1. Who is responsible
the operator of ToolsXpo is the data controller for personal data processed through ToolsXpo. Data protection enquiries: privacy@toolsxpo.com.
For payments, Paddle.com Market Ltd is a separate controller. We never see or store your card number.
2. What we collect
Account data
Your email address and a hash of your password (bcrypt — we cannot read your password). If you provide a name, that too. We record the IP address used at signup, to detect people creating multiple accounts to farm free credits.
API keys
For each key we store the name you gave it, a short non-secret prefix so you can tell your keys apart, and its usage — when it was created, when it was last used and what it has spent. You can revoke a key at any time from your dashboard, which stops it working immediately.
Usage records
For each call we record the tool called, whether it came from the API or from a tool page on the site, the workspace it belongs to, the credit cost, the HTTP status, the calling IP address and the timestamp. This is what your dashboard totals are built from, and it is how billing is auditable.
We do not store the contents of your requests or the results returned. Inputs are processed in memory to produce a response and are not written to our database.
AI tools
Almost every tool on this site runs entirely in your browser: what you paste never reaches us, so there is nothing for this policy to cover. A small number of tools — currently the AI Text Summarizer, AI Image OCR and AI Text Embeddings — are different, and the difference is worth stating plainly rather than leaving to be inferred from the sentence above.
When you use one of those, what you submit is sent to us and on to a model provider(currently Cloudflare Workers AI) to be processed, along with the model's answer. Neither is stored by us. What we keep is the accounting: which tool ran, which model answered, how many tokens were used, and what the call cost — never the content of those tokens.
We use providers on terms that do not permit training on this traffic. That is a contractual position rather than something we can enforce technically, so the practical advice is simple: if something must not leave your own systems, use one of the in-browser tools instead. Every tool page says which kind it is, and the providers are listed in Subprocessors.
Billing data
A record of credits bought, granted, spent and expired, and an identifier linking your account to your Paddle customer record. Card details never reach us.
Cookies
A session cookie when you sign in, and an admin session cookie for staff. Both are HttpOnly and strictly necessary. See the Cookie Policy.
3. Why we process it, and on what legal basis
| Purpose | Data | Lawful basis (UK/EU GDPR) |
|---|---|---|
| Providing the Service | Account, API keys, usage | Performance of a contract |
| Billing and metering | Usage, credit ledger | Performance of a contract |
| Service emails (receipts, low balance, renewal notices) | Email address | Performance of a contract |
| Preventing fraud and abuse | IP addresses, signup patterns, payment outcomes | Legitimate interests |
| Security and debugging | Request metadata, error logs | Legitimate interests |
| Meeting tax and accounting obligations | Transaction records | Legal obligation |
We do not use your data for advertising, we do not sell it, and we do not use the contents of your requests to train machine-learning models.
4. Who we share it with
Only the processors needed to run the Service. Each is listed, with what it can see and where, on the Subprocessors page. In summary: Cloudflare (hosting, database, storage), Paddle (payments), and an email delivery provider.
We may also disclose data where legally required, or to establish or defend legal claims. If we are ever compelled to hand over customer data, we will tell you unless legally prohibited from doing so.
5. International transfers
Our infrastructure runs on Cloudflare's global network, so data may be processed in countries outside your own, including the United States. These transfers rely on the UK/EU Standard Contractual Clauses and the providers' own transfer frameworks.
6. How long we keep it
- Account data — until you delete your account, then removed within 30 days.
- API usage records — 24 months, so you and we can audit historical billing.
- Billing and credit ledger — as long as tax law requires, typically 6–7 years. These records survive account deletion because we are legally required to keep them.
- Fraud and abuse records — up to 24 months after the account closes, so a blocked account cannot simply be recreated.
7. Your rights
Depending on where you live, you have some or all of the following rights:
- access a copy of your personal data;
- correct data that is wrong;
- delete your data (subject to the retention obligations above);
- restrict or object to processing, including processing based on legitimate interests;
- receive your data in a portable format;
- withdraw consent, where we relied on it; and
- complain to your data protection authority.
California residents:you additionally have the right to know what is collected and to opt out of "sale" or "sharing" of personal information. We do neither, so there is nothing to opt out of. We will not discriminate against you for exercising any right.
To exercise a right, email privacy@toolsxpo.com from your account address. We respond within 30 days.
8. Security
Passwords are hashed with bcrypt and are not recoverable from our database. Traffic is encrypted in transit. Admin access is restricted and separately authenticated. Sensitive values are encrypted at rest with keys held outside the database. No system is perfectly secure.
If a breach affects your data and creates a real risk to you, we will notify you and the relevant regulator as the law requires.
9. Children
The Service is not for anyone under 16. We do not knowingly collect their data; if we learn we have, we delete it.
10. Changes
We will post any update here and change the date at the top. For material changes we will notify you by email or in the dashboard.