Privacy
Nothing you paste into this site is transmitted anywhere. Not to us, not to an analytics service, not to a third party. This page explains exactly what happens to it, and how to check that claim yourself rather than taking our word for it.
The short version
Every tool on this site runs inside your browser tab. The parser, the formatter, the converters and the schema engine are all JavaScript and WebAssembly delivered to your device and executed there. There is no server-side component that could receive your document, because there is no server-side component at all: the site is a set of static files.
How to verify it in thirty seconds
This is the part that matters, because a privacy policy is only a promise and a network panel is evidence.
- Open any tool on this site.
- Open your browser's developer tools and switch to the Network tab. In Chrome, Edge and Firefox that is F12 or Ctrl+Shift+I; on a Mac, Cmd+Option+I.
- Clear the request list.
- Paste a document, edit it, format it, convert it, validate it against a schema.
You will see the page's own assets load once, and then nothing. No request carries your document because no request is made. If you ask for schema validation you will see the WebAssembly engine download once, which is a static file we serve to you and which carries nothing back.
The one exception is deliberate, visible and user-initiated: on the sitemap and feed validators there is a Fetch button that retrieves a URL you type. That request goes directly from your browser to the address you entered. It does not pass through us, and we do not operate a proxy for it. That is why it fails on hosts that do not send permissive CORS headers, and why we hand you a curl command instead of routing it through a server.
What is stored, and where
One thing is stored, and it is stored on your own machine. Your input is saved to this browser's localStorage so that refreshing the page does not lose your work.
- It never leaves your device.
localStorageis not transmitted with requests. - It is per-tool and per-browser, and it is not synced anywhere by us.
- Documents over 300 KB are not stored at all, because writing them on every keystroke would make the editor stutter.
- The Clear button on each tool removes it immediately. Clearing site data for this domain removes all of it.
Your theme preference (light or dark) is stored the same way. That is the complete list.
Cookies
Google Analytics sets two first-party cookies on this domain, _ga and_ga_FBP23VH3XG. Both hold a randomly generated number that lets Google tell a returning browser from a new one. Neither carries a name, an email address or anything you typed, and both expire two years after your last visit.
Nothing else on this site sets a cookie. No functional cookies, no advertising cookies, and no cookies from any party other than the two above. Every tool works with cookies disabled, because no tool reads one.
Analytics and third-party scripts
The site uses Google Analytics 4, property G-FBP23VH3XG. It is the only third-party script on any page, and it is the only thing on the site that talks to a server after the page has loaded. It records which URL you visited, which page sent you here, an approximate location worked out from your IP address, and the broad strokes of your browser and device. Google processes that data.
It cannot read what you paste, and that is a property of how the tools are built rather than a promise about behaviour. The editor's contents are never written to the DOM in a form a third-party script could scrape, never placed in the URL, and never passed to any function outside the tool's own module. Analytics sees the page address, the same one already in your address bar, and nothing from inside the editor.
Everything else the word tracking usually covers is still absent: no session recording, no heatmaps, no chat widget, no social share buttons, no error-reporting service, and no advertising of any kind.
To opt out, block googletagmanager.com and google-analytics.com. Most content blockers already do. The site is built to work identically when they are blocked, and none of the tools change behaviour either way.
Fonts are self-hosted from this domain rather than loaded from Google Fonts, which would otherwise disclose your IP address to a third party on every page view.
Server logs
The site is served as static files from Cloudflare Pages. Cloudflare's edge records standard request metadata for the files it serves, which is the same information any web server sees: the IP address making the request, the URL of the file, the time, the user agent. This is a property of serving a website over HTTP at all, and it applies to the HTML, CSS, fonts and JavaScript.
Your document is not in that data, because your document is never requested from the server and never sent to it. There is no endpoint that accepts it.
Why this is unusual, and why it matters here
Several of the best-known XML validators do send your document to a server. One of the highest-ranking ones asks you to tick a box confirming you understand that your data is stored on their servers and may be retained for service improvement. Another states in its own privacy policy that uploaded XML and schema files are kept in memory for the duration of your session, which is an admission that they are uploaded. At least one tool in this category saves submitted documents to a public URL by default, and those URLs have been indexed by search engines.
This matters more for XML than for most formats. The documents people paste into an XML validator are SOAP envelopes with bearer tokens in the header, configuration files with connection strings, integration payloads with customer records, and SAML assertions. Uploading those to an unknown third party during a production incident is a bad idea, and it is frequently a breach of the policy the person is working under.
Contact
If you find something on this site that contradicts anything above, that is a bug and we want to know. Write to [email protected].
Changes
If this policy changes in a way that affects what happens to your data, the change will be described here rather than silently applied. Last reviewed 12 September 2026.