Overview
DevToolKit provides PDF, image, developer, and everyday tools with processing labels that describe where each tool’s core operation runs. This Privacy Policy explains how information may be handled when you use the website.
This page is informational and is not legal advice. Consult a qualified professional if you need formal legal guidance.
Who operates the site
DevToolKit is operated as an independent web project. The public product name is DevToolKit. No separate legal entity name or business address is published on this site today.
For privacy questions, contact amanhirut32@gmail.com.
Information you enter
When you email DevToolKit, we receive your email address, message content, and any details you choose to include, such as bug reports, browser information, or workflow descriptions.
Basic tools do not require an account today. There is no live contact-form backend; email is the primary support channel.
Do not send passwords, private keys, confidential documents, or production secrets unless absolutely necessary for your question.
In-browser tool processing
Forty-three tools perform their core operations in your browser. For those workflows, the tool’s primary input is not sent to a DevToolKit processing endpoint for the core task.
In-browser processing does not mean the page makes no network requests. The site still loads application assets and may send analytics metadata, advertising-related requests when configured, and ordinary browser traffic.
Local processing does not create a legal or technical confidentiality guarantee. Browser extensions, shared devices, clipboard history, downloaded files, screen capture, malware, and browser caches remain possible exposure points.
Server-backed tool processing
Two tools transmit input to configured DevToolKit backend services: Background Remover and PDF Editor & Signer.
Background Remover: After you click Remove background, the selected image is sent to POST /api/images/remove-background on the configured application backend. The backend typically forwards the image to an internal Python background-removal service. In high-quality mode, if a remove.bg API key is configured on the server, the image may also be sent to remove.bg (https://api.remove.bg) before or instead of certain local model paths. Output is returned to your browser for download.
PDF Editor & Signer: When you upload a PDF or request previews, text detection, or export, the selected PDF and related edit data are sent to configured PDF endpoints such as /api/pdf/edit, /api/pdf/text-layer, and /api/pdf/page-image. These requests are forwarded to a configured Python PDF service for processing.
The inspected server upload handlers use in-memory buffers rather than saving uploaded files to an application database or object store. Framework buffers, hosting infrastructure, reverse proxies, service logs, and external providers may still retain data according to their own practices.
The current implementation does not establish a user-facing deletion guarantee or fixed retention schedule for server-backed file processing.
External thumbnail retrieval
YouTube Thumbnail Downloader parses video URLs or IDs in your browser. To preview thumbnails, your browser requests image URLs from Google’s thumbnail CDN at https://i.ytimg.com/vi/{videoId}/{filename}. DevToolKit does not use the YouTube Data API for this workflow.
Opening the watch page sends you to YouTube. A thumbnail request can expose ordinary network information (such as IP address and browser metadata) to YouTube or Google.
Public thumbnail accessibility does not establish video status, ownership, or reuse rights.
Contact and waitlist messages
Email messages and mailto links on Contact, Support, Pricing, and API pages are handled through your email provider. DevToolKit receives whatever you send.
There is no automated waitlist database or contact-form storage in the current public site implementation. Early-access interest is collected through email only.
Support correspondence may be kept for as long as reasonably necessary to respond, maintain support history, and improve the service.
Analytics and diagnostics
DevToolKit uses a first-party analytics endpoint at /api/stats/track. Client code sends event metadata such as event name, page path, referrer, timestamp, and non-sensitive fields. Known sensitive keys such as passwords, tokens, file names, and raw file contents are filtered out before sending.
The backend may store aggregated daily counters by tool slug in MongoDB (request counts and byte totals). This is not designed to store uploaded file contents.
Server request logs may include route, status, duration, IP address, and user agent. These logs are intended for operations and debugging, not for storing file contents.
Identified event payloads are designed not to include tool contents where verified, but analytics and hosting providers may receive ordinary request and device metadata.
Advertising and Google AdSense
DevToolKit is configured for Google AdSense. A publisher account meta tag is present in site metadata for site ownership verification. The AdSense script loads only when NEXT_PUBLIC_ADSENSE_ENABLED and NEXT_PUBLIC_ADSENSE_CONSENT_READY are both true after a Google-certified consent platform is configured.
Display ad units remain disabled until those flags are set and ad slots are configured. ads.txt includes the publisher authorization line matching the site meta tag once deployed; AdSense dashboard verification of ads.txt remains the publisher’s responsibility.
When advertising is active, Google and authorized advertising partners may use cookies or similar technologies to serve, measure, and personalize ads, subject to consent choices and applicable law. You can review Google ad personalization controls at https://adssettings.google.com and Google’s advertising policies at https://policies.google.com/technologies/ads.
Ad partners receive technical data needed to deliver and measure ads, not the contents of files you process in tools.
Consent choices
DevToolKit does not currently deploy a Google-certified consent management platform (CMP) or IAB TCF integration in the public site code reviewed for this policy.
If you are in the European Economic Area, the United Kingdom, or Switzerland, advertising cookies should not be treated as consent-governed until a certified CMP and consent signals are implemented in a separate technical task.
Depending on applicable law, you may have rights relating to personal information. Contact the privacy address above to make a request. DevToolKit does not offer a self-service privacy dashboard today.
Local storage
The inspected public application code does not define persistent localStorage or sessionStorage keys for preferences, consent records, or saved tool history.
Your browser may still store cached assets, downloaded outputs, and form autofill data according to its own settings.
Service providers
DevToolKit may rely on hosting (including Render for the configured API backend), MongoDB for aggregated analytics, Google AdSense when enabled, Google/YouTube thumbnail CDN requests from the YouTube Thumbnail Downloader, internal Python processing services, optional remove.bg for certain background-removal modes, and email delivery through your mail provider when you contact support.
Provider availability, processing location, logging, and retention practices may differ. Contact support before using a server-backed tool when you need details about the provider currently configured for that workflow.
Retention
Tool inputs for in-browser tools remain in browser memory unless you download results or your browser caches them.
Server-backed uploads are handled in memory in the inspected handlers and are not explicitly written to persistent application storage. Retention by hosting infrastructure, logs, or external providers is not guaranteed to match job completion.
Aggregated analytics counters persist in MongoDB by day and tool slug until deleted through backend administration.
Advertising data controlled by Google or other ad partners is governed by their policies, not this site’s retention settings.
Security limitations
DevToolKit is served over HTTPS in production, but HTTPS alone is not a complete security guarantee.
Do not upload confidential legal, medical, financial, identity, or private business files to server-backed tools unless you accept the processing and provider boundaries described above.
International processing
DevToolKit is available on the public web. Server-backed processing, analytics storage, advertising, and external thumbnail requests may involve infrastructure or providers in countries other than your own.
Children
DevToolKit is a general-purpose utility site and does not knowingly collect personal information from children through a dedicated account system. Basic tools do not require signup.
If you believe a child has sent personal information by email, contact the privacy address above.
Policy changes
This Privacy Policy may be updated when processing behavior, providers, or legal requirements change. The “Last updated” date at the top reflects the most recent material revision.
Contact
For privacy questions, email DevToolKit at amanhirut32@gmail.com. Include enough detail for us to understand your question, but avoid sending confidential file contents unless necessary.
Contact support if you need to know which backend or external provider is currently configured for a server-backed tool.