Privacy Policy

Almost nothing about you, on purpose.

Last updated 20 August 2026. In effect from the same date.

TinkerYard is a small workshop of free tools, browser extensions and desktop apps. There is nothing to sign up for, no account to create, and most of what is here never sends your data anywhere at all. This page is the long, specific version of that claim: what is collected, what is not, which tool does which, and who else is involved when a request does leave your browser.

The short version

  • No accounts, no signups, no logins, anywhere on the site.
  • Eleven of the thirteen things here do all their work inside your browser. Your files, camera frames, pasted text and generated passwords never reach a server.
  • Two tools do need one: YouExtrac and Kontrib. Exactly what they send, and to whom, is spelled out below.
  • We do not sell, rent or trade information about you, and there is no mailing list to end up on.
  • Page-view analytics are aggregate and cookie-free. The ads that pay for hosting are Google's, and those do use cookies - you can switch off personalised ones.

Who we are

TinkerYard is an independent project built and run by Yash Pandey (“TinkerYard”, “we”, “us”). It is not a company, and it has no staff beyond one person, which is why the honest answer to most privacy questions here is “we never had it.” For any question about this policy or the data behind it, the responsible contact is hello@tinkeryard.xyz.

This policy covers tinkeryard.xyz and everything hosted under it, plus the PinThemes browser extension and the LitePad desktop app. It does not cover other websites we link to, which run their own policies.

What we collect

Things you type, paste or upload

Handled by the tool that needs them, and nothing else. For browser-only tools that means no transmission of any kind. For the two tools that call a server, only the specific text needed for the lookup is sent - a URL, a search line, a GitHub username - and it is used to build your result and then dropped. There are no user profiles, no saved history, and nothing tying one visit to the next.

Things collected automatically

  • Aggregate page views through Vercel Web Analytics: the page path, referrer, country, browser and device type. No cookies, no cross-site identifier, and no way to single you out of the counts.
  • Standard server logs from our host when a page or API route is requested: IP address, timestamp, user agent and requested path. These are the host's operational logs, kept briefly for security and debugging, and are not used to build a picture of you.
  • A short-lived rate-limit counter on YouExtrac's lookup routes, keyed to your IP address so one visitor cannot burn through the shared API quota. It lives in server memory for minutes, is never written to a database, and is not joined to anything else.

Things stored on your device

The site sets no cookies of its own and does not save your tool inputs. PinThemes keeps your theme settings locally through chrome.storage.local. Copy buttons and the share rail use your clipboard, which is a local action your browser performs and we never see the contents of.

Things you email us

If you write to hello@tinkeryard.xyz, we have your address and your message in an ordinary inbox for as long as the thread is useful. You are not added to any list, and we will not contact you about anything unrelated.

Tool by tool

The claim above is only meaningful if it is specific, so here is every live project and what it actually does with what you give it.

  • QR Code ScannerNever leaves your device

    Camera frames and uploaded images are decoded inside your browser. No frame, photo or decoded result is uploaded, and the camera stream stops when you leave the page.

  • Barcode ScannerNever leaves your device

    Same as the QR scanner - the video stream is read by your own device and nothing about it is sent anywhere.

  • Color PickerNever leaves your device

    Images you open are read locally to sample colours. The file never leaves your machine.

  • Password GeneratorNever leaves your device

    Passwords are generated in your browser using its built-in cryptographic randomness. They are never transmitted, logged, stored or seen by us.

  • JSON FormatterNever leaves your device

    Pasted JSON is parsed and formatted in the page. It is not sent to a server, so it is safe to paste payloads you would not want to upload.

  • Markdown PreviewerNever leaves your device

    Markdown is rendered as you type, entirely client-side. Nothing is saved between visits.

  • Image CompressorNever leaves your device

    Compression happens on a canvas in your browser. Your originals and the compressed output both stay on your device.

  • Spin the WheelNever leaves your device

    The entries you type exist only in the open page and disappear when you close or reload it.

  • Something to Stare AtNever leaves your device

    Runs in your browser with no input from you. The scene artwork and audio are downloaded from our public asset host on GitHub, so GitHub sees a request for those files the same way any image host would.

  • YouExtracCalls a server

    The playlist or video URL you paste, or a line of a tracklist, is sent to a TinkerYard API route which queries the YouTube Data API to look up titles and video IDs. The result comes straight back to you and is not stored, and no part of your request is attached to you.

  • KontribCalls a server

    The GitHub username you enter goes to Kontrib's backend, which reads that account's public commit history from GitHub's API. Those public commit messages and the computed metrics are then sent to Groq, which writes the feedback text. Private repositories are never accessible, and nothing is kept after the response is returned.

  • PDF ToolsNever leaves your device

    Merge PDF, Split PDF, Organize PDF Pages, Rotate PDF, PDF to JPG and JPG to PDF all read your file with code running inside this tab - there is no upload step and no server involved. Documents are held in memory only while the page is open, and closing or reloading the tab discards them. This is why every one of them warns you to download the result before you leave.

  • PinThemesNever leaves your device

    The browser extension has no servers and no analytics. Your colours, opacity and any background image are stored on your own machine via chrome.storage.local and never leave it.

  • LitePadNever leaves your device

    The Windows app has zero telemetry - it does not phone home, check in or report usage. Downloads are served from GitHub Releases, so GitHub sees the download request itself.

Third parties

These are every outside service involved in running the site. Each one has its own privacy policy, and once a request reaches them their terms govern what happens next.

  • VercelHosting and analytics

    Serves every page and API route, and provides the cookie-free page-view counts. Sees standard request data, including IP address, in its operational logs.

    Their privacy policy

  • Google AdSenseAdvertising

    The ad script that pays for hosting. Google and its partners may set cookies or read device identifiers to serve, cap and measure ads.

    Their privacy policy

  • YouTube Data API (Google)YouExtrac lookups

    Receives the search terms and video or playlist IDs derived from what you paste into YouExtrac.

    Their privacy policy

  • GitHubPublic data, assets and downloads

    Provides the public commit history Kontrib reads, and hosts the Stare scene files and the LitePad installer.

    Their privacy policy

  • RenderKontrib backend hosting

    Runs the small service Kontrib's analysis calls, and sees that request in its own operational logs. The service itself writes nothing down.

    Their privacy policy

  • GroqKontrib feedback text

    Receives the public commit messages and metrics for the username you analysed, and returns the written comparison.

    Their privacy policy

  • Buy Me a CoffeeSupport button

    The support badge image is loaded from its CDN, so that request is visible to them. Nothing about you is sent unless you click through and choose to pay.

    Their privacy policy

There is no other pipeline. Nothing is shared with data brokers, ad networks beyond Google's, or anyone paying for access, because there is nothing collected that would be worth selling.

Ads and cookies

TinkerYard sets no cookies itself. Ads are what keep the tools free and the hosting paid for, and they come from Google AdSense, which does use cookies and similar device identifiers to serve, frequency-cap and measure them - and, unless you say otherwise, to personalise them based on your earlier visits to this site and others.

You can change that at any time, from your side:

  • Turn personalised advertising off at Google My Ad Center. Ads still appear; they stop being tailored.
  • Opt out of other vendors' cookies at aboutads.info or the NAI opt-out page.
  • Block third-party cookies in your browser, or use an ad blocker. Nothing on this site is gated behind either, and every tool keeps working.

Where the law requires consent for advertising cookies - the EEA, the UK and Switzerland - Google's consent mechanism applies before personalised ads are served, and declining simply means the ads are non-personalised. For the detail on what Google does with data from sites that use its services, see how Google uses information from partner sites.

We do not track you across other websites ourselves, so there is no cross-site profile of you on our side to honour a Do Not Track or Global Privacy Control signal against. Where such a signal reaches Google's ad stack, its own handling applies.

How long we keep it

  • Tool inputs: not retained. They are processed in memory and gone with the response.
  • Rate-limit counters: minutes, in memory, then discarded.
  • Host request logs: kept short-term by our host under its own retention schedule, and only read when something is broken or being abused.
  • Analytics: aggregate counts only. There is no individual record to export or erase.
  • Email: kept while the conversation is useful, then deleted on request or in the normal course of clearing an inbox.

Your rights

Most requests are quick to answer here, because there is no account to export, no profile attached to your visits and no stored copy of anything you typed into a tool. You still have the right to ask what we hold, get a copy or a correction, ask for deletion, object to or restrict processing, and complain to your local data protection authority.

If you are in California: we do not sell or share personal information as the CCPA and CPRA define those terms, we do not use it for cross-context behavioural advertising of our own, and we run no financial-incentive programmes. Ad personalisation is controlled through the Google settings linked above. You will never be treated differently for exercising any of this.

To make a request, email hello@tinkeryard.xyz. We reply within 30 days, usually the same week, and we may ask for enough detail to identify what you are referring to - which is often nothing, because we hold nothing.

Children

The tools here are not directed at children under 13, or under the higher minimum age where you live, and we do not knowingly collect personal information from them. With no accounts and no forms, there is essentially nothing for a child to submit. If you believe a child has sent us something by email, write to us and it will be deleted.

Security

Everything is served over HTTPS. The strongest protection here is structural rather than procedural: the tools that touch anything sensitive - passwords, images, documents, your camera - never transmit it, so there is no store of it to breach. Where a server is involved, only the minimum needed for that one lookup is sent, and nothing is written down afterwards.

No system is perfectly secure, and we cannot promise absolute security for the parts we do not control. If you find a vulnerability, please report it to hello@tinkeryard.xyz before disclosing it publicly.

Where data goes

The site runs on a global edge network, and the services listed above operate from several countries including the United States, so a request may be handled outside the one you are in. Those providers rely on their own transfer safeguards, such as the EU standard contractual clauses. Given how little is transmitted in the first place, this mostly concerns ordinary request metadata rather than anything you typed.

Changes

When this policy changes, the date at the top changes with it, and anything material also gets a line on the Versions page so there is a public record of when it happened. Continuing to use the site after an update means the revised version applies to you. If a change ever meaningfully reduces your privacy, it will be called out plainly rather than buried in a diff.

Contact

Questions about this policy, requests about your data, or a sentence in here that reads wrong - all of it goes to hello@tinkeryard.xyz. This page is written in plain language on purpose. If something is unclear, that is a bug worth reporting, and the About page explains the thinking behind building it this way.