Privacy Policy
Your privacy is our priority. This document explains the zero-knowledge guarantees powering Karvics and the limited scenarios where data briefly touches our infrastructure.
Karvics ("we", "our", "us") operates as a Client-Side First toolkit. Most utilities run entirely in your browser memory, so we never possess the files or secrets you process.
This Privacy Policy explains that architecture, what limited data our premium audits require, and how you remain the data controller for everything you run through Karvics.
By using our Services, you confirm that you understand the difference between client-side and server-side workflows and accept responsibility for the data you submit.
01. The Karvics Data Model
PDF tools, image utilities, cryptography, password generators, TOON converters, secure notepad
These tools execute entirely in your browser via JavaScript and WebAssembly. Everything stays in local memory (RAM), so we never see or receive your data.
- •Data egress: zero. Files, secrets, and passphrases never touch Karvics servers.
- •Works offline. Load the tool, disconnect from the internet, and it still functions.
- •Performance and file size are limited only by your device resources.
SSL Checker, Website Security Audit, Complete Web Auditor
Diagnostics that need to crawl remote sites must relay the target URL to our managed infrastructure to bypass CORS and run security scans.
- •URLs are processed immediately, not indexed, and reports are streamed back to your browser.
- •Generated PDFs are not archived server-side; export them if you need a copy.
- •Access requires Google or GitHub OAuth—no Karvics passwords exist.
02. Information We Collect (and Don’t)
What we do not collect
- ✕Files processed through client-side tools (PDFs, images, JSON, TOON payloads).
- ✕Passwords created with the Random Password Generator or keys generated via Web Crypto.
- ✕Prompts, tokens, or API keys used in the Token Cost Estimator.
What we do collect
- •OAuth profile basics (name, email, avatar) when you sign in for premium features.
- •Session telemetry to keep you logged in while using premium workflows.
- •Privacy-friendly analytics that aggregate tool popularity without linking to file contents.
We never collect your OAuth passwords; authentication happens directly with Google or GitHub.
03. Local Storage & Cookies
LocalStorage / IndexedDB
Utilities like the secure notepad save drafts in your browser so accidental tab closes do not wipe work. Clear your cache to remove it.
Session Cookies
Used only to maintain your premium login session. No tracking or ad tech cookies.
We do not deploy tracking pixels, retargeting cookies, or ad tech.
04. AI & LLM Data Usage
- •Token counting and TOON conversions run locally. We do not send your prompts to OpenAI, Anthropic, or other LLM vendors for estimation.
- •Inputs are never stored or reused to train any AI models.
- •Outputs remain in-memory until you export or copy them.
05. Third-Party Services
We rely on a minimal set of partners to operate the platform:
- •Vercel for front-end hosting.
- •Netlify edge/CDN utilities where applicable.
- •Google OAuth and GitHub OAuth strictly for authentication.
- •Privacy-focused analytics with anonymized IP addresses.
06. Your Rights (GDPR / CCPA)
- •Zero-Knowledge tools: you control the data entirely. Clearing your browser cache deletes everything.
- •Premium accounts: email us to export or delete the profile data tied to your OAuth identity.
- •You may revoke Google or GitHub access at any time from their dashboards.
Need help exercising a right? Reach out via the contact options below.
07. Security Measures
08. Changes to This Policy
If we modify this Privacy Policy, we will update the “Last updated” date and describe the change in this section. Continuing to use Karvics after an update means you accept the revised terms.
09. Contact Us
Questions about this Privacy Policy can be sent via our contact page. For bug reports or feature ideas, use the public GitHub tracker.
Please include timestamps, tool names, and whether the workflow was client-side or premium so we can assist quickly.
Need Clarification?
We respond to privacy inquiries in under 24 hours. Reference this policy and share any diagnostic logs if you suspect an issue.
Contact Support