Don’t trust us. Check.
Every tool site says your data stays local, and you are usually asked to take that on faith. Here the guarantee is a response header your browser enforces, so you can read it yourself and take our word for nothing.
Check it in ten seconds
- 01 Open any tool page, then open DevTools.
- 02 Go to the Network tab and use the tool. Paste a token, drop a HAR, run a diff.
- 03 Nothing appears. The page fetched its own files — HTML, CSS, fonts we serve ourselves — before you started; using the tool adds no request of any kind.
- 04 Select the page's own request and read its Content-Security-Policy response header. That is the whole proof.
The header we ship
Content-Security-Policy: default-src 'self'; script-src 'self' 'wasm-unsafe-eval' <inline hashes>; style-src 'self' 'unsafe-inline'; img-src 'self' data: blob:; font-src 'self'; connect-src 'none'; worker-src 'self' blob:; object-src 'none'; frame-ancestors 'none'; base-uri 'self'; form-action 'none'
connect-src 'none' blocks fetch, XHR, WebSocket, EventSource and
sendBeacon. form-action 'none' blocks form submission.
Together they mean a compromised dependency inside our own bundle still could not send
your paste anywhere: the browser refuses before our code gets a say.
Where the exceptions are, and why
A page running anything other than the strict policy says so in its own badge, generated from the same registry field that generates its header. There is no page here that quietly runs something weaker than what it displays.
- strict — connect-src 'none'
- Your browser blocks every request this page could make. Nothing you paste can leave your machine, even if our own code tried to send it. This is every tool here — all 17 of them.
- self-fetch — connect-src 'self'
- A tool needing a WebAssembly binary has to fetch it. The browser permits requests to tabonly.com and nowhere else. tabonly.com serves static files: there is no endpoint that accepts a request body, and form-action 'none' still holds. No route runs this today.
- ads — csp: ads
- A commodity converter page carrying one ad unit talks to the ad network, and its badge says so. Never a flagship tool, never /verify. No route runs this today.
What we collect
Nothing, in your browser. There is no analytics script on this site, because a script that reported anything would have to make a request, and it cannot. Traffic is counted at the CDN from the request itself — the same server log any website has — and it never sees what you pasted, because what you pasted was never sent.