search
verified_userGlobal Data Protection Standard

Privacy Policy & Global Data Policy

Effective Date: September 4, 2026 • Last Reviewed: September 2026

At ToolSphere ("ToolSphere", "we", "us", or "our"), your privacy is the architectural foundation of our engineering. We design high-performance file utilities, format converters, and developer APIs with an unwavering commitment to data minimization, transparency, and user ownership.

This Global Data Policy details how ToolSphere handles your files, accounts, and metadata in strict compliance with global privacy regulations, including the European Union General Data Protection Regulation (GDPR), United Kingdom GDPR, California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), Canada PIPEDA, and the EU ePrivacy Directive.

timer

Strict 60-Minute Purge

When server processing is required, uploaded files and converted outputs are stored in ephemeral sandboxes and automatically wiped within 60 minutes.

lock

Zero AI Model Training

Your documents, images, and converted data are never analyzed, indexed, mined, or used to train, fine-tune, or evaluate artificial intelligence models.

visibility_off

Zero Third-Party Tracking & Advertising SDKs

We have completely eliminated third-party tracking scripts, advertising SDKs, and commercial analytics beacons. We do not monetize user data or participate in cross-site behavioral tracking networks.

1. Core Privacy Principles

Our engineering framework adheres to four fundamental pillars:

  • Absolute Data Minimization: We only process data strictly necessary to execute the tool function requested by you.
  • Ephemeral Storage: Files are never retained beyond the immediate operational requirement. Once processed, your files are permanently purged.
  • Client-Side Execution Priority: Whenever technically feasible (e.g., client-side PDF manipulation, SVG rasterization, image filters), tasks execute directly inside your local web browser sandbox using WebAssembly (Wasm) and HTML5 APIs without uploading a single byte to any remote server.
  • No Data Monetization: We generate revenue solely through optional Pro/Enterprise subscriptions and developer API licenses. We will never sell, rent, or trade your personal data or document content to brokers or marketers.

2. File Lifecycle & The 60-Minute Rule

The 60-Minute Lifecycle: Files transmitted to ToolSphere for server-side processing reside in isolated, single-use execution sandboxes. Automated container lifecycle cron jobs systematically sweep storage volumes and permanently purge all input files, temporary working buffers, and processed outputs within 60 minutes of upload.

Please note:

  • Irreversible Deletion: Once the 60-minute window has elapsed, deleted files cannot be restored, retrieved, or recovered by our engineering team. We strongly urge you to download your converted files immediately upon completion.
  • No Inspection: No human or automated system ever opens, reads, parses, or reviews the contents of your files, documents, or images.
  • In-Memory Processing: Where possible, document transformations occur directly in volatile system memory (RAM) and are discarded immediately upon stream delivery.

3. Information We Collect

We collect only the minimum information necessary to maintain platform reliability, security, and user accounts:

A. Account Information (Registered Users Only)

If you register for a ToolSphere account, we collect your email address, securely encrypted account password, optional name, and dashboard preferences (e.g. pinned tools, theme preference). Guest users can use all free utilities without creating an account.

B. Payment & Subscription Data

Paid subscription transactions are handled exclusively by our certified PCI-DSS Level 1 payment gateway partner. ToolSphere never receives, stores, or processes complete credit card numbers, CVVs, or bank details. We receive only a tokenized customer identifier, subscription status, and billing cycle dates.

C. First-Party Technical Telemetry

To protect our infrastructure from automated attacks, enforce API rate limits, and monitor server capacity, our internal systems record pseudonymous technical metadata: request timestamps, HTTP response codes, tool identifier invoked, file size bytes, duration, and pseudonymous connection identifiers. This diagnostic telemetry is stored in our private database and is never shared with third parties.

D. Voluntary Feedback & Reviews

If you voluntarily submit tool reviews or ratings, your rating and comment are stored. You are not required to provide personal identifying information when leaving feedback.

4. European & UK Privacy Rights (GDPR / UK GDPR)

If you reside in the European Economic Area (EEA), United Kingdom, or Switzerland, the following provisions apply under the General Data Protection Regulation (Regulation (EU) 2016/679) and UK Data Protection Act 2018.

Legal Bases for Processing (GDPR Art. 6)

  • Performance of a Contract (Art. 6(1)(b)): Executing requested file conversions, managing account access, and fulfilling paid Pro/Enterprise subscriptions.
  • Legitimate Interests (Art. 6(1)(f)): Mitigating automated abuse, rate-limiting, diagnosing technical errors, and maintaining cloud network security.
  • Legal Obligation (Art. 6(1)(c)): Retaining statutory financial and taxation records for paid transactions as required by commercial law.
  • Consent (Art. 6(1)(a)): Where you provide explicit opt-in consent for optional communication or preferences.

Your Statutory Data Subject Rights (Chapter III)

Right of Access (Art. 15)Request confirmation of personal data processed and receive an export copy.
Right to Rectification (Art. 16)Request correction of inaccurate or incomplete personal records.
Right to Erasure (Art. 17)Request permanent deletion of your account and personal profile data.
Right to Data Portability (Art. 20)Receive your personal profile data in a structured, machine-readable JSON format.
Right to Restriction (Art. 18)Request suspension of processing under statutory dispute circumstances.
Right to Object (Art. 21)Object to processing founded upon legitimate business interests.

You also retain the statutory right to lodge a formal complaint with your local Data Protection Authority (DPA) in your EU Member State or the UK Information Commissioner's Office (ICO). To exercise your rights, submit a verified request via our Contact Us Portal (select "Privacy, GDPR & Legal Requests"). We respond to all verified requests within 30 days without charge.

5. California & US State Privacy Rights (CCPA / CPRA)

Under the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA) and similar statutes in Virginia, Colorado, Connecticut, and other US states, residents possess specific rights regarding their personal information.

Notice at Collection (Preceding 12 Months)

CategoryExamples CollectedBusiness Purpose
IdentifiersEmail address, account ID, pseudonymous connection identifier, session token.Authentication, account administration, security abuse prevention.
Commercial RecordsSubscription tier, payment timestamps, billing history.Subscription access, billing support, financial accounting.
Internet ActivityTool invocation counts, technical browser/OS headers, page paths.Platform capacity planning, error diagnostics, DDoS mitigation.
GeolocationCountry-level origin derived from reverse-proxy network headers.Localization, compliance enforcement, security auditing.

Do Not Sell or Share My Personal Information

ToolSphere does not sell your personal information for monetary consideration, and does not share your personal information for cross-context behavioral advertising. We have not done so in the preceding 12 months.

We do not collect or process Sensitive Personal Information (SPI) for inferring consumer characteristics. California consumers may exercise their Right to Know, Right to Delete, Right to Correct, and Right to Non-Discrimination directly through our Contact Us Portal (select "Privacy, GDPR & Legal Requests").

6. Sub-Processors & Infrastructure

To operate our high-availability platform, ToolSphere engages a limited number of specialized technical sub-processors. All sub-processors are bound by strict Data Processing Agreements (DPAs) and security obligations:

Sub-ProcessorFunctionLocationTransfer Mechanism
Payment Gateway PartnerCredit card payment gateway & subscription billing portalUnited States / GlobalData Privacy Framework / Standard Contractual Clauses (SCCs)
Cloud Infrastructure ProviderEphemeral execution environments and private encrypted databasesEuropean Union / USAISO 27001 / SOC 2 Certified Data Centers
Headless Conversion EngineSelf-hosted isolated document rendering service (Internal Network)Self-Hosted Private BridgeIsolated internal application network; Zero external egress

We do not utilize third-party analytics vendors, advertising data networks, or cloud AI APIs for processing document contents.

7. Cookies & Browser Storage Policy

ToolSphere employs a privacy-first approach to browser storage. In strict accordance with the EU ePrivacy Directive and global cookie guidelines:

Strictly Necessary Authentication CookiesStandard session tokens (next-auth.session-token, __Host-authjs.csrf-token) are set solely to authenticate registered user accounts, protect against Cross-Site Request Forgery (CSRF), and maintain session security. These cookies are essential for account functionality.
Functional Browser Local StorageWe utilize client-side localStorage to remember your selected interface theme (Dark/Light mode), recently accessed tools, and a pseudonymous session key (toolsphere_vid) used to throttle automated bot abuse and prevent rate-limit flooding. These items never leave your device for advertising purposes.
Zero Third-Party Advertising or Marketing CookiesToolSphere places zero advertising cookies, tracking beacons, or cross-device profile builders.

You can control or erase cookies and local storage items at any time through your browser settings. Disabling local storage will not prevent you from using our free document utilities.

8. Data Retention Schedule

Data Record TypeRetention WindowPurge Mechanism
Uploaded Documents & Output FilesMaximum 60 MinutesAutomated cron job unlinks and wipes files from disk block volumes.
User Account ProfilesDuration of account lifecyclePermanently purged immediately upon user request or account deletion.
Tool Processing MetadataDuration of account lifecycleStores non-content record (tool, duration, size); purged on account deletion.
Infrastructure Security Logs30 DaysAutomatically overwritten on rolling 30-day log rotation.
Financial & Invoicing Records7 YearsMandatory retention for statutory tax and financial compliance.

9. Technical Security Controls

We implement comprehensive technical and organizational measures (TOMs) to safeguard your data:

  • Encryption in Transit: All data transmitted between your browser and our servers is enforced over TLS 1.3 with HSTS (HTTP Strict Transport Security) preloading enabled.
  • Container Isolation: File processing commands execute inside unprivileged, ephemeral Linux containers with restricted system calls and isolated file system namespaces.
  • Defensive Security Headers: Comprehensive Content Security Policy (CSP), X-Frame-Options (DENY), and Cross-Origin Resource Policy headers protect against clickjacking and script injection.
  • Rate Limiting & Abuse Defense: Built-in rate limiting (withApiSecurity) prevents brute-force attacks and denial-of-service abuse.

10. Children's Privacy

ToolSphere is not intended for or directed to children under the age of 13 (or under 16 for residents of the European Economic Area). We do not knowingly solicit, collect, or process personal information from children. If we discover that a child has provided us with personal data, we will immediately delete that information from our servers. Parents or guardians who believe their child has submitted personal data may notify us directly through our Contact Us Portal.

11. Contact & Data Protection Requests

If you have any questions, inquiries, or requests regarding this Privacy Policy, your statutory data rights, or our security practices, please contact our Data Protection Team:

Data Controller: ToolSphere Precision Utility System
Inquiry & Compliance Portal: Reach our Data Protection Officer and Privacy Operations Team via our Contact Us Page (select Privacy, GDPR & Legal).
Response Commitment: All verified GDPR, CCPA, and general privacy inquiries are answered within 30 calendar days.