Privacy Policy
How information is handled when you use Utilbox.
Last updated: September 20, 2026
About this policy
Utilbox operates utilbox.org. This policy describes information processed to provide our tools, accounts, purchases and support. Data handling depends on the feature you use: some tools work locally, while sharing, publishing, AI extraction and webhook workflows require server processing.
Tool inputs and hosted workflows
- Local utilities: Tools such as JSON formatting perform their core conversion in your browser. Their input is not uploaded for that conversion. Optional sharing, saving or other hosted actions have different data handling.
- OmniExtract AI: Documents you upload, extraction instructions and selected pages are processed using our backend, storage providers and Google Gemini. We store processing records and results to deliver the extraction and, where available, account history. This feature does not run entirely in your browser.
- Share Text: Your browser encrypts text before uploading it. Our service stores encrypted content, expiry information and share metadata. The normal sharing flow puts the decryption key in the link fragment after #, which is not part of the HTTP request. Anyone who receives the complete link may be able to read the share.
- Markdown publishing: Publishing sends your document to our service. A published link makes that document accessible to people who can open the link. Previewing a document locally and publishing it are separate actions.
- Webhooks and network tools: These features may process endpoint addresses, request headers, payloads, response details or an IP address. Captured webhook requests and saved histories use hosted storage. Avoid including credentials or personal information that is not needed for your task.
Only upload or share information you are authorized to provide. Review each tool's instructions before submitting confidential material.
Account, payment and operational information
Signing in provides account information such as your email, profile and authentication identifiers through Firebase Authentication. We use account and transaction records to manage credits, feature access, purchases, refunds and support. Paddle handles purchase checkout; we receive transaction status and identifiers needed to fulfill purchases.
Our infrastructure and security services process connection and device information, request logs and abuse-prevention signals. We also process messages you send to support. These records help operate the service, investigate failures and prevent misuse.
Cookies, local storage and analytics
Local storage and cookies support functions such as sign-in, preferences and usage limits. Optional Google Analytics collection is controlled by the cookie notice. You can reject it and continue using the tools. Use "Cookie preferences" in the footer to change your choice. Rejecting optional analytics stops future collection by our analytics integration; you can also remove existing cookies using your browser settings.
When enabled, Google Analytics processes usage information such as pages visited, tool interactions and device/browser details. We also use Cloudflare Web Analytics for aggregate website performance and usage measurement. These services are separate from the data needed to process a tool request.
Google advertising and your choices
Utilbox may display Google AdSense advertising when available. When advertising is active, Google and other third-party advertising vendors may use cookies based on your previous visits to this and other websites. Google advertising cookies allow Google and its partners to personalize advertisements using that browsing activity, subject to applicable consent.
You can manage personalized advertising in Google My Ad Center and review how Google uses information from partner sites. Other participating advertising vendors provide opt-out choices through YourAdChoices.
Where an advertising consent message is shown, use its privacy controls to manage your advertising choices. The optional analytics choice in our cookie notice is separate from advertising consent. Declining personalized advertising does not necessarily remove all ads.
Service providers
We use providers to operate the features described above:
- Google and Firebase: authentication, application data, Gemini processing, optional analytics and advertising. See Google's privacy policy.
- Supabase: hosted database and storage for extraction workflows.
- Upstash: temporary storage, queues and rate limiting.
- Vercel and Cloudflare: application hosting, network delivery, security and website measurement.
- Paddle: purchase checkout and payment processing.
Processing may take place in countries other than your own. The information sent to a provider depends on the feature requested. We do not sell the documents or text you submit to tools.
Retention and deletion
Retention varies by feature. Encrypted shares have the expiry selected when created, and burn-after-read shares become unavailable after the supported read flow consumes them. Extraction workflows keep job records and results; uploaded source files are scheduled for cleanup after processing. Cleanup can be delayed by processing or infrastructure errors.
Where history or publishing controls provide deletion or revocation, you can use those controls to remove the corresponding record or published access. This does not necessarily remove related payment, security or operational records. Such records may be retained for service operation, dispute handling or legal obligations. Contact us about information you cannot remove through the available controls.
Your rights and security
Depending on your location, you may have rights to access, correct or delete personal information, restrict its use or withdraw consent. Contact us with your request; we may need to verify your identity before acting. HTTPS and access controls help protect information, but no service can promise absolute security. Link recipients can retain copies of content they have already accessed.
Contact and updates
For privacy requests, email [email protected] or use our contact page.
We update this page when our practices change and revise the date above.