Skip to content
bugsTobuild

Privacy Policy

Last updated 24 September 2026

The short version: all 17 tools on bugsTobuild do their work inside your browser. What you paste into them is not sent to our servers, so there is nothing for us to log, store or lose. The longer version, below, is about the parts of a website that are not a tool — the request your browser makes to load the page, and the measurement and advertising services that may sit alongside it.

Who this is about

bugsTobuild is a collection of browser-based utilities at bugstobuild.com. This policy covers that website and nothing else.

The service is operated by NexodusCode.

What the tools do with your input

Every tool currently published — 17 of 17 — is marked Runs in your browser. The text you paste, the files you load and the results you get are processed by JavaScript on your own device. They are not transmitted to a bugsTobuild server, because there is no server-side tool endpoint for them to be transmitted to.

You do not have to take that on trust. Open your browser’s network inspector while using a tool: you will see the page and its assets load, and then nothing further carrying your input.

That badge is generated from the same configuration that decides how each tool runs, so it cannot fall out of step with the code. If a future tool needs a server — for very large files, or for something that cannot run locally — it will say so on its own page, before you use it, and this section will be updated to describe what is sent.

What we collect

No account is required and none is offered, so we hold no name, email address, password or profile. We do not collect the contents of anything you put into a tool.

Like any website, loading a page involves a request from your browser to the server hosting it, and such requests inherently carry technical information including your IP address, the page requested, and your browser and device type. We do not build profiles from it and we do not combine it with anything else.

Analytics

This site uses Google Analytics 4 to understand, in aggregate, which pages and tools people use.

What that measurement is designed to collect is worth setting out either way, because it is the part most privacy policies leave vague. The events are:

  • tool_view — a tool page was opened, with the tool’s identifier, name and category.
  • tool_action — a deliberate command, as one word from a fixed list such as copy, download, clear or generate, with the tool’s identifier.
  • tool_error — a tool rejected its input, as a category such as invalid_json. Never the error message, because a parser’s message can quote your document back.
  • tool_search — a search of the catalogue, as the number of characters typed and the number of tools matched. Never the words.
  • tool_category_select and related_tool_click — which category was chosen, and which tool was followed from which, using identifiers from our own catalogue.

Page views record the path of the page — /tools/json-formatter — and its title. The query string is deliberately removed before the path is sent, because on this site it can contain what you typed into the tool search.

These events are built so that tool content cannot travel inside one. Every value is either an identifier from our catalogue or a single word from a fixed list, and anything else is discarded before sending rather than trimmed to fit. We do not create a user identifier, and we do not send passwords, tokens, email addresses, names or any text you have entered through these events.

Google Analytics is a third-party service, and Google’s own processing is governed by its terms rather than ours. When analytics is enabled, Google receives the events above together with the technical information any web request carries, including your IP address, and may set cookies or similar identifiers in your browser. We cannot and do not claim otherwise on Google’s behalf.

There is no in-page control for turning analytics off at present. The code contains a single consent gate that every event passes through, which is what a consent banner would use, but no such banner has been built. Where consent is legally required, it will be in place before analytics is enabled for that audience. Browser-level controls and extensions that block analytics scripts work on this site as they do on any other.

Advertising

There are no advertisements on bugsTobuild today, and no advertising network is loaded. Nothing on this site currently requests an ad, sets an advertising cookie or builds a profile of you.

The intention is to support the free tools with advertising. The places an ad would sit are already designed — above a tool, between a finished tool and its documentation, and below the cards on catalogue pages — and they are deliberately separate from the tools themselves, so an ad never sits between your input and your result and never receives what you paste.

When advertising is enabled, it will be served by Google AdSense. Advertising providers commonly use cookies or similar technologies to measure and select advertisements, and what Google sets in a particular case depends on its own systems and your settings rather than on anything we control. Google publishes how it uses information from sites that use its services at policies.google.com/technologies/partner-sites. This page will be updated before advertising goes live, and consent will be collected where the law requires it.

Cookies and similar technologies

bugsTobuild sets no cookies of its own. Your theme preference — light or dark — is kept in your browser’s local storage so the site does not flash the wrong colours on your next visit. It stays on your device, is never transmitted, and clearing your browser data removes it.

The third-party services described above may set cookies or similar identifiers when they are enabled. At the time of writing, the services marked active below are the ones that may do so.

Third-party services

These are the external services that receive information about your visit when they are switched on. The many software packages the site is built from are not listed: they run as part of the page and receive nothing.

Google Analytics 4

Enabled

Aggregate measurement of which pages and tools are used.

Receives when enabled: Page paths, the events listed above, and the technical information any web request carries — including your IP address, which Google processes as part of providing the service.

Their privacy information

Google AdSense

Not enabled

Advertising in the reserved placements, once it is switched on.

Receives when enabled: The page an advertisement is requested for, and the technical information any web request carries. Advertising providers commonly use cookies or similar technologies.

Their privacy information

The site is served by a hosting provider, which necessarily processes the requests your browser makes in order to deliver the pages.

How information is used

The technical information a request carries is used to serve the site. Analytics information, when enabled, is used to understand which tools are worth building on and where the catalogue is missing something. Advertising information, when enabled, is used by the advertising provider to select and measure advertisements.

We do not sell information about you, and we do not share it with anyone beyond the services described above.

Data retention

We operate no database and no account system, so there is nothing for us to retain about you. Tool content is never received in the first place.

Where a third-party service is enabled, that service retains what it collects according to its own policies and the settings on the account — Google Analytics data retention, for instance, is configured in the Google Analytics property rather than here.

Security

The site is served over HTTPS, and tool processing happening on your device means the most sensitive thing you handle here — the content you paste — is never in transit to us at all. That is a structural protection rather than a promise about our systems.

No website can guarantee perfect security, and we do not claim to. If you find something that looks like a security problem, please report it; details are on the contact page.

Children

These are developer and text utilities; they are not directed at children and we do not knowingly collect information from them. If you believe a child has provided information through this site, please get in touch and we will look into it.

Your rights

Depending on where you live, you may have rights over personal data held about you — to access it, correct it, delete it, or object to its processing. Because we operate no accounts and hold no database, we normally hold nothing to act on; a request to us will usually be answered by saying exactly that.

Where a third-party service holds information — Google Analytics, or Google’s advertising systems once enabled — requests about that information are handled through that provider, and their privacy pages, linked above, explain how. You can write to bugstobuild@gmail.com either way and we will point you in the right direction.

Changes to this policy

When this policy changes in a way that affects how information is handled, the date at the top of the page changes with it. There is no mailing list and no notification system, so that date is the honest signal, and it is worth checking when something about the site visibly changes — advertising appearing, for example.

Contact

Questions about this policy, or about anything here that does not match what the site does, can go to bugstobuild@gmail.com or through the contact page.