Skip to content

SECURITY & DATA GOVERNANCE

Privacy Policy

Last updated: August 25, 2026 · Version 1.0

Kitland is built on a simple premise: your code, API keys, tokens, and data payloads belong exclusively to you. We design every tool to execute locally on your device with no payload uploads and zero tracking SDKs.

1. Zero Payload Collection & Storage

No Payload Logging: Kitland does not collect, record, log, transmit, or store any text, code, JSON payloads, API keys, hashes, tokens, or files you input into any tool.

No User Accounts: Kitland does not require accounts, logins, email addresses, or user profiles.

No In-App Tracking SDKs: Kitland does not embed third-party behavioral tracking libraries (such as Mixpanel, Hotjar, or session recorders) inside the tool application.

2. 100% Client-Side & Local Execution

All transformations, formatters, cryptographic algorithms, regex testers, and data converters run entirely client-side inside your browser tab or local Web Workers.

No payload network requests are dispatched during tool execution. Tools operate completely offline without requiring an active internet connection.

3. Browser Extension & Permissions Boundary

The Kitland Browser Extension operates under a strict zero-permission model:

  • No Permissions: Declares permissions: [] and host_permissions: [] in manifest.json.
  • No Website Access: Does not inject content scripts or access web pages you browse.
  • No Background Network Activity: Contains no background tracking service workers or remote code loading.
  • Store-Level Metrics: Aggregated usage statistics (such as total installs, active extension users, and crash reports) are provided anonymously by the Chrome Web Store Developer Console at the platform level without any telemetry code embedded in the extension itself.

4. Web Sharing & Link State

When using the Web application:

Fragment-Only State: If you explicitly choose to generate a share link, the state is encoded entirely in the URL hash/fragment (#), which is never sent to the web server in HTTP request headers. No server-side payload database is used.

5. Hosting & Third-Party Infrastructure

The static web application is hosted via Cloudflare Pages. Standard, privacy-preserving edge access logs (IP addresses and browser user-agent headers for basic routing and DDoS protection) may be processed by the CDN provider in accordance with their privacy standards. No tool payloads or user inputs are ever visible to or processed by the hosting provider.

We do not sell, rent, monetize, or trade any user information to third parties.

6. Open Source Transparency

Kitland is open source under the MIT License. You can inspect, audit, or self-host our entire codebase on GitHub:

https://github.com/outof0/kitland

7. Contact & Inquiries

If you have any questions, suggestions, or concerns regarding this Privacy Policy, please contact us: