Privacy Policy
Last updated: July 2026
1. Overview
Aarunya Apps (“we”, “our”, “the Service”) is a collection of privacy-first browser-based developer tools. Our core principle is simple: your data never leaves your browser. All tool logic runs entirely client-side. We do not operate servers that receive, process, or store any content you enter into our tools.
2. Information We Do Not Collect
We do not collect, transmit, or store:
- Any content you paste, type, or upload into our tools (e.g. .env files, schemas, config files, email HTML)
- IP addresses tied to individual usage
- Browser fingerprints
- Cookies of any kind (we are cookie-free by design)
- Local storage or session storage data beyond: (a) daily usage counters for free-tier rate limits, (b) your Pro license key identifier, (c) an anonymous analytics identifier (see section 3), and (d) encrypted saved outputs (Pro only, local only — see section 4a)
The one exception: if you give us your email address on purpose — joining a waitlist or subscribing to Deliverability Monitoring — we store it. Section 4b explains exactly what is kept and how to delete it.
3. Analytics
We use Cloudflare Web Analytics for aggregate page-view counts. Cloudflare Web Analytics is cookieless, does not use fingerprinting, and does not track you across sites. No personal data is associated with analytics events. We do not use Google Analytics, Facebook Pixel, or any other behavioural tracking service.
We also use PostHog (EU-hosted)for anonymous product analytics — which tools are used and where upgrade prompts appear. It is cookieless (a random anonymous ID in your browser's localStorage), has session recording and autocapture disabled, and respects the Do Not Track browser setting. The content you put into tools is never captured — only the fact that a tool was used. See PostHog's privacy policy.
4. Tools That Make Network Requests
Most tools make zero network requests. The exceptions, and exactly what each sends:
- AI Regex Generator — the plain-English description you type is forwarded to OpenRouter via our Cloudflare Worker proxy. Only the description text is sent — never the strings you test against, file contents, or personal data. We do not log or persist prompts or responses.
- DNS tools (MX Lookup, BIMI Validator, DNS Email Diagnostics) — the domain name you enter is resolved via Cloudflare DNS-over-HTTPS. Only the domain name is sent; results are displayed in your browser and not stored.
- OG Tester and Meta Tags Analyzer(URL mode) — the URL you enter is fetched through our Cloudflare Worker proxy so the page's tags can be read. The URL is not logged or stored; paste-HTML mode makes no requests at all.
4a. Pro Saved Outputs (Local Storage)
Pro subscribers can save tool outputs for later use. Saved outputs are stored exclusively in your browser's IndexedDB using client-side AES-GCM encryption. The encryption key is derived from a device-local identifier stored in localStorage. Saved outputs are never sent to our servers. Clearing your browser storage permanently deletes them. We cannot recover them.
4b. Waitlists & Deliverability Monitoring
Two features store data you explicitly give us, on Cloudflare's infrastructure:
- Waitlists — your email address and which waitlist you joined, used only to notify you about that feature.
- Email Deliverability Monitoring— your email address, the domain(s) you monitor, and daily snapshots of that domain's public DNS records (SPF, DMARC, MX, BIMI, blocklist status). Subscriptions are double-opt-in. If you point your DMARC
ruaat your monitoring address, we also process the aggregate reports mailbox providers send about your domain (message counts, sending-server IPs, authentication results — these reports contain no message content) and retain a rolling 30-day summary.
Deletion is self-serve and immediate:every monitoring email includes a one-click “stop monitoring” link that deletes the record, its snapshots, and its report summaries. For waitlist removal, email us (section 11).
5. Payments
Paid subscriptions are processed by Paddle, our Merchant of Record. Paddle collects and stores payment information (card details, billing address) directly. We do not receive or store your payment card details. Paddle's privacy policy governs their data handling.
6. License Keys
Pro license keys are stored in your browser's localStorage. We store only an anonymous key identifier on our servers for validation — no personal data is associated with it.
7. Third-Party Services
- Cloudflare — CDN, Workers runtime, and Web Analytics. Cloudflare may process IP addresses and request headers as part of DDoS protection and routing. Web Analytics is cookieless. See Cloudflare's privacy policy.
- OpenRouter — AI model routing used exclusively by the AI Regex Generator. Only receives the plain-English prompt you type. See section 4 above. See OpenRouter's privacy policy.
- Paddle — Payment processing and subscription management for Pro plans. During checkout, Paddle collects your email address, payment card details, and billing address directly. We never see your card number. Paddle issues your invoice and manages tax compliance. See Paddle's privacy policy.
- Resend — transactional email delivery for license keys, waitlist notifications, and Deliverability Monitoring alerts/digests. Resend processes the recipient address and message content of those emails. See Resend's privacy policy.
- PostHog (EU) — anonymous, cookieless product analytics. See section 3. PostHog's privacy policy.
- Fonts — Space Grotesk, Geist, and JetBrains Mono are loaded via next/font at build time and self-hosted. No runtime requests are made to Google Fonts or any font CDN.
8. Data Retention
Tool inputs exist only in your browser tab and are discarded when you close or clear the page — there is nothing server-side to retain. The exceptions from section 4b: waitlist emails are kept until the feature launches or you ask for removal; monitoring records are kept until you click “stop monitoring” (deletion is immediate); DMARC report summaries roll off automatically after 30 days.
9. Your Rights
Under GDPR, CCPA, and similar regulations, you have the right to access, correct, or delete personal data we hold about you. For tool usage we hold none. For waitlist and monitoring data (section 4b), use the self-serve deletion links or email us and we'll action it promptly. For payment-related data, please contact Paddle directly.
10. Changes to This Policy
We may update this policy as new features are added. The “Last updated” date at the top will reflect any changes. Continued use of the Service after changes constitutes acceptance.
11. Contact
For privacy questions or concerns, contact us at aarunyatechnmedia@gmail.com.