Privacy Policy
We built VeloTools on one principle: your data is yours. Everything stays on your device. Always.
The Simple Version
This Privacy Policy explains what limited information we do collect (basic anonymous analytics) and how we handle it in full compliance with the EU General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and Google's Publisher Policies.
What Data We Collect
We collect no personally identifiable information (PII). We never ask for your name, email address, phone number, or any other identifying information. VeloTools does not require account creation.
The only data we receive is what your browser sends to any web server when you visit a website:
- IP address — processed by our hosting provider (Cloudflare) to route traffic. We do not store or log individual IP addresses.
- Browser type and version — used in aggregate to improve compatibility.
- Referring URL — the page you came from, used in aggregate analytics.
- Pages visited and time on page — aggregated, never tied to an individual.
- Country/region — derived from IP at a country level only, used in aggregate.
How File Processing Works
All file processing on VeloTools is performed entirely within your browser using the following web technologies:
- Canvas API — for image compression, format conversion, resizing, and effects.
- JavaScript / WebAssembly — for background removal (AI model runs locally), PDF compression, and raw image decoding.
- Web Crypto API & localStorage — for saving invoice data locally in your browser.
- Blob API — for generating downloadable output files without server involvement.
When you upload a file, it is read into browser memory using the FileReader API. The file data exists only in your browser's RAM for the duration of the session. It is never transmitted over the network.
Analytics
We use anonymous, aggregated analytics to understand how our tools are used and to improve the service. This may be provided by a privacy-focused analytics provider (such as Cloudflare Web Analytics or Plausible).
Our analytics approach:
- No persistent identifiers or cross-site tracking cookies.
- Data is aggregated — we see totals, not individual user journeys.
- No fingerprinting of browsers or devices.
- Page views and tool usage counts help us decide which tools to improve.
Advertising
VeloTools may display advertisements through Google AdSense to support our free service. By displaying ads, Google may use cookies and web beacons to serve ads based on your prior visits to our website or other websites on the internet.
Google's advertising practices:
- Google uses the DoubleClick cookie to serve ads based on browsing history.
- Ad personalization uses data collected across websites using Google services.
- You can opt out of personalized advertising at google.com/settings/ads.
- You can opt out via the Network Advertising Initiative at networkadvertising.org.
We comply with Google's EU User Consent Policy and obtain appropriate consent from users in the EEA and UK before serving personalized ads. We do not pass any personally identifiable information to Google AdSense.
Third-Party Services
VeloTools uses a small number of third-party services to deliver the application. These services may collect limited technical data as part of their operation:
We load the "DM Sans" typeface from Google Fonts. This causes your browser to make a request to Google's servers. Google may log this request per their Privacy Policy. No font data is transmitted — only the font file is downloaded.
Our site is served via Cloudflare's CDN. Cloudflare may process IP addresses and request metadata to provide DDoS protection and performance optimization, per their Privacy Policy.
The QR Code Generator tool loads the qr-code-styling library from a CDN (esm.sh). This request may be logged by the CDN provider.
Cookies & Local Storage
VeloTools uses localStorage (a browser-side storage mechanism, not a network cookie) to save your settings and in-progress work locally on your device. This data:
- Never leaves your device and is never transmitted to our servers.
- Includes saved invoice data, tool preferences, and Focus Room tasks.
- Can be cleared at any time via your browser settings (Clear Site Data).
Google AdSense cookies — if ads are displayed, Google may set cookies in your browser to serve personalized advertising. These are third-party cookies governed by Google's Privacy Policy. You can manage cookie preferences in your browser settings or via Google's ad settings.
We do not use any first-party tracking cookies, session cookies, or persistent identification cookies of our own.
Your Rights (GDPR / CCPA)
Because we collect no personally identifiable information, most data subject rights have no practical application to VeloTools — there is simply no personal data for us to provide, correct, or delete. However, we fully recognize your rights:
- Right to Access — You may request confirmation of whether we hold any personal data about you.
- Right to Erasure — You may clear all locally stored data by clearing your browser's site data for velotools.app.
- Right to Object — You may opt out of any analytics or advertising via your browser settings or the opt-out links provided above.
- Right to Portability — Any data stored in your browser (e.g., saved invoices) is already in your possession.
- CCPA Rights — California residents have the right to know, delete, and opt out of the "sale" of personal information. We do not sell personal data.
To exercise any of these rights, contact us at privacy@velotools.app.
Children's Privacy
VeloTools does not knowingly collect any personal information from children under the age of 13 (or 16 in the EU). Our service is a general-purpose productivity toolkit with no age-gated content. Since we collect no personal data from any user, COPPA compliance is inherent in our design.
If you are a parent or guardian and believe your child has provided us with personal information, please contact us at privacy@velotools.app and we will take immediate steps to address your concern.
Security
Our strongest security measure is architectural: your files never travel over the network. There is no server-side component that handles your files, so there is no server-side breach risk for your content.
- All traffic to velotools.app is encrypted with TLS 1.3.
- Our site is served from Cloudflare's global CDN with enterprise-grade DDoS protection.
- Content Security Policy (CSP) headers restrict JavaScript execution to known sources.
- No passwords or sensitive credentials are ever stored on our servers.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. When we make significant changes, we will update the "Last updated" date at the top of this page. We encourage you to review this policy periodically.
Continued use of VeloTools after any changes to this Privacy Policy constitutes your acceptance of the updated policy. If you disagree with any changes, please stop using the service.
Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please reach out:
For legal requests (GDPR data subject requests, CCPA requests, law enforcement inquiries), please use the same address with a clear subject line.