferences: Theme (light/dark) and similar settings stored locally in your browser using localStorage or equivalent. These never reach our servers.

4. How we process files in our tools

4.1 Browser-side processing (default for most tools)

Unless explicitly stated otherwise on the tool page, our image tools, PDF tools, and text/developer tools are implemented entirely with client-side JavaScript using the Web platform API and open-source libraries such as pdf-lib, pdf.js, the HTML Canvas API, and the WebCodecs API where available.

  • Files do not leave your device. The file bytes you upload or drop onto the page stay inside the current browser tab.
  • No server copy is created. We cannot access your files, nor can we see their contents.
  • Result downloads happen locally. When you press “Download” the output is generated locally with URL.createObjectURL and the Blob API.

4.2 Tools that may reach a server

If and when we introduce a tool that performs processing on our servers or on a third-party service (for example, an AI feature), the tool page will clearly disclose:

  • that data is uploaded,
  • what is sent and to whom,
  • the retention period, and
  • the lawful basis for processing (consent, contract, or legitimate interest).

5. How we use information we receive

We use the limited information we receive only to:

  1. operate, maintain, and improve the Website and its tools;
  2. protect the Website against abuse, spam, and security incidents;
  3. respond to support inquiries, bug reports, or feature requests submitted by you;
  4. comply with any legal obligation, court order, or enforceable regulatory request; and
  5. gather aggregated, non-identifying usage statistics to prioritize features (for example, “which tools should we expand?”).

We do not sell, rent, share, or trade personal information with advertisers, data brokers, or marketing networks.

6. Cookies and local storage

We do not deploy advertising cookies or third-party marketing tags on the Website. We may use:

  • Essential / strictly necessary cookies: to respect your theme preference (light/dark) and a few similar UX toggles. These cookies are required for core site functionality and are never used for tracking.
  • Client-side storage (localStorage, sessionStorage): to remember UI state inside the current session, such as which tab in a tool is open.

You can delete Website data any time via your browser’s Clear site data menu or equivalent.

7. Third-party services and hosting

The Website is hosted on a modern cloud platform (e.g. Vercel/Cloudflare/Netlify, depending on our current deployment). These providers may automatically log standard HTTP information as described in their respective privacy policies. We choose privacy-oriented providers whenever possible.

In addition, a small number of third-party resources may be loaded directly in the browser to enable a tool (for example, a font file, or a PDF.js worker module loaded from a CDN with Subresource Integrity). We keep this list as short as possible and review it with every release.

8. Children’s privacy

The Website is a general-audience utility site. We do not knowingly collect personal information from children under 13 (or the relevant age threshold in your jurisdiction, e.g. 16 under GDPR). If you believe we have inadvertently received such information, contact us and we will delete it promptly.

9. International transfers

If you access the Website from outside the country in which our infrastructure is hosted, please understand that your information (for example, the IP address captured in CDN logs) may be transferred to, stored in, and processed in that country. By using the Website you consent to any such transfer to the extent it is required to operate the service.

10. Your rights

Subject to applicable law (including, without limitation, the EU GDPR and California CCPA/CPRA), you may have the right to:

  • request access to any personal information we hold about you;
  • request correction of inaccurate or incomplete information;
  • request erasure (“right to be forgotten”) where lawful;
  • object to or restrict certain types of processing; and
  • request a portable copy of data you submitted to us.

Because the Website stores so little, most of these rights can often be satisfied by simply clearing your browser’s local storage for our domain or by asking us to delete a specific contact-form submission. We respond to requests within 30 days.

11. Retention

  • Contact form submissions / support emails: We keep them only as long as needed to answer the question and for a short period afterwards for audit and continuity purposes (typically 12 months).
  • CDN / server log data: Retained for 7–30 days depending on the provider, then automatically deleted.
  • Analytics aggregates: Kept indefinitely in non-identifying, aggregated form.

12. Data security

We use industry-standard measures to safeguard the small amount of information we do collect (HTTPS everywhere, SRI for third-party scripts, minimal permissions, regular dependency updates). That said, no method of transmission or storage is 100% secure. For tools that run entirely in the browser, the security boundary is your own device, and we never see the data at all.

13. Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in the law, changes to our features, or changes in our practices. We will post the updated policy on this page with a new “Last updated” date. Material changes (for example, a new feature that collects data) will be announced with reasonable notice via a banner on the homepage for at least 30 days before they become effective.

14. Contact us

Questions, requests, or complaints regarding this Privacy Policy or our handling of personal information should be directed to:

Email: support@toolbox.example
Operator: ToolBox Team
Website: https://www.loveutool.com

If you are based in the European Economic Area and believe our processing infringes applicable data protection law, you also have the right to lodge a complaint with your local data protection authority.


Questions about this page? Email us at support@toolbox.example.