Privacy Policy

Last updated: July 12, 2026

Privacy Policy

Last updated: July 12, 2026 Version: 2026-07-12 Data controller: Devglaze LLC

This Privacy Policy explains what Devglaze LLC ("we", "us", "our") collects when you use ToolsPow, why we collect it, how long we keep it, and the rights you have over it. It is written to satisfy the EU General Data Protection Regulation (GDPR, Regulation 2016/679), the UK GDPR, the California Consumer Privacy Act (CCPA) as amended by the CPRA, and equivalent laws in other regions.


1. Data we collect

1.1 When you visit anonymously (no signup)

1.2 When you sign up

1.3 When you use tools while signed in

1.4 When you pay

1.5 When you use the API or MCP

1.6 When something breaks


2. Why we collect each item — legal bases

Data Purpose Legal basis (GDPR Article 6)
Email + password Account access 6(1)(b) contract
IP + user-agent Abuse prevention, rate limits 6(1)(f) legitimate interest
Uploaded files Run your conversion 6(1)(b) contract
Usage counters Enforce per-tier quotas 6(1)(b) contract
Stripe customer ID Bill subscriptions, ledger token purchases 6(1)(b) contract
Essential cookies Session, CSRF, consent choice 6(1)(f) legitimate interest + ePrivacy strictly-necessary exemption
Preferences cookies Save theme, favorite tools 6(1)(a) consent
Analytics cookies (if enabled) Improve the product 6(1)(a) consent
Marketing cookies (if enabled) Ads and cross-site targeting 6(1)(a) consent
Error logs Fix bugs, security incidents 6(1)(f) legitimate interest
Consent audit trail Demonstrate compliance 6(1)(c) legal obligation (Article 5(2))

3. Data retention

Data category How long we keep it
Uploaded files (anonymous) Deleted 1 hour after conversion, always.
Uploaded files (signed-in, retained) Until you delete them from /user/files, or 30 days after account deletion.
Uploaded videos Never retained. Deleted 1 hour after conversion regardless of account.
Account data (name, email, password hash) For as long as your account is active; deleted 30 days after account deletion request (grace period for recovery).
Payment records (Stripe IDs, ledger entries) 7 years (accounting law retention).
Tool job records (slug, timing, status) 90 days rolling window; older records aggregated to per-day counters.
Cookie consent choice + audit event 5 years (Article 5(2) accountability).
IP addresses in web-server logs 90 days rolling.
Error logs 180 days, then auto-purged.

4. Cookies + localStorage inventory

4.1 Cookies

Name Category Purpose Duration Provider
toolspow_session Essential Session identifier for signed-in users 2 hours rolling First-party
XSRF-TOKEN Essential CSRF protection for form submissions 2 hours rolling First-party
tp_uid Essential Anonymous visitor ID for rate-limiting + abuse detection 400 days First-party
(No third-party analytics or marketing cookies are set today.)

4.2 Browser localStorage

Key Category Purpose Duration
cookie_consent_v2 Essential Your granular consent choice + policy version — stops the banner reappearing Until you clear browser storage or reset via footer link
favorite-tools Preferences (opt-in) Your starred tools list Until you clear browser storage
theme Preferences (opt-in) Light/dark theme choice Until you clear browser storage

4.3 Withdrawal of consent

Click Cookie preferences in the footer of any page. The preferences modal reopens; toggle categories off and click Save — that is exactly as easy as giving consent, satisfying GDPR Article 7(3).

If we materially change our cookie use, we bump the policy version, and every user is re-prompted on their next visit.


5. Third-party data processors

We share only the minimum data necessary with these processors. All are bound by data-processing agreements or equivalent contractual protections.

Processor Purpose Data shared
Stripe Payments Card data (goes directly to Stripe, never through us), email
Google Sign-In + Drive picker (both opt-in per use) Google account ID, email, name
Dropbox Dropbox Chooser (opt-in per use) OAuth session, file ID
Microsoft OneDrive picker (opt-in per use) OAuth session, file ID
Cloudflare Turnstile Bot protection on signup/login/contact forms Anonymous fingerprint tokens
cPanel ClamAV Malware scanning of uploaded files (local, our server) File content (streamed to local scanner, not third party)
rdap.org WHOIS Domain Lookup routing Domain name you look up
ipwho.is What Is My IP geolocation IP address you look up (may be yours)
Sentry (if DSN configured) Error monitoring Stack traces, requesting URL, hashed user ID
Our SMTP mail provider Sending account, verification, and reply emails Email address, message body

6. Your rights under GDPR

You have the following rights concerning your personal data. To exercise any of them, email info@toolspow.com with subject line "DPR: [right]" — for example "DPR: Access". We respond within 30 days.

Phase 3 of our GDPR-compliance rollout adds self-service buttons in your account dashboard for Export my data and Delete my account — so you don't need to email us for the common cases.


7. Consent management


8. International transfers

Our primary server is in the European Union. Data may be transferred to our processors (Stripe, Google, Microsoft, etc.) whose infrastructure spans multiple regions. Where transfers happen outside the EEA, our processors use Standard Contractual Clauses or equivalent safeguards approved by the European Commission.


9. Security

No system is perfectly secure. If we suffer a breach affecting your personal data we will notify you and applicable supervisory authorities within 72 hours as required by GDPR Article 33.


10. Children

The Service is not directed at children under 16 in the EU (or the equivalent age of consent in your jurisdiction; 13 in the US under COPPA). If you believe a child has provided us with personal data, please email info@toolspow.com and we will delete it.


11. Automated decision-making and profiling

We do not use fully automated decision-making or profiling that produces legal or similarly significant effects for you. Tool jobs are run as-requested and returned as-is; we do not score users or make decisions about them based on behavior patterns.


12. Changes to this policy

Material changes to this Policy will be announced here and (for paying customers) by email at least 14 days before they take effect. Non-material changes (fixed typos, clarified wording) will not trigger a version bump.


13. Contact


This Privacy Policy is written to cover the data flows we actually run. Version 2026-07-12.