Skip to content

Privacy Policy

Effective date: August 8, 2026 · Last updated: September 7, 2026

This policy explains how SimpleTaskTools handles browser data, optional account data, network requests, and third-party services. The processing-mode notice on each tool is part of this policy: it tells you whether that tool works locally or needs a network request.

SimpleTaskTools is operated by Star InfoTech 360, based in India. For privacy questions or data requests, email hello@simpletasktools.com.

1. Local-first summary

  • You can use the core tools without creating an account.
  • Favorites, recent tools, settings, workspaces, drafts, and supported saved results are stored on your device by default.
  • Signing in does not upload existing local work or turn sync on.
  • Online saving starts only after you explicitly enable it and select the data categories that may sync.
  • Password-like content, JWTs, API keys, private-key material, and secret-like saved items are blocked from account saved-item sync by default.

2. Browser storage

Small preferences use localStorage. Larger workspaces, drafts, invoices, and saved results use IndexedDB. Local records include a storage version so future releases can migrate them safely. The storage settings page lets you export a local JSON backup, import a backup without enabling sync, or clear SimpleTaskTools data from the current device.

Local browser data remains under the browser profile’s security model. Clearing site data, using private browsing, changing profiles, or uninstalling a browser may remove it, so export a backup when the work matters.

3. Optional accounts and selected sync

Account features are available only on deployments configured with database and authentication secrets. If you create an account, we store your email address, optional display name, a one-way password hash, account timestamps, and an HttpOnly signed session cookie. Plain-text account passwords are not stored.

Cloud sync is off for new accounts. You can separately allow favorites, recently used tools, drafts, saved results, workspaces, invoice drafts, UTM presets, prompt templates, API request templates, and preferences. Enabling one category does not authorize another. Existing local records are not silently migrated; the settings page provides a separate, explicit upload action for eligible records.

Synced records may include a tool identifier, title, type, workspace reference, data payload, notes, tags, and timestamps. Saved-item APIs reject secret-like or oversized payloads. You can turn sync off without deleting local data, or delete all synced saved items, workspaces, and preferences while keeping your local copy.

4. Tool inputs and network-enabled features

Local-mode tools process their working input in the browser. Examples include formatters, most generators, calculators, and file tools. Optional account saving is separate from processing and occurs only when you request it under enabled sync settings.

Some features need the network and are labeled accordingly. Examples include network diagnostics, webhook endpoints, public API calls, and optional AI-assisted features such as Tone Formalizer or Brand Context generation. When you initiate one of those actions, the submitted data is sent to the relevant SimpleTaskTools endpoint and may be forwarded to the service needed to complete the request. Do not submit secrets to network-enabled tools.

5. Other information you submit

  • Tool requests and contact messages: the information you enter is sent when you submit the relevant form so we can review or respond. Business inquiries may include an optional company, expected usage, or budget. Submission does not enroll you in marketing or enable account sync. Messages are available to authenticated administrators and can be deleted on request. Rate-limit counters help prevent submission abuse.
  • Webhook tester: requests sent to a generated webhook URL are stored temporarily so the tool can display them.
  • Runtime error reports: when enabled by the application, diagnostic messages may be sent to the site error endpoint. Do not intentionally place secrets in error messages.

6. Analytics, advertising, and sponsors

We use Vercel Analytics to count page views and to record which tools are opened, when output is copied, and when a file is saved. It is cookieless, sets no identifier on your device, and never receives the content you type into a tool, the files you process, or the names you save them under — only the tool name, its category, the kind of action, and for a download the file extension, so we can see which export formats matter. It can be switched off for a deployment with an environment variable.

Optional Google Analytics is separate. On enabled deployments, its script loads only after you accept analytics in the visitor banner. Rejecting does not affect tools or account sync. Google may receive public-page, device, and network information and set first-party analytics cookies. Our manual page-view events exclude URL query strings, fragments, referrers, tool inputs, and account or admin routes. The Analytics settings control at the bottom of each page lets you change your choice. It is saved locally for 180 days; if browser storage is unavailable, it lasts only for this visit. We honor browser Do Not Track and Global Privacy Control signals by blocking Google Analytics.

Withdrawing acceptance disables further Google measurement and attempts to remove this site's first-party Google Analytics cookies. It does not erase information already received by Google. Advertising consent is not granted by accepting analytics. Ad serving is paused in this version while content is reviewed. Before ads are enabled, a separate appropriate advertising consent setup is required; this analytics banner does not activate ads or Google Tag Manager. If Google ads are enabled in a future version, Google and its partners may use cookies, web beacons, IP addresses or other identifiers to deliver and measure ads.

Sponsor blocks render only when a sponsor name and destination are configured, and they are labeled “Sponsor.”

Business inquiry events record an allowlisted inquiry type and button placement, or that a business message was submitted successfully. These events do not include your name, email, company, budget, or message. Contact submissions and saved tool work are not sold to sponsors.

See how Google uses information from partner sites for Google’s explanation of its data use.

7. Security and retention

Account and admin sessions use HttpOnly cookies. Mutating account and admin endpoints reject cross-origin requests. Passwords use a salted scrypt hash. These controls reduce risk but no storage system can promise absolute security.

Local data remains until you clear it or the browser removes it. Synced account work remains until you delete it through settings or request account assistance. Some operational collections use shorter product-specific retention, such as temporary webhook or diagnostic records.

8. Your choices and rights

  • Use tools in guest/local-only mode.
  • Choose individual sync categories, change them later, or disable sync.
  • Export, import, or clear local data independently of online data.
  • Delete synced saved data from account settings.
  • Request access, correction, or deletion assistance through the contact page, subject to applicable law.

9. Children and policy changes

SimpleTaskTools is not directed to children under 13, and we do not knowingly collect their personal information. We may update this policy when the product or legal requirements change; the date above identifies the current version.

10. Contact

For privacy questions or account-data requests, email hello@simpletasktools.com or use the contact page.