🛡️ GDPR & Privacy by Design

Privacy Policy & GDPR Compliance

Pure Client Tools was engineered from the ground up around a fundamental principle: your data belongs exclusively to you. Learn how our architecture ensures complete data protection under the EU General Data Protection Regulation (GDPR).

Last updated: August 2026 • Effective immediately

🛡️ 1. Core Commitment: Privacy by Design (GDPR Art. 25)

Under Article 25 of the General Data Protection Regulation (GDPR), controllers are mandated to implement data protection principles by design and by default.

Pure Client Tools fulfills this standard to the highest possible extent: all data transformation, parsing, decoding, hashing, generation, and inspection algorithms execute 100% locally inside your web browser using standard native web technologies (JavaScript V8/SpiderMonkey, Web Crypto API, Canvas, and DOM parsers).

✓ Not a single byte of your code, JSON structures, JWT tokens, passwords, or text inputs is ever transmitted to our servers or any third-party infrastructure.

👤 2. Data Controller

The Data Controller for Pure Client Tools (accessible at https://pureclienttools.com) is:

Publisher & Developer: Christophe Canon
Project: Pure Client Tools

📊 3. What Data Is (and Is Not) Collected

A. Tool Payloads & Content (Zero Collection)

We do NOT collect, view, store, or log any text, keys, tokens, or files that you input into our tools. When you refresh or close the tab, the volatile RAM used by your browser is instantly released.

B. Anonymous Usage Telemetry

To understand which tools are popular and ensure site stability, we collect aggregate, non-identifying telemetry (e.g. "json-formatter visit: 1").

  • No Raw IP Storage: Your IP address is never stored in plaintext. To avoid duplicate rapid counting, an ephemeral SHA-256 hash combined with a daily rotating salt is computed in memory. It cannot be decrypted or reverse-engineered to identify you.
  • No Fingerprinting: We do not track device canvas signatures, audio contexts, or hardware identifiers.

C. Tool Suggestion Form Submissions

When you voluntarily submit a tool proposal through the suggestion form, we record the submission (optional author handle, tool title, description). This information is solely used to consider new tool features. It is never sold, shared, or used for marketing. Legal basis: Consent (GDPR Art. 6(1)(a)).

D. Web Server Infrastructure Logs

Like all web servers, our hosting infrastructure (Hostinger) maintains standard technical access logs (HTTP request code, user agent, timestamp) strictly for technical security, DDoS mitigation, and server maintenance. Legal basis: Legitimate Interest (GDPR Art. 6(1)(f)).

🍪 4. Cookie Policy: Zero Tracking Cookies

Pure Client Tools uses NO tracking cookies, NO advertising cookies, and NO third-party analytical cookies.

In compliance with the ePrivacy Directive and CNIL / European Data Protection Board (EDPB) recommendations, sites that do not deploy tracking cookies are exempt from displaying intrusive consent banners. You enjoy a clean, uninterrupted, and privacy-respecting experience from your very first click.

⚖️ 5. Your Rights Under GDPR (Articles 15–22)

Under the GDPR, you hold several essential rights regarding your personal data:

Right to Access & Rectification:

Request confirmation of whether we hold data concerning you and ask for corrections.

Right to Erasure ("To Be Forgotten"):

Request the deletion of any suggestion or feedback you previously submitted.

Right to Restrict & Object:

Object to specific processing activities based on legitimate interests.

Right to Lodge a Complaint:

Lodge a formal complaint with a European data protection authority (e.g. CNIL in France, cnil.fr).

Note: Since we do not maintain accounts or store identifiable tool payloads, we have no personal data relating to your tool conversions. For any inquiry, write to contact@pureclienttools.com.

🔒 6. Hosting, SSL & Security Standards

Pure Client Tools is served exclusively over encrypted HTTPS / TLS with strong cipher suites and strict security headers (X-Content-Type-Options: nosniff, X-Frame-Options: SAMEORIGIN, Referrer-Policy: strict-origin-when-cross-origin).

The website is hosted on high-availability cloud infrastructure provided by Hostinger International Ltd., adhering to European data protection standards and datacenter security certifications.

Have questions about our privacy practices?

We are always glad to discuss architecture, code transparency, and privacy engineering.

✉️ Contact Privacy Team