Last updated: 2026-07-10
Privacy Policy
1. Who we are
This site (the “Service”) is a browser-based developer toolkit operated by SUB&SUB LLCthe site owner (“we”, “us”, “our”). For privacy questions you can reach us at [email protected][email protected].
2. Local-only processing
Most tools — Base64, TOTP, JWT, QR, hashing, hex, HTML entities, regex, diff, color, UUID, password, Unix timestamp, coin flip, timer, and melody — run entirely in your browser. The data you paste, type, or drop into these tools is never sent to our servers, never stored on disk by us, never shared with any third party, and is discarded when you close the tab. (Tool preferences — such as timer and alarm setups — are the one exception: they sync to your account if you sign in, as described in section 6.)
3. What we do not do
We do not run analytics, advertising, fingerprinting, or behavioural tracking. Your browser loads no third-party scripts, fonts, or tracking pixels — all assets are self-hosted. We never sell, rent, or share your data with third parties for marketing purposes.
4. Local browser storage
The Service uses localStorage to remember your preferences and tool state on your device. This includes: theme settings (mode, palette, font, animation), active tab and tab ordering, clipboard history, file-share history, currency converter preferences, weather favorites, timer/alarm configuration, radio favorites, melody notes, and your LAN pairing code. This data stays on your device, is readable only by this site, and you can clear it at any time from your browser settings.
The Service is also installable as a Progressive Web App. The service worker caches static page assets so the tools keep working offline. It does not cache or transmit any of your input.
5. Account & authentication
Signing in is entirely optional. You can use every tool without an account. If you choose to sign in, authentication is handled by the main site (subnsub.com), which sets an sid session cookie scoped to .subnsub.com. This cookie is HttpOnly (not readable by JavaScript), SameSite=Lax, and contains only a random session token — no personal data. The tool site reads this cookie solely to identify your session; it never sets cookies of its own.
6. Cloud sync
When signed in, you may opt to sync your settings across devices. This uploads a subset of your localStorage data — theme and appearance preferences (including fonts, background and wallpaper settings), tab layout and groups, per-tool preferences (pinned currencies, weather favorites, timer and alarm configuration, and similar), clipboard history, and file-share history — to our server, stored in a per-user record. If you set a custom background image, that image is uploaded to your account's private storage as well; removing it deletes the stored copy. Generating a settings sync link packages the same settings into a small file uploaded through the temporary file share, where it expires like any other shared file. This data is visible only to you, is never shared with third parties, and can be deleted by signing out and clearing your account. No sync occurs unless you are signed in.
7. Temporary file sharing
The file-share tool lets you upload files for temporary sharing. Files are stored on our infrastructure and automatically expire (5 minutes to 3 hours depending on your tier). We do not inspect file contents. All files are served as opaque downloads. After expiry, files are deleted and cannot be recovered.
8. Server-proxied tools
A few tools fetch live data through our server, which acts as a proxy to public data sources — and a couple connect your browser directly to the service they measure or play. No user account or identity is forwarded in either case.
- Weather: the city name or coordinates you search are forwarded to a weather data provider to return forecasts.
- Stocks: the ticker or company name you search is forwarded to a market-data provider.
- Wallet / ENS: the wallet address or ENS name you enter is forwarded to a public Ethereum node. We do not log or store this query.
- Currency: our server fetches a public exchange-rate table. The amounts you convert never leave your browser.
- IP info: your own IP address and the geolocation metadata your hosting provider attaches to the request are shown back to you. We do not store this data — unless you are signed in and explicitly save a network snapshot (see below).
- World Cup: live scores, fixtures, and standings are fetched from public sports feeds (ESPN, TheSportsDB) through our server. Nothing about you is forwarded.
- Speed test: your browser connects directly to Cloudflare's measurement endpoints (speed.cloudflare.com, aim.cloudflare.com) to run the test. Cloudflare already serves this site; signed out, we log nothing about your runs. Signed in, each finished result — speeds, latency, jitter, packet loss, your ISP/ASN and the Cloudflare location, with a timestamp — is saved to your account's speed history (the last 10 results, 100 with Plus; older entries roll off automatically). You can delete any entry, and deleting your account wipes the history.
- Radio (in the Timer panel): streams connect your browser directly to each station's own server, and the station directory is fetched from radio-browser.info. Both stay off until you enable the radio.
- My IP self-checks: the WebRTC leak probe contacts a public STUN server (stun.l.google.com) and the DNS checks query cloudflare-dns.com and dns.google directly — that is how those checks work. Results are shown only to you; we do not store them.
- LAN transfer: online pairing relays a small connection offer through our signalling worker (it never sees file contents), and connection setup may contact public STUN servers (Cloudflare, Google) to discover network addresses. The file bytes themselves never touch our servers — they normally travel directly peer-to-peer. On Plus, if no direct route can be established, the encrypted stream may fall back to a TURN relay operated by Cloudflare; the relay can see connection metadata (device addresses and traffic volume) but forwards only encrypted bytes and cannot read file contents.
- On This Day: the history card on the Today page fetches the day's events from Wikimedia through our server. Only the calendar date and your interface language are sent; nothing about you is forwarded.
- Gas & oil prices: our server fetches public futures quotes from market data providers. The request carries nothing about you.
- Apple Music artwork: the album, song, playlist or artist ID from the Apple Music link you paste is forwarded to Apple to fetch its cover art. Nothing else about you is sent, and the request is not stored.
- Tool requests (Community tab): a request you submit while signed in — its title, description, your replies, your interface language and timestamps — is stored with your account so staff can review it and you can track its status. Requests that reach a final state may be deleted after 90 days; deleting your account deletes them immediately.
- My Tools generation (Plus): the tool description you submit — plus your interface language — is sent to our AI relay to draft the tool spec. The description and the resulting draft are stored with your account so you can review them; finished jobs may be deleted after 90 days, and deleting your account deletes them immediately.
- My Tools runs: when you run one of your own tools, the values you typed (and any API keys you saved for it, decrypted only server-side) are substituted into that tool's single declared API request and proxied by our server to the host its spec allows. We do not store the request or the response.
- Network snapshots (My IP): when you are signed in and press Save snapshot, that moment's record — your IP address, approximate location, timezone, ISP/ASN, Cloudflare location, the reverse-DNS name shown to you, and the reputation and IPv6 scores — is stored with your account (3 snapshots, 10 with Plus). Saving is always an explicit click, you can delete any snapshot, and deleting your account wipes them all.
- Calculator (Calc Pro): every calculation runs entirely in your browser — expressions are never sent anywhere to be evaluated. Signed out, nothing is stored. Signed in, each calculation you explicitly save (Enter / =) — the expression and its result — is kept in your account's calculation history (the last 10 entries, 100 with Plus; older entries roll off automatically). You can delete any entry, and deleting your account wipes the history.
- Doc to PDF (Plus): the document you convert is sent to our conversion server over an encrypted connection, converted to PDF in memory by a LibreOffice engine, and streamed straight back. Neither the file nor its name is stored or logged anywhere — the moment your PDF is delivered, nothing remains. Conversions are rate-limited per account; only the count, never the content, is tracked.
- Referral (pilot): signing up through an invite link stores which account invited you, and your first subscription marks that referral as converted so the inviter earns promo days. Promo days of your own are stored with your account; all referral data is deleted with your account.
- Published images (Plus): when you explicitly publish a clipboard image, a metadata-stripped copy (EXIF/GPS removed) is placed at a random public URL on img.200000.live — anyone who has the link can view it. The ownership record (which slot, when) is stored with your account. Unpublishing (or deleting the slot) removes the public copy, though CDN caches can hold it up to a day; deleting your account removes every published image.
9. IP address handling
For rate limiting and abuse prevention, our server hashes your IP address (SHA-256) and stores only the truncated hash. Your plaintext IP address is never written to any persistent storage. The IP info tool shows your IP back to you but does not store it — the one exception is a network snapshot you explicitly save while signed in, which is kept with your account until you delete it.
10. Billing
The optional paid plan (Plus) is billed through Stripe via the main site (subnsub.com). Payment details (card number, billing address) are handled entirely by Stripe and never reach our servers. We store only your subscription status and expiry date.
11. Hosting & infrastructure
The Service is hosted on Cloudflare. Cloudflare may process request metadata (IP address, headers, timestamps) as part of delivering the site. Cloudflare’s own privacy policy applies to that processing. We do not use any Cloudflare analytics or tracking products.
12. Security
All connections use HTTPS. Sensitive operations (hashing, TOTP, JWT) happen entirely on your device. We recommend keeping your browser and OS up to date and avoiding the use of secrets (such as TOTP seeds or private keys) on shared or compromised machines.
13. Children’s privacy
The Service is a general-purpose developer tool and is not directed at children under 13. We do not knowingly collect personal information from children.
14. Changes to this policy
If we update this Privacy Policy, we will revise the “Last updated” date at the top of this page.
15. Contact
Questions, requests, or concerns about this policy can be sent to [email protected][email protected].