Privacy Policy
How Hostt protects your privacy and keeps your data secure
π Your Privacy is Protected
Most text, code, and image tools process their input in your browser. Network, lookup, audit, monitoring, and alert tools send the data needed for the requested operation to Hostt's server-side endpoints or named providers. Tool inputs, uploaded filenames, target URLs, and account identifiers are excluded from analytics.
π οΈ How Our 53 Tools Work
Client-Side Processing (45 Tools)
π Image Magnifier
- β’ Process images entirely in your browser using HTML5 Canvas
- β’ Create magnifying glass effects without uploading files
- β’ Export processed images directly to your device
π Diff Checker
- β’ Compare text files using client-side JavaScript algorithms
- β’ File contents never leave your browser
- β’ Real-time highlighting and difference detection
π Text to Markdown
- β’ Convert rich text and HTML using the Turndown library
- β’ Paste from Word, web pages, or enter HTML directly
- β’ All conversion happens in your browser
π Word Counter
- β’ Real-time text analysis with JavaScript
- β’ Count characters, words, sentences, and paragraphs
- β’ Calculate reading time estimates locally
π·οΈ HTML Tag Checker
- β’ Validate HTML using client-side parsing
- β’ Detect unclosed, mismatched, or invalid tags
- β’ HTML5 compliant validation with line number reporting
π¨ Favicon Generator
- β’ Generate multi-size favicon packages with adjustable cropping
- β’ Process images entirely in your browser with security validation
- β’ Create all 25+ icon sizes for browsers, mobile apps, and PWAs
- β’ Selected image contents are not uploaded to Hostt
β‘ Image Optimizer
- β’ Compress and convert images using client-side processing
- β’ Support for PNG, JPG, GIF, WebP, AVIF, and HEIC formats
- β’ Advanced compression with quality control and format conversion
- β’ All processing happens locally - no image uploads
π Text Processing Tools (5 Tools)
- β’ Prefix/Suffix: Add text to line beginnings/ends
- β’ Remove Duplicates: Clean duplicate lines while preserving original order
- β’ Remove Empty Lines: Clean blank lines and whitespace
- β’ Remove Extra Spaces: Format spacing with advanced options
- β’ Combination Generator: Generate combinations from multiple lists
Server-Side Processing (8 Tools)
π HTTP Viewer
- β’ Inspect HTTP headers from any URL
- β’ Server-side processing to bypass browser CORS limitations
- β’ Headers only - no content download for security
- β’ Rate limited to 5 requests per minute
- β’ No request data is logged or stored
π Redirect Detector
- β’ Track URL redirect chains and analyze paths
- β’ Server-side requests follow and report redirect steps
- β’ View status codes, headers, and timing for each step
- β’ Rate limited and security validated
- β’ No URLs or redirect data is stored
π DNS Lookup
- β’ Look up A, AAAA, MX, TXT, CNAME, and NS records
- β’ Server-side processing for reliable DNS resolution
- β’ Rate limited to prevent abuse (10 requests per minute)
- β’ No domain queries are logged or stored
π Uptime Monitor
- β’ Check website availability and response times
- β’ Server-side checks to bypass CORS restrictions
- β’ Your site list stored locally in browser
- β’ Rate limited and security validated
- β’ No monitoring data stored on servers
π IP Intelligence
- β’ Get geolocation, ISP, and security threat information
- β’ Server-side API integration with timeout protection
- β’ Rate limited to 5 requests per minute
- β’ API keys redacted from logs for security
- β’ No IP lookup data is stored
π§ Tech Detection
- β’ Identify technologies used by websites (CMS, frameworks, etc.)
- β’ Server-side browser automation with Puppeteer
- β’ Strict rate limiting (2 requests per 2 minutes)
- β’ Network request interception for security
- β’ No website data or results are stored
π Lighthouse Auditor
- β’ Run Google PageSpeed Insights audits
- β’ Server-side Google PageSpeed Insights request
- β’ Very strict rate limiting (2 requests per 2 minutes)
- β’ No audit data or URLs are stored
π Alert Manager
- β’ Scheduled website checks with email alerts
- β’ Secure user accounts with magic link authentication
- β’ Server-side storage for alert rules and monitoring data
- β’ Encrypted data storage with privacy protection
- β’ Email notifications sent securely via Mailgun
- β’ No personal data tracking or sharing
Why server-side? These tools need network access that browser security restrictions, DNS APIs, scheduled jobs, or provider credentials do not permit directly from the page.
π« What We Don't Do
- βStore your files, images, or text content
- βTrack your browsing behavior
- βCollect personal information
- βUse invasive cookies
- βShare data with third parties
- βRequire user registration
- βLog your tool usage patterns
- βSell or monetize your data
β What We Do
- βProcess most data entirely in your browser
- βUse secure, rate-limited APIs when necessary
- βImplement strong security headers
- βPrivacy-oriented Plausible analytics and limited Google Analytics page measurement
- βProvide tools completely free of charge
- βMaintain transparent, open practices
- βProtect against malicious URLs and attacks
- βContinuously improve security and privacy
βοΈ Technical Details
Security Measures
- β’ Content Security Policy (CSP): Prevents XSS attacks and unauthorized script execution
- β’ HTTPS Everywhere: All connections are encrypted with TLS
- β’ Advanced Rate Limiting: Distributed rate limiting with IP-based tiers and concurrency controls
- β’ Input Validation & Sanitization: All user inputs validated, HTML sanitized with DOMPurify
- β’ SSRF Protection: DNS-over-HTTPS resolution, private IP blocking, request interception
- β’ CORS Restrictions: Origin-restricted CORS headers, no wildcard access
- β’ PII Protection: No personally identifiable information logged in production
- β’ Magic Link Authentication: Secure passwordless authentication for Alert Manager
Data Processing
- β’ Client-Side: 13 tools process data entirely in your browser using JavaScript
- β’ Server-Side: 8 tools use secure serverless functions for CORS bypass and API integration
- β’ No Persistence: Most tools store no data; Alert Manager uses encrypted storage
- β’ Memory Only: Server processing uses only temporary memory for most operations
- β’ Immediate Cleanup: All processing data is cleared after response
- β’ Secure Storage: Alert Manager data encrypted in Vercel KV with user consent
Analytics & Monitoring
We use Plausible Analytics for privacy-oriented aggregate traffic data. We also use Google Analytics 4 to measure canonical page visits and publisher engagement in Beaconhouse.
- β’ Privacy-First: Plausible is GDPR, CCPA, and PECR compliant
- β’ Plausible: Plausible does not use tracking cookies or local storage
- β’ Limited GA4: Advertising signals and advertising-personalization signals are disabled
- β’ Minimal GA4 Event: Hostt sends only the canonical page path, location, and title; Google may process standard request and device metadata
- β’ Aggregate Use: We use analytics reporting to understand aggregate page visits and usage patterns
- β’ Open Source: Plausible's code is fully open source and auditable
- β’ Canonical Pages Only: GA4 receives the canonical page path, location, and titleβnever tool inputs, uploaded filenames, target URLs, or account identifiers
What we track: Aggregate page visits, popular tools, and general usage patterns to improve the service.What we don't track: Tool content, uploaded filenames, target URLs, account identifiers, or cross-site advertising profiles.
Questions About Privacy?
We're committed to transparency and protecting your privacy. If you have any questions about how we handle data or our privacy practices, we're here to help.
Last updated: August 22, 2025
Updated to reflect recent security enhancements and new tools