Privacy Policy

Last updated: September 19, 2026

Your privacy matters to us. This policy is written in plain language so you can see what we collect and why.

1. Overview

ToolDock is built so that most tools run entirely in your browser and never send what you type to us. This policy explains the personal data we do handle: what it is, why we use it, who we share it with, and what choices you have. It applies to tooldock.dev and its API. Using the Service is also subject to our Terms of Service.

2. Data we collect

Account data. When you sign up we collect your email address and password. Passwords are handled by our authentication provider and are not stored in readable form. On your account page you can optionally add a display name, phone number and avatar.

API keys. If you create API keys, we store the key names and the data needed to validate them.

Feedback. If you send feedback, we receive your message, the category you chose and the URL of the page you were on.

Data sent to server-side tools. Most tools run in your browser. A few need our servers, such as the uptime, TLS and security-header checkers, the website screenshot and HTML-to-PDF tools, the webhook tester, and AI-powered tools. For those, the input you provide (for example a URL, a prompt or text to convert) is sent to our API to produce the result. The webhook tester also records requests that other systems send to your test endpoint, including their headers, body and source IP address.

Usage and device data. We count how often each tool is viewed or used, in aggregate. Our servers and providers may log technical data such as IP address, browser type and request time for security and reliability. If you choose “Accept all” in our cookie banner, Google Analytics collects page views and similar usage information, and Microsoft Clarity records how you use our pages, such as clicks, scrolling, mouse movement and the page content shown on screen, with sensitive fields masked. We also use Ahrefs Web Analytics for traffic statistics without cookies (see Section 5).

3. How we use data

  • to create and secure your account and provide the tools you ask for;
  • to operate the API, enforce usage limits and prevent abuse (including bot protection at signup and login);
  • to understand which tools are useful and improve the Service;
  • to respond to feedback and support requests;
  • to send account emails, such as sign-up confirmation and password reset;
  • to comply with legal obligations.

Where the GDPR applies, our legal bases are performing our contract with you (providing your account and the tools), our legitimate interests (security, abuse prevention, and aggregate counts of tool usage), your consent (for analytics cookies and session recordings, which we use only if you choose “Accept all”), and legal obligation.

4. Who we share data with

We don't sell your personal information. We share data only with service providers that help us run ToolDock:

  • authentication and database hosting (Supabase);
  • hosting, networking and bot protection (Cloudflare, including Turnstile);
  • analytics and session recording (Google Analytics, Microsoft Clarity and Ahrefs Web Analytics);
  • AI model providers, when you use an AI-powered tool, which receive the text you submit to that tool.

We may also disclose data if the law requires it, to protect the rights, safety or security of ToolDock or others, or as part of a merger or sale of the business.

5. Cookies and analytics

The first time you visit, a banner asks you to choose between Essential only and Accept all. Both choices are equally easy to make, and the site works the same either way.

Always on (essential).

  • Cookies that keep you signed in and run bot protection (Cloudflare Turnstile).
  • Local storage in your browser to remember your theme, your cookie choice, and webhook endpoints you created.

Only if you choose Accept all.

  • Google Analytics sets cookies (such as _ga) to measure traffic and how tools are used.
  • Microsoft Clarity sets cookies (such as _clck and _clsk) and records sessions and heatmaps: clicks, scrolling, mouse movement and the page as you see it. Clarity masks text typed into fields, numbers and email addresses by default, and we additionally hide the content of tools that handle credentials and secrets, such as the password, OTP, JWT, hash and share-secret tools. Recordings are processed by Microsoft on our behalf.

If you choose Essential only, neither Google Analytics nor Microsoft Clarity is loaded and neither sets cookies. We also use Ahrefs Web Analytics for traffic statistics; it doesn't use cookies.

Changing your mind. Use Cookie settings in the site footer at any time. Switching to Essential only removes the analytics cookies and stops recording straight away. Data already collected stays with the provider until their retention period ends. You can also block or delete cookies in your browser settings, though signing in may not work without essential cookies.

6. How long we keep data

We keep account data while your account is active and delete it when you close your account, except where we must keep some information to comply with the law or resolve disputes. Server-side tool inputs are processed to return a result and aren't kept as part of your account data. Webhook tester endpoints expire after a period of inactivity, and only a limited number of recent requests are stored. Backups and logs may persist for a short period afterward.

7. Your rights and choices

Depending on where you live, you may have the right to access, correct, delete, export or restrict the use of your personal data, to object to certain processing, and to withdraw consent. Residents of California have the right to know what personal information we collect, to delete it, to correct it, and to opt out of its sale or sharing. We don't sell personal information or share it for cross-context behavioral advertising. We won't discriminate against you for exercising these rights.

You can update or delete much of your data from your account page. For anything else, or to make a request, contact us using the feedback button on the site. If you are in the EU or UK, you can also complain to your local data protection authority.

8. Children

ToolDock is not directed to anyone under 18, and you must be at least 18 to create an account. We don't knowingly collect personal data from children. If we learn we have collected data from someone under 18, we will delete it and close the account. If you believe a child has given us personal data, contact us so we can remove it.

9. International transfers

We and our providers may process data in countries other than your own, including the United States. Where required, we rely on appropriate safeguards for those transfers, such as standard contractual clauses.

10. Security

We use reasonable technical and organizational measures to protect your data, including encrypted connections and bot protection on sign-in. No method of transmission or storage is completely secure, so we can't guarantee absolute security.

11. Changes to this policy

We may update this policy from time to time. When we do, we'll change the date at the top of this page and, for material changes, take reasonable steps to let you know.

12. Contact

Questions about this policy or your data? Send us a message using the feedback button at the bottom of any page on the site.