Files
text-tools/public/docs/PRIVACY-SECURITY.md
T
2026-09-01 02:53:56 +02:00

1014 B
Raw Permalink Blame History

Privacy and security

Source text, imported files, recipes and results stay in page memory. There is no telemetry, analytics, account, persistence or runtime network path. Imported text is rendered as text/preformatted content, not executable HTML; HTML escaping produces a string and does not preview it as markup.

Files are rejected above 16 MiB before reading. Decoded/pasted pipeline input is limited to 2,000,000 UTF-16 units, recipe text to 1,000,000 units/100 steps, and output to both 8× the original (with a small-input floor) and 32 MiB. These limits reduce accidental expansion but do not prove that output is safe for a downstream interpreter.

Compatibility normalisation, case conversion, transliteration, whitespace/line transforms, column selection and narrow encodings can change or lose information. Locale sorting depends on the browser's Intl.Collator. The exact source, output, per-step counts and warnings remain visible so users can review those changes before copying or downloading.