11 / PRIVACY
Privacy policy
How Toolars handles browser workspaces, account records, explicit submissions, local preferences, and session data.
Content maintained by Toolars · Updated 2026-09-11
Workspace data
Available local-first tools process workspace content in the active browser context.
Toolars does not intentionally collect raw text, source code, images, PDFs, clipboard values, generated output, or workspace snapshots through account, analytics, logging, request, or feedback systems.
Account and submitted data
When Supabase is configured, authentication and narrow user-owned records support account features.
- AuthenticationAuthentication providers process the email and session information needed for sign-in.
- FavoritesFavorites store tool slugs, not tool contents.
- Tool requestsTool requests store the requested name, use case, optional HTTPS reference, account owner, status, and timestamps.
- Feedback and contactFeedback and contact records store the message, category, relevant tool/path context, account owner, status, and timestamps.
Browser storage and cookies
Historical favorite migration records and saved categories may use local storage. Locale and authenticated sessions may use necessary cookies.
When configured, Toolars sends cookieless PostHog $pageview, $pageleave, $web_vitals, and limited product-usage events. Page-leave fields are limited to opaque page-view IDs, current and previous route paths with query strings and hashes removed, duration, and numeric scroll position and percentage values. Web Vitals fields are limited to numeric CLS, FCP, INP, and LCP measurements plus minimal metric status metadata; attribution, DOM elements, browser performance entries, resource URLs, query strings, and hashes are removed.
The approved product events are tool_open, run_success, download_started, related_tool_click, search_open, no_result, search_result_click, workflow_open, workflow_run_started, workflow_run_success, workflow_export_started, workflow_task_completed, newsletter_subscribe, newsletter_subscribe_success, cta_click, favorite_add, tool_share, task_completed, and tool_task_completed. Product fields are limited to approved event types, tool or Workflow slugs, search result position, and locale; raw search queries are never collected. The task_completed event records only that a tool produced user-taken output: the output action class (download, copy, or export), the outcome class (success or failure), and an optional coarse duration bucket (under 1 second, 1-5 seconds, 5-30 seconds, or over 30 seconds); it never records file names, file sizes, output content, or raw timings. The tool_task_completed and workflow_task_completed events keep the same boundary: each records only the tool or Workflow identifier, locale, and output action class for the first output taken after a successful run, and nothing else. A run starts only after local input checks pass; success means all candidates in that attempt meet the workflow’s verification criteria. Retries count as new attempts. Workflow events do not collect files, file names, counts, formats, dimensions, settings, preset names, findings, errors, or outputs. Click and form autocapture, session recording, browser persistence, user identification, network timing, and tool-content collection remain disabled. Analytics requests are routed through PostHog's managed first-party proxy at track.toolars.com, which uses Cloudflare to forward them to PostHog. The Cookie Settings page can clear known local preferences without signing you out.
Purpose, access, and retention
Toolars is responsible for the data practices described in this policy. Account data supports authentication and user-owned product features; submissions support moderation and product improvement. Privacy requests can be sent to contact@toolars.com.
Row-level security limits users to their own readable records, while trusted service roles support moderation. Anonymous product analytics and error monitoring through PostHog remove unapproved fields, user data, cookies, request headers and bodies, query strings, and extra context before an event is sent. Records may be retained while needed for the stated purpose, abuse prevention, legal obligations, and operational integrity.
Your choices
You can use local tools without an account, avoid optional submissions, reset browser preferences, and sign out of an authenticated session.
Questions or requests concerning account-linked personal data can be submitted through Contact or emailed to contact@toolars.com. Verification may be required before acting on a request.
Policy changes
Material changes will update the effective date and will be announced when they alter the product boundary.
A future cloud or hybrid processor must disclose its service boundary before launch; this policy will not silently represent remote processing as local.
Browser extension
The Chrome extension is a separate surface that collects nothing.
Three permissions: sidePanel opens the tools; contextMenus adds actions for selected text and images; storage passes selected text to the side panel locally.
Extension privacy chapterWant the verifiable view?
Plain-language boundary, typed runtime declarations, disclosed hosts, served security headers, and the checks behind them.