Skip to content
CarefulKit
Ctrl K

Privacy & safe use

What stays on this device, what can leave, and how to protect your files.

Reviewed August 27, 2026

Tool content stays here

Tools process your text, files and results in this browser, not on CarefulKit servers.

Source files stay unchanged

CarefulKit reads selected files and creates a separate result. It does not write back to them.

You control exports

A result leaves the page only when you copy, download, print or share it.

Before deleting, replacing or sharing a file

Local processing reduces one privacy risk; it does not make every result correct or every destination safe.

  1. Keep an independent copy of the original until you have checked the result.
  2. Open the exported file and check every important page, redaction, crop and piece of text.
  3. Confirm the filename, save location and recipient before replacing, submitting or sharing anything.

Tool content and results

The boundary CarefulKit controls, and the limits it cannot remove.

Runs locally

Files and results stay in this browser.

  • Working content stays in this tab’s memory. Only settings you explicitly choose to remember can persist on this device.
  • Processing happens in the page or a Web Worker. There is no data path to a server.
  • Results leave the page only when you copy, download, print or share them.

Important limits

  • Local processing cannot protect a compromised device, browser, extension, clipboard, download folder, backup, printer or recipient.
  • Compression, conversion, OCR, redaction and Local AI results can be incomplete or wrong. Review them before relying on them.
  • CarefulKit is a tool, not a backup service or a substitute for legal, medical, financial, security or compliance review.
  • CarefulKit is provided without a guarantee that every feature or result will meet your needs, to the extent allowed by law. Rights that cannot legally be limited still apply.

Network and outside services

Tool content stays local, but the website, desktop app and browser still have a few visible network boundaries.

Site hosting (Cloudflare)

Loading CarefulKit necessarily reveals ordinary connection details, such as your IP address and browser request, to Cloudflare. Tool content is not included in those requests.

Problem reports are an exception you control

Nothing is sent until you press Send. The dialog shows the fields first. The written report is kept in a private GitHub issue until removed; an optional processed screenshot is stored in Cloudflare R2 for up to 30 days. Cloudflare Turnstile verifies the request.

Browser-managed downloads

Chrome may download Local AI or speech language packs from its provider. CarefulKit cannot read those downloads or their network requests.

Desktop model downloads are your choice

On CarefulKit Desktop, choosing Download & use connects directly to Hugging Face and reveals ordinary connection data such as your IP address, requested model and download time. The verified GGUF file stays in CarefulKit’s Application Support folder until you delete it in Model manager. Conversation content is never included.

Anonymous usage counts

This counts engaged visits and how many times each tool is used. It is used for one purpose: deciding which tools and experiences to improve next.

What may be sent

  • The tool’s id, such as “json-formatter” — not its filename, options, or anything you typed
  • How many times you used it since the last time this was sent
  • Your interface language, such as “en” — only if you have set one; most readers have not, and nothing is sent for this field for them
  • The date — never a time of day
  • At most one engaged visit per tab, after the page is visible for 3 seconds and you use the keyboard or pointer — never what you clicked or typed

CarefulKit stores these as combined daily totals in Cloudflare D1. It does not create a person- or device-level usage record.

Never included in the usage report: what you type, files, results or filenames. CarefulKit adds no account, cookie or app identifier and stores only the daily aggregate fields above. As with any request, Cloudflare can see ordinary connection data.

Loading…

Stored on this device

Preferences are separate from the content you process.

Stored on this device

  • tool_state — tool id, favorite, hidden, use count, shared-count marker, last used, and NanoKit avatar choices.
  • app_settings — theme, language, layout, Local AI and install-prompt choices, and whether usage counts are shared.
  • temporary_content — the Quiet Reader document, translated paragraphs and reading position for refresh recovery; deleted on Back to Reader or after 12 hours.

Not stored by other tools

  • Other tool input, including recordings and transcripts
  • Other file names and file contents
  • Other tool results
  • Tokens, keys and certificates

Your controls

Reduce network access or remove CarefulKit preferences from this browser.

CarefulKit Offline

Save the complete toolbox on this device, then block CarefulKit from using the network.

Checking this device…

The lock covers CarefulKit requests. Chrome may still check for browser updates or download a built-in AI or speech model; CarefulKit cannot see those requests or their contents.

Removes preferences, activity and temporary Quiet Reader recovery copies. Desktop GGUF models are managed separately in Model manager. It does not delete other files already downloaded or shared, submitted problem reports, or browser-managed language and AI packs.