Data Protection & Confidentiality

Privacy Policy

Last updated: January 2026 · Effective Date: January 1, 2026

Our Foundational Promise: Zero Server Transmission

When you paste, format, or validate JSON payloads on Format & Validate Json, your data never leaves your device. All parsing, error calculation, syntax colorization, and minification execute entirely inside your local browser memory.

1. Information We Do Not Collect

Unlike conventional developer utilities that submit inputs over HTTP POST requests to remote backend servers, Format & Validate Json has no backend processing pipeline. Specifically:

  • No JSON Payloads or Code: We do not log, inspect, store, or transmit any string, object, or document you input into the editor.
  • No API Credentials or Tokens: If your JSON includes confidential keys, tokens, passwords, or customer records, they remain strictly inside your browser sandbox.
  • No Personal Identifiable Information (PII): We do not ask for accounts, names, telephone numbers, or credit cards.
  • No Tracking Cookies: We do not utilize advertising cookies or cross-site tracking pixels.

2. Information Stored Locally in Your Browser

To ensure an optimal user experience across browsing sessions, this website uses browser localStorage for a single purpose:

Theme Preference
A single key (theme) storing either "dark" or "light" to preserve your interface appearance without screen flicker.

You can clear this anytime through your browser's clear site data settings.

3. Third-Party CDNs and Assets

This website is statically delivered via modern edge content delivery networks (CDNs). When loading static pages, your browser sends standard HTTP headers (such as IP address and user-agent string) to retrieve website assets:

  • Google Fonts: Typographic styles (Geist and Geist Mono) are loaded via Google Fonts CDN to deliver readable developer typography.
  • Static Assets: JavaScript bundles, stylesheets, and icons are served over HTTPS with strict security headers.

4. Regulatory Compliance (GDPR & CCPA)

Because we do not collect, transmit, profile, or sell personal data:

  • GDPR (General Data Protection Regulation): We do not act as a data controller or processor for your JSON payloads. Your data never crosses borders because it never leaves your machine.
  • CCPA / CPRA (California Consumer Privacy Act): We do not sell or share personal information under any circumstance.

5. Updates to This Policy

We may update this Privacy Policy periodically to reflect enhancements or legal standards. Any revisions will be published directly on this page with an updated Effective Date.

6. Contact Us Regarding Privacy

If you have questions about our privacy architecture or client-side execution model, please reach out via our Contact Page.