Privacy
Privacy Policy
Draft — not yet in force.
This page is awaiting legal review and is excluded from search engines. It describes what Roftrlabs actually does today, but it is not yet a binding statement by Roftr Clouds LLP. Do not rely on it.
Last updated 2026-08-15
The short version
Roftrlabs has no accounts and runs no advertising. We use Google Analytics to count visits and see which tools get used — nothing more. Most of our tools never send your data anywhere — they run entirely inside your browser. When a tool does need our servers, it is because it has to fetch a web address on your behalf, and what we keep from that is deleted within 24 hours.
Tools that run in your browser
Tools marked as running in your browser — the JSON formatter, for example — process what you paste entirely on your own device. The content never reaches Roftr Clouds LLP, is never transmitted over the network, and cannot be seen by us. You can confirm this: disconnect from the internet after the page loads and the tool still works.
Tools that check a web address
Some tools need to request a page from the internet to tell you anything about it. When you submit an address to one of these:
- We store the address you submitted, in normalised form, along with the result of the check.
- Both the address and the result are erased 24 hours later. After that the result link still resolves, but it tells you the result has expired — the data behind it is gone, not hidden.
- Results are shared. If someone else asks about the same address within 15 minutes, they are served the result of the earlier check rather than the site being fetched again. Do not submit an address you consider confidential — a private staging URL, or a link containing a token — as the result becomes visible to anyone who submits the same address.
We do not store the content of the pages we fetch. We keep the structured findings — status codes, headers, measurements — not a copy of the page.
Your IP address
We need to recognise a repeat caller in order to enforce rate limits and stop the service being used to attack other people's websites. We do not need to know where you are, so your IP address is never written to our database. It is converted to an irreversible keyed hash the moment a request arrives, and only that hash is stored. Two requests from the same address produce the same hash; the hash cannot be turned back into an address, including by us.
Our web server keeps ordinary access logs, which do contain IP addresses, for a short period for security and abuse investigation.
What you search for
When you use the search box we keep the phrase you searched for and how many results it produced. We do this for one reason: a search that comes back empty is a tool somebody wanted and we do not have, and it is how we decide what to build next.
The phrase is stored on its own. It is not attached to a name, an account, a cookie or a session, and nothing in that record can be used to connect two searches to the same person — the only identifier stored alongside it is the same irreversible hash described above, used to stop one source flooding the record. Phrases are deleted after 180 days.
We refuse to store some things outright, because search boxes are where people paste text meant for somewhere else. Anything containing an email address, anything containing a long run of digits such as a card or phone number, and anything long enough to be a paste rather than a search is discarded and never written down. A pasted web address is reduced to its domain before it is stored, so the path and any token in it are dropped.
Cookies and tracking
The public site uses Google Analytics, which sets two cookies holding a random identifier so that two page views can be counted as one visitor. That measurement is the only tracking on the site: we embed no advertising, no social widgets and no session recording, and blocking analytics in your browser changes nothing about how the site works. Our cookie policy names each cookie, its purpose and its lifetime.
What we never do
- Sell, rent or share your data with advertisers or data brokers.
- Build an advertising profile of you, or follow you across other sites.
- Retain the content of pages we fetch on your behalf.
Your rights
Under India's Digital Personal Data Protection Act 2023 you may ask what personal data we hold about you, ask for it to be corrected or erased, and complain about how we have handled it. In practice we hold very little: with no accounts, an anonymous visitor's data is a hashed identifier and a submitted address that deletes itself within 24 hours.
Because the identifier is a one-way hash, we usually cannot connect a request to you even if you ask us to — which is the point of hashing it, but does mean we may be unable to locate records on request.
Contacting us about privacy
- Entity
- Roftr Clouds LLP
- LLPIN
- Not yet published — see the draft notice above.
- Registered office
- Not yet published — see the draft notice above.
- Not yet published — see the draft notice above.
- Grievance officer
- Not yet published — see the draft notice above.
Changes to this policy
If we change what we collect or how long we keep it, we will update this page and the date at the top of it. Material changes to how we handle data will be reflected here before the change takes effect, not after.