Privacy
What grepyard collects.
Last reviewed: 7 September 2026.
Tool inputs
We do not store or log what you paste into a tool, and we never associate it with you. There is no account, no session, and no cookie for it to be attached to.
Most tools do their work entirely on your device, so what you paste never leaves the page at all. The JWT decoder and the X.509 decoder handle bearer tokens and private keys, so they say so on their own pages.
One tool does send your input to a server we run, because it has to: the JA4 fingerprint lookup answers from a corpus that lives there and cannot be shipped to your browser. That fingerprint is stripped from our error reports and may appear briefly in our own internal request traces. It is still never associated with you, for the same reason as above. The tool says so on its own page.
The same tool has one button that is different in kind, and it is the only thing on this site that records anything about you. “What is my fingerprint?” opens a connection from your browser to an edge server we run, which records that connection’s TLS and TCP fingerprint, your IP address and your User-Agent. We keep that observation. The fingerprint and User-Agent become part of the public corpus the lookup searches, where anyone who looks up the same fingerprint will see them counted; your address is stored with the observation and counted, but is not itself served by the lookup. This happens only when you click the button, the button says all of this before you do, and nothing you paste is involved.
What we collect
Anonymous page-view counts via a self-hosted Umami instance. Umami sets no cookies, records no IP address, and builds no cross-site profiles. If a tool throws an unhandled error, the stack trace is sent to a self-hosted error monitor with JWTs, PEM blocks, and email addresses scrubbed in your browser before sending.
No tracking cookies are set. Your theme preference is stored in your browser's localStorage and never leaves your device.
Front-end infrastructure
The site is fronted by Cloudflare for DDoS protection and TLS termination. Cloudflare retains its own edge logs under their default retention.