Privacy Policy
Last Updated: August 2026
1. Introduction
Welcome to Useful Utilities ("we", "our", or "us"). We are committed to protecting your personal information and your right to privacy. If you have any questions or concerns about this privacy notice, or our practices with regards to your personal information, please contact us at support@usefulutils.in.
2. Information We Collect
The short version: we do not store the data you put into our tools. There are a small number of specific exceptions, and they are all listed below. We would rather spell them out than make a blanket promise that is not exactly true.
What we do not collect
Web interface (browser): The great majority of our tools run entirely on your device. When you use the text, image, PDF, JSON, list, table, or security utilities on this website, your input is processed in your browser's own memory and is never transmitted to us. We do not receive it, log it, or store it.
API and MCP server: When you or an AI agent calls our Model Context Protocol (MCP) server, the request content is sent to our backend so it can be processed. That content is handled ephemerally, in memory, and is never stored, logged, or retained once the request completes. Our usage analytics record which tool was called β never the arguments you passed or the result returned.
The exceptions β where data is collected or leaves your device
- MCP API key creation. When an API key is first generated we store the key, the IP address it was created from, the creation time, and an approximate location derived from that IP β country, state or region, and city. This exists to enforce fair-use limits, to prevent abuse, and to understand roughly where the server is being used from. To determine that location the IP address is sent to a third-party lookup service; we tryipwho.is,ipinfo.io andipapi.co in that order until one responds. The location is approximate β it is derived from the network your connection belongs to, not from device location or GPS, and is often only accurate to the nearest large city. This applies only to key creation and does not affect the βnever storedβ guarantee for the content of your subsequent tool calls.
- OCR. The OCR tool uploads your image to our backend to run native Tesseract text extraction β unlike the rest of this site's tools, it needs a network connection. That image is handled ephemerally: held in memory only for the duration of the request, never written to disk or a database, and discarded once the extracted text is returned to your browser. Your IP address is used to enforce a short-lived, in-memory rate limit (3 requests/minute, 20/hour, 100/day) to prevent abuse; those counters are not a database and reset on their own (per time window, and entirely on a server deploy).
- Analytics. We use Google Analytics on the website, and our MCP server reports basic tool-usage metrics to the same property. See section 3 for exactly what this covers.
- Tools that must contact an outside service. A few tools cannot work offline, because their entire purpose is to fetch or reach something live. In these cases what you type is sent directly from your browser to that third party β not to us:
- Package Latest Version Checker β the package name goes to the relevant public registry (npm, PyPI, Maven Central, NuGet, the Go module proxy, crates.io, RubyGems, Packagist, or vcpkg).
- Currency Converter β exchange rates are fetched from a public rates API.
- Network utilities (latency test, DNS check, path quality) β these measure a real connection, so they necessarily make real network requests.
- Webhook Tester β receives and displays HTTP requests that are sent to it.
- Stored in your browser only. Your dark-mode preference and recent-tools history are kept in your browser's LocalStorage. This never reaches us, and clearing your browser data removes it.
3. Cookies and Tracking
We use minimal cookies to ensure the website functions correctly.
- Essential Cookies: We store your "Dark Mode" preference and "Recent Utilities" history in your browser's LocalStorage. This data stays on your device.
- Analytics: We use Google Analytics to understand which tools are most popular. It does not collect your name, email address, or other directly identifying information, and does not store your IP address (only an approximate region, derived from it and then discarded). It does assign your browser a persistent, randomly generated identifier (stored in a
_gacookie) to distinguish separate visits β this makes the data pseudonymous rather than fully anonymous: the identifier isn't tied to your real-world identity, but it is a persistent value that can track behavior on this site over time. - MCP Usage Analytics: Separately, our MCP server reports basic usage metrics (which tool was called, an approximate region, and a truncated/hashed fragment of the API key used) to the same Google Analytics property, so we can understand usage patterns and catch abuse. It never receives your tool-call arguments, results, or the full API key.
- Advertising: We use third-party advertising companies (Google AdSense) to serve ads when you visit our Web site. These companies may use aggregated information (not including your name, address, email address or telephone number) about your visits to this and other Web sites in order to provide advertisements about goods and services of interest to you.
4. Third-Party Services
We may share anonymous, aggregated data with the following third-party service providers:
- Google Analytics: To measure site usage and understand which tools are most popular. Read how Google Analytics handles data.
- Google AdSense: To display advertisements. Read Google's Ad privacy policies.
- IP geolocation services (ipwho.is, ipinfo.io, ipapi.co): One of these receives an IP address once, at MCP API key creation, to resolve it to an approximate country and city. They are tried in order until one responds. Example privacy policy.
- Public package registries (npm, PyPI, crates.io, RubyGems, Packagist) and a public exchange-rate API: contacted directly by your browser when you use the Package Version Checker or Currency Converter. They see the request as an ordinary visit from your device.
5. Data Security
Because we do not store your input data (files, text, images) on our servers, there is no risk of a server-side data breach exposing your content. Your processed files in the web interface are only accessible to you during your browser session. API and MCP requests are encrypted in transit via HTTPS and discarded immediately after processing.
The exceptions in section 2 are the limits of that statement. The only personal data we durably retain is the IP address recorded when an MCP API key is created; there is no account system, no password, and no stored file content anywhere in our infrastructure. OCR images are handled in memory only, for the duration of a single request, and are never written to disk or a database.
6. Contact Us
If you have questions or comments about this policy, you may email us at support@usefulutils.in.