omnitoolbox is built on a simple premise: tools that can run in your browser should run in your browser. This policy explains exactly what data is processed when you use the site, what goes to a server, and what doesn't.
This policy applies to the website at omnitoolbox.net and all tools hosted on it. It does not apply to third-party services that tools may call (such as Proton or Google AdSense) — those are governed by their own privacy policies, linked where relevant.
Short version: Most tools process your data entirely in your browser. When a tool does need a server, we read only what the tool requires and we do not log your queries or store personal data.
The table below is a complete reference for what omnitoolbox does and does not collect.
| Data type | Collected? | Notes |
|---|---|---|
| IP address | Transient | Read by Cloudflare infrastructure and by server-side tools (My IP, VPN Check). Not stored in any database by omnitoolbox. |
| Tool inputs — browser-only tools | No | Passwords, hashes, JSON, Base64, regex, JWTs, etc. never leave your browser tab. |
| Tool inputs — server-side tools | Transient | Domain names and URLs sent to our Workers to fetch results. Not logged or stored. |
| First-party cookies | No | We set no cookies. Theme preference is stored in localStorage only. |
| Third-party cookies (AdSense) | Yes | Google AdSense may set cookies for interest-based advertising. See §4. |
| Analytics / tracking pixels | No | No Google Analytics, Plausible, Mixpanel, or equivalent tracking script is loaded. |
| Error / crash monitoring | No | No Sentry, Datadog, or similar tool is in use. |
| User accounts or profiles | No | The site has no registration, login, or account system. |
| Email addresses | No | Not collected except when you email us directly. |
| Payment data | No | The Service is free. No payments are processed by omnitoolbox. |
| Infrastructure logs (Cloudflare) | Yes — via host | Cloudflare logs standard access data (IP, path, timestamp, status code) per its own retention policy. |
The following tools process all input locally, using browser APIs. Your data is never sent to our servers or any third party:
window.crypto.getRandomValues() and exist only in your browser tabatob() in the browser; tokens are never sent over the networkbtoa() / atob() locallyencodeURIComponent() / decodeURIComponent() in the browsercrypto.randomUUID() or a fallback; no server call is madeIntl APIFor these tools, the only network requests are the initial page load (HTML, CSS, JS from Cloudflare's CDN) and, if you have not blocked it, the Google AdSense script.
Some tools need to make outbound requests to function. In each case, the request is the minimum necessary to return a result and is not logged beyond what Cloudflare's infrastructure records as standard access logs.
| Tool | What is sent | Why |
|---|---|---|
| My IP & Privacy Audit | Your browser's request itself (IP address, headers, TLS version) | The tool reads connection metadata from the incoming request to show your public IP, ISP, geolocation, and TLS grade |
| VPN & Proxy Checker | Your public IP address | Checked against ASN and reputation databases to determine if the IP belongs to a VPN, datacenter, or residential ISP |
| WHOIS Lookup | The domain name you enter | Our server queries WHOIS databases on your behalf and returns the registration record |
| DNS Lookup | The domain name and record type you select | Our server queries authoritative DNS resolvers and returns the records |
| SSL Certificate Checker | The domain name you enter | Our server connects to the domain's HTTPS port and retrieves the certificate chain |
| HTTP Header Inspector | The URL you enter | Our server makes an HTTP request to the URL and returns the response headers |
| Website Down Checker | The domain or URL you enter | Our server attempts to reach the target and reports whether it is reachable |
| Meta Tags Checker | The URL you enter | Our server fetches the page HTML and extracts Open Graph, Twitter Card, and standard meta tags |
We do not combine server-side query data with any user identity or store it in a database. Standard infrastructure logs (IP addresses, timestamps, response codes) are retained only as long as required by Cloudflare's default log retention policy.
omnitoolbox sets one first-party item in localStorage: your theme preference (dark, light, or system). This is stored locally in your browser and never transmitted to any server.
No session cookies, authentication cookies, or tracking cookies are set by omnitoolbox directly.
Third-party cookies may be set by Google AdSense (see section 4 below).
omnitoolbox displays advertising provided by Google AdSense. Google AdSense is a third-party advertising network that may use cookies and device identifiers to serve ads based on your prior visits to this and other websites. This is known as interest-based or personalised advertising.
Google's use of advertising cookies is governed by Google's own Privacy Policy at policies.google.com/privacy. You can manage Google's use of your data for advertising through:
omnitoolbox does not pass personally identifiable information to Google AdSense. The ads you see are determined by Google's systems based on contextual signals from the page and, if you have not opted out, your browsing history.
Some links on this site are affiliate links, primarily to Proton's suite of privacy-focused services (VPN, Mail, Drive, Pass). When you click an affiliate link and complete a purchase, omnitoolbox may earn a commission at no additional cost to you.
Affiliate links are not disguised as editorial content. They appear in the navigation bar and in tool pages where Proton's services are directly relevant (for example, the VPN checker page links to Proton VPN). Affiliate relationships have no influence on how tool results are generated or displayed.
omnitoolbox may use privacy-respecting analytics to understand aggregate traffic — page views, top tools, referrer sources, and browser/OS breakdown. If used, this is aggregated data only. Individual users are not identified, profiled, or tracked across sessions.
No analytics scripts that share individual-level data with third parties are in use on this site beyond Google AdSense (covered in section 4).
Server-side tools make requests to third-party APIs to fetch results:
omnitoolbox does not control the privacy practices of these third-party data sources. We pass only the minimum query required (a domain name, URL, or IP address) and do not include any identifiers that would allow the third party to link a query to you.
omnitoolbox does not maintain a database of user queries, tool inputs, or results. The site does not operate user accounts and therefore does not store personal profiles.
Cloudflare, our infrastructure provider, may retain server access logs (IP address, request path, timestamp, HTTP status code) in accordance with its own data retention policy. These logs are used for abuse detection and infrastructure monitoring. For details, see Cloudflare's Privacy Policy.
If you are located in the European Economic Area (EEA) or United Kingdom, the General Data Protection Regulation (GDPR) or UK GDPR may apply to the processing of your personal data.
You have the right to: access personal data held about you; rectify inaccurate data; erase data ("right to be forgotten"); restrict processing; data portability; and object to processing based on legitimate interest. Because omnitoolbox does not store personal data in any database, most of these rights are fulfilled by design. For Cloudflare infrastructure logs, please refer to Cloudflare's Privacy Policy. For AdSense data, refer to Google's Privacy Policy.
omnitoolbox is hosted on Cloudflare's global network. Your requests may be processed at a Cloudflare data centre outside your country. Cloudflare maintains Standard Contractual Clauses and other transfer mechanisms required under GDPR. Google AdSense similarly operates under GDPR-compliant transfer frameworks.
omnitoolbox retains no personal data. Cloudflare's infrastructure log retention is governed by Cloudflare's own policies. We do not have access to or control over those logs beyond what Cloudflare exposes in its dashboard.
If you are a California resident, the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA) provides you with specific rights regarding your personal information.
In the past 12 months, omnitoolbox has collected the following categories of personal information (as defined by CCPA):
| Category | Collected | Source |
|---|---|---|
| Identifiers (IP address) | Transient — via Cloudflare | Automatically from your device when you access the site |
| Internet / network activity | Transient — via Cloudflare | Request paths and timestamps recorded in infrastructure logs |
| Geolocation data | Derived — via Cloudflare | Approximate location inferred from IP address for geo-routing |
| Commercial information | No | — |
| Biometric information | No | — |
| Audio, visual, or similar | No | — |
| Professional / employment info | No | — |
| Sensitive personal information | No | — |
Personal information collected (IP addresses and request logs via Cloudflare) is used solely to: deliver the Service to you; maintain security and prevent abuse; and comply with legal obligations. We do not sell personal information. We do not share personal information with third parties for cross-context behavioural advertising, except as described in §4 (Google AdSense), where you can opt out.
To submit a CCPA request, contact us at [email protected]. We will respond within 45 days as required by law.
omnitoolbox does not knowingly collect personal data from children under the age of 13 (or the applicable local age of digital consent). The tools are general-purpose developer and utility tools not directed at children. If you believe a child has submitted personal data through the site, contact us at the address below and we will take appropriate action.
This policy may be updated from time to time. The date at the top of the page reflects when it was last revised. Significant changes will be noted in that date. Continued use of the site after an update constitutes acceptance of the revised policy.
We do not send policy update notifications by email because there are no user accounts or email lists on this site.
Questions about this policy or data handling practices: [email protected]
We aim to respond within 5 business days.