This Privacy Policy explains what information ToolField ("ToolField", "we", "us" or "our") collects when you use toolfield.com and its related tools and services (the "Services"), how we use and protect that information, and the rights you have over it - wherever in the world you are.
THE SHORT VERSION: your files are yours. Files processed by our server-side tools are encrypted in transit, processed automatically, never opened or read by people, never sold, never used to train AI, and deleted automatically within approximately 2 hours. In-browser tools never upload your files at all. We collect the minimum operational data needed to run a secure, reliable service, and we do not sell personal data.
1. WHO IS RESPONSIBLE FOR YOUR DATA
1.1. ToolField, the operator of toolfield.com, is the "data controller" (or the equivalent role under your local law, such as "data fiduciary" under the Digital Personal Data Protection Act, 2023 of India) for personal data processed through the Services. Contact for all privacy matters: [email protected].
2. WHAT WE COLLECT
2.1. Your files. When you use a server-side tool, we receive the file(s) you choose to upload, solely to perform the operation you request. When you use an in-browser tool, your file or text is processed entirely on your device and is never transmitted to us.
2.2. Usage and device data. When you use the Services we collect technical data needed to operate and secure them: IP address, browser/user-agent string, request identifiers, timestamps, the tool used, and technical facts about each run (such as file count, total size, duration and success/failure). With your consent, we may additionally derive an approximate location (country level) and basic device characteristics.
2.3. Account and identity data. You can use the Services without an account; a pseudonymous guest identifier (a cookie) keeps your session working. If you register, we collect the data you provide - such as name, email and password (stored only as a secure hash) or your social-login identity.
2.4. Payment data. If you make a voluntary contribution, the payment is handled by a third-party payment gateway (for example Razorpay). We receive only transaction metadata (amount, currency, status and a payment reference); we never receive or store your card or banking details.
2.5. Support data. If you contact us, we collect what you submit: your message, contact details, optional attachments, and (for bug reports) context such as the page URL and browser version.
2.6. Cookies. See our Cookie Policy for the exact cookies we set, their purposes and lifetimes.
3. YOUR FILES - HOW THEY ARE HANDLED
3.1. Encrypted in transit. Files travel over HTTPS/TLS, and downloads use short-lived, expiring links.
3.2. Automated processing only. Files are processed entirely by software. Our staff do not open, view, read or analyse the content of your files, except where strictly necessary to investigate abuse, security incidents or to comply with legal obligations.
3.3. No content exploitation. We do not sell your files, share them with third parties for their own purposes, use them for advertising, profiling or marketing, or use them to train artificial-intelligence models.
3.4. Automatic deletion. Inputs and outputs of server-side tools are deleted automatically after a short retention window - currently approximately 2 hours - by scheduled cleanup processes, with a storage-level backstop. Support attachments are kept for approximately 7 days. After deletion, files are not recoverable.
3.5. Storage. During the retention window, files are stored with reputable cloud storage providers (see Section 6).
4. WHY WE PROCESS YOUR DATA AND OUR LEGAL BASES
4.1. Where laws such as the EU/UK GDPR apply, we rely on the following legal bases:
(a) Performance of a contract - operating the tools you ask us to run, delivering results and providing support (GDPR Art. 6(1)(b));
(b) Legitimate interests - securing the Services, preventing fraud and abuse, rate-limiting, and measuring aggregate, PII-free usage so we can run and improve the platform (Art. 6(1)(f));
(c) Consent - optional analytics enrichment (approximate country and device class) and any marketing we may introduce (Art. 6(1)(a)); you can withdraw consent at any time via the cookie preferences;
(d) Legal obligation - keeping records we are required to keep (for example payment and tax records) and responding to lawful requests (Art. 6(1)(c)).
5. WHAT WE DO NOT DO
5.1. We do NOT sell or rent personal data. We do NOT share personal data with third parties for their own marketing. We do NOT run third-party advertising. We do NOT make decisions about you that produce legal or similarly significant effects by solely automated means.
6. WHO WE SHARE DATA WITH (SERVICE PROVIDERS)
6.1. We share data only with service providers who process it on our instructions, under contract, to run the Services: cloud hosting and infrastructure; cloud file storage and content delivery (for example Cloudflare); transactional email delivery (for example Brevo) for support replies and acknowledgements; payment gateways (for example Razorpay) when you choose to contribute; and operational monitoring tooling. Each provider receives only the data it needs for its function.
6.2. We may also disclose data where required by law, regulation or valid legal process; to protect the rights, safety or property of ToolField, our users or the public; to investigate fraud, abuse or security incidents; or in connection with a merger, acquisition or sale of assets (in which case your data remains protected by this policy or one no less protective).
7. INTERNATIONAL TRANSFERS
7.1. Our infrastructure and providers may store or process data in countries other than yours (including in the European Union, the United States and India). Where data protected by the GDPR or similar laws is transferred internationally, we rely on appropriate safeguards such as adequacy decisions or standard contractual clauses, and we require equivalent protection from our processors.
8. HOW LONG WE KEEP DATA
8.1. Retention periods:
- Server-tool files (inputs and outputs): approximately 2 hours, then deleted automatically.
- Support attachments: approximately 7 days.
- Support tickets and correspondence: as long as needed to resolve the matter and for a reasonable period after.
- Session and security logs (IP, user agent): short, rolling retention for security and reliability.
- Account data: for as long as your account exists; deleted or anonymised after closure, subject to legal retention duties.
- Payment and contribution records: as required by tax, accounting and anti-fraud laws.
- Aggregate, PII-free usage statistics (for example how many times a tool ran): retained indefinitely - they identify no one.
9. SECURITY
9.1. We use industry-standard measures appropriate to the risk: TLS encryption in transit, encrypted token storage, hashed passwords, least-privilege access, short-lived signed URLs, rate limiting, input validation and audit logging. No system is 100% secure, so we cannot guarantee absolute security; please keep copies of your important files. If we learn of a breach affecting your personal data, we will notify you and/or the relevant authority where the law requires.
10. YOUR RIGHTS
10.1. Everyone. Wherever you live, you can contact [email protected] to access, correct or delete personal data we hold about you, to object to or restrict our processing, or to ask questions about this policy. We respond as required by the laws that apply to you.
10.2. EU/EEA and United Kingdom (GDPR / UK GDPR). You have the rights of access, rectification, erasure, restriction of processing, data portability and objection, and the right to withdraw consent at any time (without affecting processing already carried out). You also have the right to lodge a complaint with your local supervisory authority.
10.3. California (CCPA/CPRA). You have the right to know, correct and delete personal information; the right to opt out of "sale" or "sharing" of personal information (we do not sell or share personal information as those terms are defined by the CCPA); the right to limit the use of sensitive personal information (we do not use it beyond what the law permits for providing the Services); and the right not to be discriminated against for exercising your rights. We honour Global Privacy Control (GPC) signals. An authorised agent may submit requests on your behalf.
10.4. India (Digital Personal Data Protection Act, 2023). You have the right to access a summary of your personal data and the processing activities applied to it, the right to correction and erasure, the right to grievance redressal, and the right to nominate another person to exercise your rights on your behalf. Requests and grievances: [email protected]. If your grievance is not resolved, you may approach the Data Protection Board of India.
10.5. Other jurisdictions (for example the LGPD of Brazil, PIPEDA of Canada, the Privacy Act of Australia and other US state privacy laws). You may have similar rights of access, correction, deletion and objection; we will honour valid requests in accordance with the law that applies to you.
10.6. Verification. We may need to verify your identity before acting on a request, and we may decline requests that are unlawful, technically impossible (for example, files that have already been auto-deleted) or manifestly unfounded - and will explain why.
11. CHILDREN
11.1. The Services are not directed at children under 13 and we do not knowingly collect personal data from them. Users under 18 (or the applicable age of digital consent in your jurisdiction) should use the Services only with parental or guardian consent. If you believe a child has provided us personal data, contact us and we will delete it.
12. DO NOT TRACK AND GLOBAL PRIVACY CONTROL
12.1. We honour Global Privacy Control (GPC) signals where legally required. Because we do not sell personal data and do not engage in cross-site tracking, browser "Do Not Track" signals do not change how the Services behave.
13. CHANGES TO THIS POLICY
13.1. We may update this policy from time to time. The "Last updated" date shows the current version, and material changes will be announced on the Services. Continued use after a change takes effect means the updated policy applies.
14. CONTACT
14.1. Privacy questions, requests and complaints: [email protected], or use the contact form on the Services. We aim to respond as soon as possible.