Privacy & sharing
Updated September 27, 2026. This page explains tool processing separately from website requests and analytics.
Tool input is processed in your browser. The site still loads scripts, fonts and page analytics, and optional share links contain a readable copy of your input.
Every tool page also has a "What this page sends" box describing that specific tool.
Tool inputs and files
Formatting, conversion, decoding, hashing, and mock query execution happen in your browser. ByteKiln does not upload your input, selected files, or generated output to a processing API. The GraphQL playground uses local mock resolvers; SQL Runner uses an in-memory SQLite database whose WebAssembly engine is downloaded from ByteKiln on first use.
A few tools use hardware or device features, only when you start them: the ESP32 Flasher and Serial Monitor talk to your board over Web Serial (firmware files are read locally and written only to the selected board), and the QR scanner uses your camera, decoding frames in the page without recording them. Your browser asks you to choose and authorize a serial port or grant camera access when you start the relevant action.
Generated passwords and keys are created in the tab rather than stored by ByteKiln. Some option choices, such as generator settings, are saved in browser local storage; the generated secret is not. The cURL Converter redacts recognizable credentials by default, but redaction is best-effort: inspect generated code and share links before copying them.
Use sample data for troubleshooting. Local processing does not protect against browser extensions, someone with access to your device, or content you choose to copy, download, or share. HTML inspected by the accessibility checker can load resources referenced in that markup, such as images; remove external references from sensitive snippets.
Optional share links
The Share button embeds input and output in the URL fragment after #d=. This is Base64 encoding, not encryption: anyone with the complete link can read the content. The fragment is not included in the HTTP request to ByteKiln, but the complete link can be stored in browser history, clipboard managers, or the service where you share it.
The viewer stops displaying content after one hour. This is a browser-enforced expiry, not deletion or revocation: the encoded content remains recoverable from a saved link. Do not share credentials, access tokens, personal information, or production secrets.
Older links using ?d= still work and are rewritten to the fragment form after loading. Their original query string is sent in the initial request and may appear in hosting logs. Share pages load no Google Analytics tag and send no referrer when following links.
Page analytics
Ordinary production pages use Google Analytics to measure page visits. Google Analytics can use cookies and receives technical information such as browser/device details. Tool pages also send usage events (for example tool_run or tool_output_copied) carrying only the tool name and category, an output format, success, or a fixed error category. The tools catalog sends aggregate interaction events for category selection, search use, empty results and tool opens, with category/tool IDs and whether search preceded a click. Search text is not included. No event includes input, output, file contents or error messages. Our page-view configuration uses the page path and title, strips query strings and fragments from page URLs, retains only the referring site's origin, and disables Google signals and advertising personalization signals.
Analytics is not initialized on share pages, missing pages, local previews, or visits whose URL contains a query string or fragment. No analytics event includes tool input, tokens, file contents, or generated output. Automatic measurements are also controlled in the Google Analytics property and must be reviewed separately from this source configuration.
Website resources and hosting
Loading the site makes network requests for HTML, scripts, images, and fonts. Fonts load from Google Fonts. On desktop screens, the Monaco code editor used by the two-panel tools is downloaded from cdn.jsdelivr.net (phones use a bundled lightweight editor). SQL Runner downloads its SQLite WebAssembly engine from ByteKiln itself. These providers and the hosting/CDN service receive request metadata such as IP address, user agent, requested URL, and time. Local tool processing is separate from those requests.
Tools can continue processing locally once the required resources have loaded. A fresh visit or an uncached dependency still needs a connection; the site does not provide an offline installation.
Browser storage and contact
Theme and some tool settings are saved in your browser's local storage. Clipboard and download actions use browser features. You can clear site storage and cookies through your browser settings.
For questions about this explanation, contact hello@bytekiln.com.