Qortex Tools

Privacy Policy

What Qortex Tools collects, what it does not, and why. Written to be accurate rather than comprehensive, because a policy describing things we do not do is worse than no policy.

Last updated 6 August 20267 minute read

Privacy Policy

Last updated: 6 August 2026

This policy describes what Qortex Tools collects, what it does not, and why. It is written to be accurate rather than comprehensive, because a policy that describes things we do not do is worse than no policy.

The short version

The tools do not send your data anywhere. Everything you paste, type or configure stays in your browser. No upload, no server-side processing, no copy on our systems.

Two things do reach our servers, and only because you asked them to: a message you send through the contact form, and anything you explicitly save to an account. Both are described below.

We also collect anonymous usage counts so we know which tools are worth maintaining. We never collect what you put into them.

What the tools do with your input

Every tool on this site runs client side. Your schema, your JSON, your field configuration and your generated data are processed in your browser and never transmitted.

This is not a policy promise. It is how the tools are built, and it is enforced by an automated check that fails our build if any tool makes a network call.

When you share a tool configuration, it is encoded in the part of the URL after the #.

Browsers never send that part to a server. It does not appear in our logs, in analytics, or in the Referer header when you follow a link. Anyone you send the link to can see it, because it is in the link, so treat a share link the way you would treat the data itself.

What we collect

Anonymous usage events, so we know which tools are used and which are broken:

  • Which tool, and which action: viewed, run, succeeded, failed, copied, downloaded
  • How large the input was in bytes, and how long the operation took
  • Whether it succeeded, and if not, the category of failure
  • Coarse country and device type
  • The site that linked you here, if any

We do not collect any input, any output, any filename or any parsed value.

On IP addresses. We do not store IP addresses in our analytics. Country is derived from the connection at the moment a request arrives and only the country is kept, never the address it came from.

Our web server keeps standard access logs, which include IP addresses, for security and diagnostics. They are kept for a short period for that purpose and then rotated out, and they are not used for analytics or linked to anything else.

Visitors are counted using a hash of coarse signals with a salt that rotates daily. It is not a persistent identifier and it is never connected to an account, even when you are signed in.

The daily rotation means it is not designed to follow anyone across days. We are not claiming it is mathematically impossible: an unusual combination of country, device class and referrer is in principle distinguishable. We do not attempt it, we have no tooling for it, and nothing in the data would identify who it belonged to.

Error reports

When something breaks, we record the error type, where it happened, and the browser and operating system category.

Error messages are filtered through an allowlist rather than being logged as written. Parser errors often quote the text that caused them, and framework error handlers can capture entire component states. Both would mean recording your data by accident. We log the error class, a message template and a position, never raw content.

Accounts

Accounts are optional. Every tool works fully without one.

If you create one, we store your email address, your name if the sign-in provider supplies it, and anything you explicitly save: presets, configurations, history.

Saved items can contain your real data, because that is what you saved. They are stored on our servers, they are personal data, and the rights below apply to them.

Anonymous usage events are never linked to your account. That separation is enforced in the database schema and checked automatically on every build, so it cannot be quietly undone later.

Cookies

We use one kind of cookie: a session cookie, and only if you sign in. It is strictly necessary to keep you signed in and it is deleted when you sign out.

No analytics cookies. No advertising cookies. No third-party tracking. Anonymous usage counting does not use cookies.

Who we are and why we process

Controller: Qortex Lab, currently an unincorporated venture based in Hyderabad, India.

Contact support@qortexlab.com or use the contact form. We will provide a postal address on request. If Qortex Lab is incorporated, this section will name the registered entity.

WhatWhyLawful basis
Anonymous usage countsTo know which tools are used and which are brokenLegitimate interest in maintaining and improving the service. No identification is possible
Error reportsTo find and fix defectsLegitimate interest in a working service
Account data and saved itemsTo provide the account features you asked forPerformance of a contract, since you requested the account
Session cookieTo keep you signed inStrictly necessary, so no consent required
Contact messagesTo answer youLegitimate interest in responding to enquiries
Server access logsSecurity and diagnosticsLegitimate interest in operating securely

We do not process data for advertising, profiling or automated decision-making.

Your rights

If you have an account:

  • See what we hold. Export everything associated with your account as JSON, from your account settings
  • Delete it. Deleting your account removes your saved items along with the account. Anonymous usage counts are unaffected, because they were never linked to you. If you want confirmation that a deletion has completed, ask us and we will confirm it
  • Correct it. Change your name or email from your account settings
  • Ask. Use the contact form for anything not covered here

If you do not have an account, we hold nothing that identifies you.

Complaints. If you are in the EU, EEA or UK and believe we have handled your data improperly, you have the right to complain to your national data protection supervisory authority. We would rather you told us first through the contact form, but that right stands regardless.

Data location and retention

Our server is hosted with OVHcloud, a French provider, in a European data centre.

  • Anonymous usage events: 90 days, then aggregate counts only
  • Error reports: 90 days
  • Account data: until you delete it
  • Contact messages: kept while we are dealing with them and for a reasonable period afterwards, then deleted. Reviewed manually, never automatically processed

Third parties

  • Sign-in providers. Only if you choose to sign in, and only to verify who you are. Their privacy policy governs that exchange
  • Our hosting provider, which stores the data described above

No advertising networks. No analytics services. No data brokers. Nothing is sold or shared.

Children

This site is aimed at software testing professionals and is not directed at children under 13. We do not knowingly collect data from them.

Changes

Material changes will be noted here with a new date. The current version always applies.

Contact

Questions about this policy: the contact form, or email support@qortexlab.com.

QL
Qortex Lab
Tools and guides for software testing