ZERO SERVER UPLOADS • LOCAL-FIRST ASSURANCE

Privacy Policy & Architecture

At NovaTool, our core engineering philosophy is simple: your files should never leave your computer or phone. We designed our entire utility suite to execute client-side inside your browser sandbox.

The Execution Model

How Your Data is Handled

1. Reading File

When you select or drop a file, the browser's native File API and FileReader load the binary data into the browser tab's RAM memory.

2. In-Browser Execution

Images are transformed via HTML5 Canvas. Media is processed via WebAssembly FFmpeg. Developer tools run pure JavaScript parsers.

3. Direct Download

The output is saved as a local Blob URL (blob:...). When downloaded, the browser writes it straight to your disk.

Are any user files uploaded to a remote server?

No. There are no file upload API routes, no cloud buckets (AWS S3, Google Cloud Storage, etc.), and no third-party conversion APIs. The Next.js web server only delivers the website's static HTML, CSS, and JavaScript bundles.

What is stored in Browser LocalStorage?

We store only two non-sensitive UI preference keys in your browser's local storage:

  • theme: Remembers your light or dark mode UI preference.
  • novatools_recent_tools: Stores a list of up to 6 tool slugs so you can quickly return to tools you use frequently.

We never store file contents, file names, code snippets, or processed media in localStorage, cookies, or IndexedDB.

Network Separation: Static Code vs. Local Data

There is a strict, unambiguous boundary between code delivery and data execution:

  • Initial Code Download (Network): When you open NovaTool, your browser downloads the static application assets (HTML, CSS, JavaScript, and self-hosted WebAssembly binaries from /vendor/ffmpeg/) over secure HTTPS.
  • Data Execution (Local RAM Only): Once downloaded, all execution happens in your browser tab. Your files, media, images, and text inputs are held exclusively in local device RAM. No user data packets ever leave your computer or phone.

Analytics & Tracking

We do not use advertising networks or behavioral tracking scripts. We do not inspect, log, or track what text you paste into the JSON formatter, what images you compress, or what tokens you decode.

Updated: October 2026Return to Tools