Privacy policy
Effective from 29 September 2026. This policy explains how personal data is processed when you use toolseta.com (the “Service”), in accordance with Regulation (EU) 2016/679 (GDPR).
1. Data controller
The controller of your personal data is:
You can contact us about anything related to your data at the e-mail address above.
2. What we process, why, and on what legal basis
- Files you upload to file tools — processed only to perform the tool you requested (Art. 6(1)(b) GDPR — performance of a contract). Uploads are deleted right after processing and never later than 60 minutes after upload. Results are deleted automatically after 60 minutes (24 hours on Pro and Business). We never look at, share, sell or use your files for any other purpose, including training.
- Account data — name, e-mail address, a securely hashed password, plan and job history (tool used, file sizes, status — never file contents). Needed to provide the account (Art. 6(1)(b)).
- Purchases — Stripe customer identifier, subscription status, amounts and dates of payments. Needed to provide paid features (Art. 6(1)(b)) and to keep accounting records required by law (Art. 6(1)(c)). We never see or store card numbers.
- Technical and security data — IP address and browser information in server logs, and a keyed, non-reversible hash of the IP address used to apply free usage limits and prevent abuse (Art. 6(1)(f) — our legitimate interest in security and fair use).
- Product analytics — anonymous events such as “tool viewed” or “tool completed”, linked only to the IP hash (and to your account if you are signed in), used to improve the Service (Art. 6(1)(f)).
- Correspondence — messages you send us, to answer them (Art. 6(1)(f)).
Providing data is voluntary, but without an e-mail address and password we cannot create an account, and without payment details the payment provider cannot process a purchase.
3. Tools that run in your browser
Developer and everyday tools (JSON, CSV, Base64, URL, JWT, UUID, timestamps, regex, passwords, QR codes, word counter) run entirely in your browser. What you type into them is never sent to our servers.
4. Recipients and processors
We use the following service providers, who process data on our behalf or, where indicated, as independent controllers:
- OVH SAS (OVHcloud, France) — server hosting in the European Union.
- Stripe (Stripe Payments Europe, Ltd., Ireland, and its affiliates) — payment processing. Purchases are made through Stripe Managed Payments, in which Stripe acts as the reseller (merchant of record) and processes payment and billing data as an independent controller under its own privacy policy (stripe.com/privacy).
- Sendinblue SAS (Brevo, France) — delivery of service e-mails such as password reset.
We may also disclose data to public authorities where required by law.
5. Transfers outside the EEA
Our servers are located in the European Union. Where a provider processes data outside the European Economic Area (for example Stripe’s affiliates in the United States), the transfer is protected by the European Commission’s standard contractual clauses or by the EU–US Data Privacy Framework.
6. How long we keep data
- Uploaded files: until processing ends, at most 60 minutes; results: 60 minutes (24 hours on Pro and Business).
- Job history without file contents: 90 days for visitors without an account, 365 days for registered users.
- Account data: until the account is deleted.
- Payment and accounting records: 5 years from the end of the calendar year in which the payment was made, as required by tax law.
- Usage-limit records: 400 days; anonymous analytics events: 395 days; server logs: 30 days.
- Database backups: up to 6 months, after which they are overwritten.
- Correspondence: until the matter is resolved, and then as long as claims may arise.
7. Your rights
You have the right to access your data, to rectify it, to have it erased, to restrict its processing, to data portability, and to object to processing based on our legitimate interests. To exercise these rights — including deleting your account — write to us at the e-mail address above. We will respond within one month.
You also have the right to lodge a complaint with a supervisory authority. In Poland this is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warszawa, uodo.gov.pl); you may also contact the authority in your country of residence.
We do not make decisions based solely on automated processing that produce legal effects concerning you. Applying the usage limits of your plan is not such a decision.
8. Cookies and local storage
We only use cookies that are strictly necessary for the Service to work: a session cookie and a security (CSRF) cookie. Your theme preference and recently used tools are stored in your browser’s local storage and never leave your device. We do not use advertising or tracking cookies, which is why the Service does not display a cookie consent banner.
9. Security
All traffic is encrypted with HTTPS. Passwords are stored as one-way hashes. Files are stored in private storage with random names, processed in isolated workers and downloaded only through signed links that expire together with the file.
10. Changes
We will publish any changes to this policy on this page. If a change significantly affects how we process your data, we will inform registered users by e-mail.