1. Introduction & Scope
Welcome to PixiTools ("we", "us", "our", or "Platform"), accessible at pixitools.com. This Privacy Policy describes how we collect, handle, protect, and dispose of information when you interact with our suite of developer utilities, document scrubbers, converters, account services, and APIs.
By visiting PixiTools, creating an account, or utilizing any of our tools, you acknowledge the terms established in this Privacy Policy. If you do not agree with our operational guidelines, please discontinue use of our platform immediately.
We design our software around the principle of Zero-Knowledge Architecture. If a feature can be calculated or rendered in your local web browser, we refuse to transmit it over the network to our servers.
2. Core Architecture: Client-Side vs Server-Side
Unlike conventional web conversion services that funnel your confidential documents, family photographs, and source code through remote cloud server clusters, PixiTools implements a strict bifurcated model:
| Processing Category | Representative Tools | Network Transmission | Privacy Status |
|---|---|---|---|
| 100% Client-Side In-Browser Tools | AI Image Metadata Remover, PDF Password Remover, Code Formatters, Hash Generators, Media Optimizers | Zero Server Upload. Files remain 100% in local browser RAM using HTML5 File API and WebAssembly. | ✓ 100% Client-Side Private |
| Server-Assisted Cryptographic Tools | e-Aadhaar Digital Signature Verifier & Authenticator | Encrypted HTTPS Stream. Transmitted strictly to verify UIDAI root cryptographic x509 certs. | ⏱ Ephemeral (15-Min Auto-Purge) |
When you use in-browser tools on PixiTools, the processing takes place entirely within your machine's CPU/GPU and web browser sandbox. If you disconnect your internet connection after the tool page loads, the tool continues to operate completely offline.
3. Information We Collect
We categorize information into distinct tiers based on your level of interaction with the platform:
A. Information You Never Provide for Browser Tools
- File Contents: For client-side tools, your images, PDF documents, text snippets, and raw files are processed locally. Our servers never receive, inspect, or store them.
B. Information Provided When Creating an Account
Account creation is entirely optional. When you choose to register for a PixiTools account (or upgrade to PixiTools Pro), we collect:
- Profile Data: Your name and email address.
- Authentication Credentials: A securely salted and hashed representation of your password using
bcryptwith a cost factor of 12. We never store or possess plaintext passwords. - Google OAuth Data (Optional): If you choose "Continue with Google", we receive your public Google profile name, email address, and avatar URL via official OAuth 2.0 scopes. We never receive or request access to your Google password, contacts, or Google Drive files.
C. Automated Technical Telemetry & Logs
When accessing our web servers, standard non-identifying operational telemetry is logged for server reliability, DDoS mitigation, and spam prevention:
- Server Access Logs: IP address (masked and rotated), browser type, operating system, referrer URL, pages visited, and timestamps.
- Aggregated Tool Usage Metrics: Anonymous view counts and total lifetime tool executions (e.g. "Tool X used 1,420 times") to guide engineering improvements.
- Spam & Abuse Prevention (reCAPTCHA v3): We employ Google reCAPTCHA v3 on authentication forms. Google analyzes hardware and interaction signals to produce an automated bot risk score.
4. How We Use Information
Any information collected by PixiTools is utilized strictly for transparent and legitimate operational objectives:
- Delivering Core Utilities: Executing user-requested operations, providing authenticated dashboard access, and managing bookmarks and favorites.
- Enforcing Plan Quotas: Ensuring registered accounts and Pro subscribers receive their entitled unlimited daily bandwidth, fast queue privileges, and ad-free interfaces.
- Critical Service Communications: Delivering essential transactional emails, such as password reset instructions, security notifications, or customer support responses.
- Platform Security: Detecting, thwarting, and responding to brute-force attacks, DDoS attempts, vulnerability exploitation, and illegal bot activity.
We do not sell, rent, broker, or trade your personal data. We do not build commercial profiling dossiers, and we do not participate in cross-context behavioral ad networks that sell private identity data.
5. Server Tools & 15-Minute Auto-Purge Protocol
Certain specialized compliance utilities—specifically our e-Aadhaar Digital Signature Verifier—require server-side execution because browser sandboxes cannot securely evaluate full Indian Government CCA and UIDAI Root Certificate Authorities or parse complex PKCS#7 signed cryptographic byte streams directly.
For these tools, we maintain an uncompromising data hygiene protocol:
- Encrypted Transport: The PDF file is transmitted directly over TLS 1.3 / HTTPS encryption to the verification processor.
- Ephemeral In-Memory Verification: The signature certificate is extracted, validated against root certificate stores, and verification metadata is compiled in temporary RAM.
- 15-Minute Auto-Purge Window: The generated verified copy (with the certified green tick signature mark applied) is assigned a cryptographically random, single-use UUID download token valid for exactly 15 minutes.
- Irreversible Deletion: After 15 minutes (or immediately after user download), the file is permanently unlinked and shredded from storage. No permanent copies, backups, or shadow copies of your Aadhaar documents are retained.
Pro-Privacy Recommendation: We actively encourage users to utilize Masked Aadhaar (where the first 8 digits of the 12-digit number are concealed) whenever verifying signatures, as both regular and masked documents carry identical, legally binding digital signatures.
6. Cookies & Local Browser Storage
PixiTools uses minimal, modern storage mechanisms designed for utility rather than intrusive user tracking:
- Strictly Necessary Session Cookies: Standard HTTP-only, secure cookies (e.g.
pixitools_sessionandXSRF-TOKEN) to preserve your logged-in session state and defend against Cross-Site Request Forgery (CSRF). - Browser LocalStorage: Used locally on your device to store user preferences, such as your saved tool bookmarks (
pixitools_favorites) and UI states. This data never leaves your device. - Security Cookies: Google reCAPTCHA utilizes non-identifying technical cookies to assess bot behavior and block malicious scrapers.
You can disable or purge cookies through your browser settings at any time; however, logging into a personal account requires functional session cookies.
7. Google AdSense & Advertising Policy
To maintain our extensive suite of free tools for public use without requiring mandatory subscriptions, we display contextual advertisements provided by Google AdSense.
- Google and its certified third-party vendors use cookies (including the DoubleClick / DART cookie) to serve ads based on your prior visits to our website or other websites across the internet.
- Google's use of advertising cookies enables it and its partners to serve targeted ads based on your browsing patterns.
- Opt-Out Options: You may opt out of personalized advertising by visiting Google Ads Settings or through the Network Advertising Initiative at aboutads.info.
- Ad-Free Guarantee for Pro Users: PixiTools Pro subscribers enjoy a 100% ad-free experience. When logged into a Pro account, all AdSense scripts, ad slots, and associated tracking codes are completely stripped from the page DOM.
8. Sub-Processors & Third-Party Partners
We collaborate solely with reputable, enterprise-grade infrastructure providers who adhere to strict data privacy covenants:
- Cloud Hosting & Server Infrastructure: Hostinger International Ltd. (High-security cloud VPS infrastructure with hardware firewalls and encrypted drives).
- Google Cloud Platform & APIs: Google LLC (reCAPTCHA v3 bot mitigation and Google OAuth 2.0 authentication services).
- Advertising Partner: Google AdSense (Display advertising for free-tier users).
- Transactional Email Services: Enterprise SMTP relays (Postmark / Resend / AWS SES) for delivering requested password recovery and system alerts.
9. Data Retention & Instant Account Erasure
We retain your data only for as long as necessary to provide our services to you:
- Temporary Verification Files: Strictly purged within 15 minutes of generation.
- Server Logs: Retained for a rolling period of 30 days for security audits, after which logs are automatically overwritten or permanently rotated.
- Account Profiles: Maintained while your account remains active.
We respect your right to be forgotten. You do not need to submit formal tickets or wait days for review. Log in to your Account Dashboard, scroll to the "Delete Account" card, and confirm deletion. Your account, credentials, and profile records will be permanently erased from our live databases instantly.
10. Global Privacy Rights & Regulatory Compliance
Depending on your geographical jurisdiction, you are entitled to statutory rights under comprehensive data protection legislation, including the European General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA/CPRA), and the Digital Personal Data Protection Act, 2023 (India DPDP):
- Right to Access: You have the right to request a confirmation of whether we process personal data relating to you, and to obtain a copy of that data.
- Right to Rectification: You may update or correct inaccurate personal details at any time directly through your dashboard.
- Right to Erasure ("Right to be Forgotten"): You may request the permanent deletion of your personal records.
- Right to Data Portability: You may request an export of your account data in a structured, commonly used machine-readable format.
- Right to Non-Discrimination: We will never deny services, charge different prices, or provide a lower quality of service because you exercised any statutory privacy right.
- Right to Withdraw Consent: Where processing is based on consent, you may withdraw it at any time.
To exercise any of these rights, email our Data Protection team at [email protected]. We respond to all verified regulatory requests within 30 days.
11. Security Architecture & Encryption
We apply defense-in-depth security controls to safeguard data integrity and thwart unauthorized access:
- End-to-End TLS 1.3 Encryption: All traffic between your browser and PixiTools is encrypted using industry-standard Transport Layer Security (TLS 1.3) with automated HSTS preloading.
- Hardened Cloud Infrastructure: Our production servers run on locked-down Linux kernels with strict firewall ingress rules, non-root application execution, and automated security patch management.
- Cryptographic Password Hashing: Passwords are protected with salted
bcrypthashing, impervious to rainbow table attacks. - CSRF & Injection Defenses: All form endpoints are protected against Cross-Site Request Forgery, SQL injection, and XSS vulnerabilities through Laravel's built-in security middleware.
12. Children's Online Privacy Protection
PixiTools is designed for general audiences, professionals, developers, and students. We do not knowingly solicit, collect, or maintain personal information from children under the age of 13 (or under 16 in certain European jurisdictions).
If you believe that a child has provided us with personal information without parental consent, please contact us immediately at [email protected] so we can expeditiously purge such records from our systems.
13. Policy Amendments & Notifications
As we develop new utilities or comply with evolving legal mandates, we may periodically revise this Privacy Policy. When changes occur, we update the "Last Updated" timestamp at the top of this document.
For material modifications that significantly alter how we process personal information, we will provide prominent notice—such as an announcement on our homepage or an email alert to registered account holders—prior to the change becoming effective.
14. Contact Us & Grievance Redressal
If you have questions, feedback, or concerns regarding our privacy architecture, this policy, or your personal data rights, please contact our dedicated Data Privacy & Support Officer:
Data Privacy & Compliance Team
We review all incoming privacy inquiries directly. Most requests are answered within 24 to 48 business hours.