Browser-local tools
Tools explicitly marked as browser-local process supported inputs on your device. For those executions, the value you enter does not need to be sent to the Ciatto Tools API. Examples include QR generation, JSON formatting, password generation, UTM building and other local converters.
- Do not treat any online interface as a substitute for secure secret-management practices.
- Browser telemetry may record that a tool was started or completed, but product events are designed not to contain the raw tool input or result.
Server diagnostics
Some tools require a server request, for example public URL, DNS, TLS, HTTP or SEO diagnostics. The target you submit is transmitted to the Ciatto Tools API so the requested check can be performed. Operational systems may process request identifiers, timestamps, network metadata, error information and tool identifiers for security, abuse prevention and reliability.
- Do not submit private URLs, credentials or personal secrets.
- Network tools are designed for public targets and include controls intended to block access to private/internal network destinations.
AI tools
AI business tools send the context necessary for the requested generation to the Ciatto AI service. Generated output may be inaccurate and should be reviewed before use. Avoid entering sensitive personal information or confidential data that is not necessary for the task.
Advertising and cookies
When advertising is enabled, third-party advertising vendors, including Google, may use cookies or other identifiers to serve and measure ads. Google's advertising cookies can enable Google and its partners to serve ads based on visits to this and/or other websites. Users can manage personalized advertising through Google's Ads Settings.
- Ciatto Tools keeps advertising disabled until the production advertising and consent configuration is explicitly enabled.
- Where required for Google publisher products in the EEA, the United Kingdom or Switzerland, the production setup must use an appropriate Google-certified consent management platform integrated with the IAB TCF.
- Google explains how it uses information from partner sites at policies.google.com/technologies/partner-sites.
Retention and security
Operational data is retained only as needed for service operation, security, troubleshooting, abuse prevention and applicable obligations, subject to the storage systems and production configuration in use. We use technical controls intended to reduce unnecessary exposure, but no internet service can guarantee absolute security.
Third-party services and choices
Some functions rely on service providers such as infrastructure, analytics, AI or advertising providers. Their processing is governed by their own terms and privacy practices where applicable. You can use browser controls and available consent interfaces to manage cookies and advertising choices.
Changes
This policy may change as the product and its integrations evolve. Material changes should be reflected on this page before or when the related production behavior changes.