Files
token-tools/public/docs/PRIVACY-SECURITY.md
T
2026-09-01 13:04:50 +02:00

519 B

Privacy and security

All input stays in memory in the current browser. CSP allows only same-origin connections and the application initiates none. There is no telemetry, storage, account or remote asset.

Parsing is capped at 1 MiB, depth 64, 50,000 JSON values and 10,000 extracted tokens. Aliases are exact path references and cannot execute expressions. CSS/Sass strings, XML and Swift strings are target-escaped; normalized identifier collisions and unsupported composite values are recorded as explicit losses.