Privacy Policy
Last updated: August 3, 2026
Data you enter into the free tools
Every free tool on Cryonel (JSON Validator, JWT Decoder, YAML/CSV converters, Base64, UUID, Regex, OpenAPI Validator, Timestamp, and the rest of the /tools/ catalog) runs entirely in your browser via JavaScript. Whatever you paste or type into one of these tools is never sent to, processed by, or stored on our servers. See Technical Transparency for exactly how to verify that yourself.
Recent-tool and favorite-tool preferences are stored locally as tool route slugs only. They do not include tool input, output, file names, or account identifiers and are not sent to Cryonel.
Workflow progress is stored in the current tab as ordered tool slugs and a step index. A value is stored in the same tab only when you explicitly move compatible output to the next tool, and the destination clears that handoff record immediately after reading it.
This does not apply to Cryonel API Guard, our paid account-based product — see the dedicated section below, since it necessarily stores some data server-side to work at all.
Cryonel API Guard (account features)
API Guard monitors an OpenAPI spec you register and alerts you to changes, which requires storing some data server-side. Specifically:
- Account: your email address and a hashed password (we never store your password itself). A session is kept server-side and identified by a cookie in your browser.
- Watched APIs: the spec URL you register (so we know where to re-fetch it from), and a parsed, normalized copy of the spec plus a hash of it, used to detect changes. We do not store the original raw spec text you submitted or fetched.
- Change history: a record of detected changes (what changed, and how severe) for each watched API.
- Notification destinations: Pro users may store Slack or generic HTTPS webhook URLs. Those URLs and generic-webhook signing secrets are encrypted at rest. When a notable change is detected, the selected destination receives the watched API name, API Guard identifier, severity counts, change summaries, and detection time. Cryonel does not include your account email, spec URL, user ID, or raw specification in that payload.
- Billing: subscription status is synced from our payment processor, Polar, which handles your payment details directly — Cryonel never sees or stores your card information.
Deletion: removing a watched API deletes its spec data and change history immediately. Deleting your account deletes all of your sessions, watched APIs, and change history. Billing event records may be kept longer for accounting purposes (full detail for 90 days, then reduced to minimal metadata for up to 24 months) — this does not include your spec or tool data.
Full technical detail (data model, retention periods, what's logged) is in Technical Transparency.
Server logs
Like most websites, our server may keep standard access logs (IP address, browser information, page visited, timestamp). This information is used for security and basic usage analytics. Application logs are kept for 30 days and security/authentication logs for 90 days; neither ever contains free-tool tool content, API Guard spec content, or auth/session tokens.
Cookies, analytics, and advertising
Cryonel loads Google Analytics 4 on public pages and the fixed signup/dashboard funnel routes with analytics and advertising storage denied by default. Before you allow analytics, Cryonel sends no GA4 page-view or product-interaction events; the Google tag request and consent-state signals may still reach Google without analytics cookies. If you choose “Allow analytics”, GA4 receives canonical public page views plus allowlisted route-level product events. Account page views, query strings, URL hashes, email addresses, user IDs, spec URLs, and free-tool or account content are excluded. Signup and dashboard events use only fixed route, method, plan, source and billing-period labels. You can change the choice using “Privacy choices” in the footer.
Cryonel loads the Google AdSense site code only on documentation and reference pages. The homepage, free-tool workspaces, API Guard product/demo pages, pricing, services and account pages do not load it. Google may receive standard request data such as your IP address, browser information, referring page, and page URL where the code is present. Cryonel never sends free-tool input or output to Google. Ad serving for visitors in the EEA, United Kingdom, or Switzerland will not be enabled until advertising consent choices are handled through a Google-certified consent management platform.
API Guard uses strictly necessary first-party session and CSRF cookies after login. See the Cookie Policy for names, purposes, and lifetimes, and review Google's Privacy Policy for Google's processing.
Third-party links
If you follow a link away from our site, the destination site's own privacy policy applies; we are not responsible for the content of those policies.
Changes
This policy may be updated from time to time. Material changes will be posted on this page.
Contact
For privacy-related questions, use the Contact page.