Trust
Security, privacy and compliance
What runs where, what we hold, who else touches it, and how to exercise your rights. Written to be checked, not to reassure.
Two kinds of tool
On your device. 1,267 tools that run entirely in your browser: PDF, image, QR, text, calculators, converters, the Tally converter. Nothing you put into them is transmitted, stored or seen by us. No account is needed and none is created. They work with the network off.
In the cloud. The AI tools, which need a language model on a server. Each page states above the button exactly what it will send; files are read on your device so that only their text goes; personal identifiers are masked on the device before sending and restored in the answer; and neither what you send nor what comes back is stored by us. An account is needed only for these and for settings you want on more than one device.
What we hold, if you have an account
| Email address | to sign you in and to reach you about your account |
|---|---|
| Plan, status, period dates | so the tools know what you are entitled to |
| Payment references | a subscription id and, for Stripe, a customer id — never card or bank details, which we never receive |
| AI usage count, per month | to enforce the monthly allowance; pruned after 13 months |
| Saved tool settings | only if you choose to save them, e.g. a Tally column mapping |
| Credits in hand | the balance of any credits bought outright, and one row per payment so the same money cannot be credited twice |
| Webhook records from payment providers | for reconciliation and disputes; pruned after 13 months |
| AI inputs and outputs | not stored. We count that a call happened; the text is not kept |
All of it is downloadable from your account page as one file, and deletable there in one step.
Who else touches your data
| Processor | What for | Where |
|---|---|---|
| Google Cloud (Firebase) | Sign-in, the account database, the functions that run the gateway and the payment webhooks | Mumbai (asia-south1) for data and functions; Firebase Authentication is a global Google service |
| Anthropic | The language model behind the AI tools, via our own server; receives the (masked) text you send | United States. API data is not used to train models under Anthropic’s terms and is retained by them only briefly for abuse prevention |
| Razorpay | Payments in India; you pay on their page | India |
| Stripe | Payments in the UK and elsewhere; you pay on their page; billing portal | Stripe Payments UK Ltd, with processing in the EU and US under their safeguards |
| GitHub Pages | Serves the site’s static pages | Global CDN |
| Google Analytics, Microsoft Clarity | Page-view statistics, only if you allow them in the cookie prompt; never anything you type into a tool | Global |
A data processing agreement covering these sub-processors is available on request from the contact page.
How it is protected
- Everything travels over TLS. The site is static; there is no server that can be logged into, and no place a tool’s input could be written to.
- The database rules allow a browser to read its own record and write its own saved settings, and nothing else. Plans are written only by our functions after a payment provider has spoken through a signed webhook — every webhook signature is verified, and a replayed event is ignored.
- API keys for the model and the payment providers live in Google Secret Manager and are read by the functions at run time; no key is ever sent to a browser.
- The AI tools mask personal identifiers on your device before sending, show you what was masked, and restore it in the answer. The model sees structure, not people.
- Card and bank details are entered on Razorpay’s or Stripe’s pages and never pass through us.
- If a breach ever affected personal data we hold, we would tell affected people and the ICO within 72 hours of knowing.
Your rights, and how to use them
1234Tools is operated by MVR IT Services LTD, a company registered in England and Wales (no. 10251131), which is the data controller. UK GDPR and the EU GDPR apply to people in the UK and EU; India’s Digital Personal Data Protection Act 2023 applies to people in India. Under all three you can:
- Access and take away what we hold — the Download my data button on your account page gives you all of it, as JSON, immediately.
- Erase it — Delete my account does so immediately and irreversibly, cancelling any subscription first.
- Correct it — your email is set by your sign-in provider; anything else, write to us.
- Object or withdraw consent — analytics can be refused or withdrawn in the cookie prompt at any time; the AI tools send nothing unless you press the button.
- Complain — to us first, via the contact page, and to the Information Commissioner’s Office in the UK, your local supervisory authority in the EU, or the Data Protection Board of India.
Requests that need a person are answered within 30 days, usually much sooner.
Retention, in one place
- Account record and saved settings: until you delete the account.
- AI usage counts: 13 months.
- Payment webhook records: 13 months.
- AI inputs and outputs: not retained.
- Server logs: Google Cloud’s default of 30 days; they record that a function ran, not what was sent to it.