This policy explains what data AI Dev Toolkit (tools.its-tahir.com) handles, why, and what your choices are. The site is run by Tahir Nazir, who is responsible for your data here (the “data controller”), based in Punjab, Pakistan. Contact: hello@its-tahir.com.
What you type into the tools
Almost every tool runs entirely in your browser. When you paste text into a token counter, repair JSON, or fill in a config generator, that text is processed on your device. It isn’t sent to this site’s server, logged or stored.
Two kinds of tools are exceptions, and each one says so on its page:
- Tools that use your API key (playgrounds, exact token counts). These send your prompt directly to the AI provider you chose. See API keys below.
- Tools that need a server, for example fetching a web page you give a URL for. These send our server only what the tool needs to do the job, process it immediately, and store nothing.
Some tools remember your settings (not your text) on your device so they’re there next time. See what’s stored on your device.
API keys (“bring your own key”)
Some tools let you use your own key from a provider such as Google Gemini, OpenAI, Anthropic, Groq or OpenRouter. Usage is billed to your account by that provider. Here’s exactly what happens to your key:
- It goes straight from your browser to the provider. Requests are made by your browser to the provider’s own API address. Your key is never sent to this site’s server.
- It’s kept in memory by default. Close or reload the tab and it’s gone.
- Saving it is optional. If you tick “Remember on this device”, the key is saved in your browser’s local storage on that device only, and a “Forget key” button deletes it. Don’t use this option on a shared or public computer.
- It’s never logged or tracked. Keys are never put in URLs, analytics, error reports or logs.
- The browser limits where data can go. The site’s Content Security Policy only allows connections to this site, the approved provider APIs, and Cloudflare’s analytics endpoint (which receives page-view data, never your key or text). This limits where any script on the page can send data.
- Ads never appear on pages where you enter a key.
No tool uses a relay server today. If a provider ever blocks direct browser requests, that tool will say so clearly before you enter a key, and this policy will be updated first. Any relay would pass the request through without logging or storing your key or your prompt.
What you send to a provider is covered by that provider’s own terms and privacy policy. Treat your keys like passwords: use keys with spending limits where the provider supports it, and revoke any key you think has been exposed.
Analytics
The site uses Cloudflare Web Analytics to count page views and measure page speed. It doesn’t use cookies, doesn’t fingerprint your device, and doesn’t track you across sites. It sees the page URL, the referring site, your browser and device type, and your approximate country.
Google Search Console and Bing Webmaster Tools tell us which searches led people to the site. They report totals, not information about individual visitors.
Hosting and server logs
The site is hosted on Cloudflare. Like any web host, Cloudflare processes your IP address and standard request details (the URL, time, browser user agent) to deliver pages, report network errors and protect the site from abuse. The site’s own operational logs are kept for up to 3 days for debugging and security, then deleted automatically. Cloudflare’s own privacy policy applies to this processing.
Who processes data for the site
- Cloudflare: hosting, security, DNS and cookie-less analytics.
- Hostinger: the hello@its-tahir.com mailbox, if you email us.
- The AI provider you choose: only when you use a tool with your own API key, under your own account with that provider.
What’s stored on your device
- Theme (light, dark or system), in local storage, so the site doesn’t flash the wrong colours.
- Tool settings such as your last selected model, in local storage.
- Your API key, only if you choose “Remember on this device”.
None of this is sent to the server. You can clear it at any time in your browser’s site settings. The cookie policy has the details.
Advertising
There are no ads on the site today. If Google AdSense is added later, Google and its partners may use cookies to show and measure ads. Before that happens, this policy will be updated, and visitors in the European Economic Area, the UK and Switzerland will be asked for consent through a Google-certified consent tool before any advertising cookies are set. Ads will never appear on pages where you enter an API key.
If you email us
Your email address and message are used only to reply and to fix what you reported. They’re never sold, shared or added to a mailing list. Emails are kept for up to 12 months after the conversation ends, then deleted. You can ask for yours to be deleted sooner at any time.
Your rights
Because the site doesn’t ask you to sign up and doesn’t store what you type, it holds almost no personal data about you. Depending on where you live (for example under the GDPR or UK GDPR), you have the right to access, correct or delete personal data we hold, to object to processing, and to complain to your local data protection authority. To make a request, email hello@its-tahir.com.
The legal basis for the limited processing described here is legitimate interest: running a secure, working website and understanding which pages are useful.
Children
The site is for developers and isn’t directed at children under 16.
Changes to this policy
When this policy changes, the “last updated” date at the top changes too. Significant changes, such as adding advertising, will be described here before they take effect.