Who is responsible for your data. This site is operated by MetaSecurity LTDA, a company registered in Brazil under CNPJ 38.660.173/0001-09. It is the controller for everything described below. To exercise any right, or to ask anything about this policy, write to [email protected].
The short version
Almost every tool on this site runs entirely inside your browser. The file you drop into the SVG converter, the PDF you merge, the photo you blur. None of it is uploaded, because there is nothing on our side to upload it to. Those tools are static pages; the processing happens on your own device.
What we do record is that a page was visited, and what people type into the search box at the top. We record it without your IP address, which is turned into an irreversible hash before anything is written down. We do not ask for your name, we do not have accounts, and we do not sell anything.
The part that involves other companies is advertising. Google serves the ads that pay for the site, and Google Analytics measures the audience. Both use cookies, both are covered in detail below, and both can be switched off from your side.
Who this policy covers. Every tool published under
makeshortwork.com, including all pages under a subdirectory such as
/paint-calculator/. Where
one specific tool behaves differently, it is named explicitly.
What never leaves your device
This is the most important section of this policy, and it is the one most privacy policies get to bury. The majority of the tools in this network are static pages with JavaScript that runs locally. There is no upload step and no server-side processing.
Concretely, when you use the SVG to PNG converter, the PDF tools, the image beautifier, the EXIF viewer, the HEIC converter, the face blurrer, the pixelator, the hash generator, the JWT decoder, the base64 encoder or any of the calculators, the following is true:
- The file or text you provide is read by your own browser and stays there.
- It is never transmitted to us, because no request carrying it is ever made.
- We could not retrieve it if we wanted to, and we could not hand it to anyone else.
- Closing the tab discards it.
You do not have to take our word for it. Open your browser's developer tools, switch to the Network tab, and use any of those tools. You will see requests for the page itself, for the advertising scripts, and for the one-line visit beacon described below, and nothing carrying your content.
The exceptions are named, and there are only a few of them. They are listed under third parties.
What we record about visits
Every page in the network loads a small script that sends one message when the page opens. That message creates a single row in our own database. This is our analytics; it is self-hosted, and it does not use a cookie at all. Here is every field it writes, with nothing left out.
| Field | What it holds | Example |
|---|---|---|
| Tool | Which tool you opened, taken from the first part of the address | qr-generator |
| Language | English or Portuguese | en |
| Path | The page address within this site, without any query string we add | /paint-calculator/ |
| Referrer host | Only the host name of the site you came from, never the full address. Knowing you arrived from a search engine is useful; the search you ran on someone else's site is not ours to keep. Internal navigation is stored as empty. | google.com |
| Visitor hash | A SHA-256 hash of your IP address, your browser's user-agent string and a secret salt, truncated to 32 characters. It exists so we can tell four page views by one person from four people. The IP address itself is discarded and never written anywhere. The hash cannot be turned back into an IP address. | 3f9a1c… |
| Country | A two-letter country code supplied by our CDN. Country only, no region, no city, no coordinates. | US |
| Bot flag | Whether the request looked automated, and the rule that decided it | true |
| Load time | How many milliseconds the page took to start rendering, measured in your browser | 412 |
| Timestamp | When it happened | 2026-08-17 14:02Z |
That is the complete list. There is no field for your IP address, none for your user-agent, none for a screen size, none for a device fingerprint, and none for the full URL you came from.
The search box
The search box in the header searches our own tools. When you use it, we record the term you typed, whether it matched anything, which page you searched from, the language, and the same visitor hash. We do this for one reason: the terms that match nothing are the list of tools we have not built yet.
Please treat that box as public. It is a site search, not a private notepad. Do not type anything into it you would not want recorded.
What we do not collect
- Your IP address in readable form. It is hashed on arrival and the original is discarded.
- Anything you put into a tool. Files, text, numbers, images. The calculators and converters do not report what you entered or what came out.
- Your name, email address or phone number, unless you email us.
- Precise location. Country code only.
- Anything about you from other websites. We run no tracking pixel of our own and we buy no data.
Advertising and measurement
This site is free and is paid for by advertising. Two Google products are involved, and both set cookies in your browser.
Google AdSense selects and displays the ads. Google and its advertising partners may use cookies and similar identifiers to limit how often you see the same ad, to measure whether an ad worked, and, where permitted, to select ads based on your interests and your browsing on other sites. We do not receive your identity from Google. We see aggregate figures: how many impressions a page produced and what they earned.
Google Analytics 4 measures the audience: how many people arrive, which pages they land on, roughly where in the world they are, and whether they leave immediately. It sets its own cookies to recognise a returning browser.
Google acts as an independent controller for the data it collects through these products, which means Google's own privacy terms govern it in addition to this policy. The full list of cookies, what each one is for and how long it lasts is on the cookie page.
Turning personalised advertising off
These controls are Google's, they work across every site, and they do not depend on us:
- My Ad Center: switch off personalised ads on your Google account and see why you are being shown a given ad.
- Google ad settings: the same control for a browser that is not signed in.
- Google Analytics opt-out add-on: stops Analytics collecting anything from your browser, on every site that uses it.
- YourAdChoices and NAI opt-out: industry-wide opt-out for participating advertising networks.
- Your browser's own settings will block third-party cookies entirely. The tools will keep working; nothing on this site requires a cookie to function.
Third parties we involve
These are all of them. Where a tool calls an outside service from your browser, that service necessarily sees your IP address, because that is how the internet delivers a reply. We have flagged those explicitly.
| Who | Why | Where | Sees your IP |
|---|---|---|---|
| Google (AdSense, Analytics) | Advertising and audience measurement | Every page | Yes |
| Cloudflare | CDN and protection against attacks. Traffic passes through it, so it processes connection data and keeps short-lived operational logs. | Every page | Yes |
| Oracle Cloud | The servers this network runs on | Every page | Yes |
| CoinGecko | Live cryptocurrency prices | Crypto profit calculator | Yes |
| Frankfurter | Reference exchange rates | Currency converter | Yes |
| ipwho.is | Looks up what an IP address reveals, which is the entire point of those two tools | What is my IP, My location | Yes |
| Valve (Steam) | Sign-in and item prices | CS2 skin alerts | Yes |
| Resend | Delivers alert emails | CS2 skin alerts | No |
The one tool with an account
CS2 skin alerts is the single tool in this network with a server-side component that stores something about you. Everything else is anonymous. If you sign in there, we store:
- Your Steam ID, your Steam display name and your Steam avatar URL.
- The email address you gave us for alerts, and whether you confirmed it.
- The alerts you created: item name, target price, currency and direction.
- When you first signed in and when you were last seen.
Sign-in goes through Steam's own OpenID. We never see your Steam password. Your session is
a single cookie called sid, signed so it cannot be forged, marked HttpOnly so
scripts cannot read it, and valid for 30 days. Signing out clears it immediately.
Alerts only start sending after you click the confirmation link in the first email. Otherwise the tool would be a way to send mail to a stranger's address. You can delete any alert from within the tool. To delete your account and everything attached to it, email us.
How long we keep things
| What | How long |
|---|---|
| Visit records and search terms | Kept for as long as they are useful for traffic analysis and for deciding what to build next. They contain no IP address and no name, so they do not identify you. |
| Uptime checks | Deleted automatically after 30 days |
| CS2 skin alerts account and alerts | Until you delete the alert, or until you ask us to delete the account |
| Emails you send us | As long as needed to deal with what you wrote about, and then a reasonable period for our records |
| Google cookies | Set by Google, governed by Google's retention, see the cookie page |
| Cloudflare operational logs | Short-lived, controlled by Cloudflare |
If you are in the EU, the EEA or the UK
The GDPR and the UK GDPR give you specific rights. The legal bases we rely on are these:
- Legitimate interest for our own visit measurement and search logging. The interest is understanding whether the site works and what to build next; the impact on you is minimal because no IP address and no identifier that survives outside our database is stored.
- Consent for advertising and analytics cookies. Cookies that are not strictly necessary require your consent under the ePrivacy Directive, and personalised advertising requires it under the GDPR as well.
- Performance of a contract for the CS2 skin alerts account. We cannot send you an alert without storing what to alert you about.
Consent for advertising. Google requires publishers whose traffic includes the EEA or the UK to obtain consent through a certified consent management platform before personalised advertising cookies are set.
This notice is not active yet. We are stating that plainly rather than describing a mechanism that is not running. Until it is enabled, do not treat this site as compliant for EEA, UK or Swiss visitors, and if you are visiting from there, use Google's own controls linked below to turn off ad personalisation. We will update this page, with a new effective date, on the day the notice goes live.
Your rights, and how to use them:
- Access: ask what we hold about you.
- Rectification: have something wrong corrected.
- Erasure: have it deleted.
- Restriction and objection: tell us to stop a particular use, including our legitimate-interest processing.
- Portability: get a copy in a machine-readable format.
- Withdraw consent at any time, without that affecting what was lawful before.
- Complain to your national data protection authority, or to the ICO in the UK.
Email us using the address on the contact page and we will answer within one month.
An honest limitation. For ordinary browsing we hold no identifier that can be linked back to you. We keep a salted hash, not your IP address, and the hash cannot be reversed. So if you ask us to find and delete "your" visit records, we genuinely cannot locate them, not as a refusal, but because the design that protects you also makes you unfindable. The GDPR anticipates this: where a controller cannot identify a data subject, the access and erasure rights do not require it to collect more data just to be able to. For the CS2 skin alerts account, which does identify you, all of the rights above apply normally and we can act on them.
If you are in California
The CCPA, as amended by the CPRA, gives California residents specific rights. In the last twelve months the categories of personal information involved here were identifiers (a hashed derivation of an IP address, and cookie identifiers set by Google), internet activity (pages viewed, referring site, search terms) and coarse geolocation (country). They come from you, from your browser and from our CDN, and they are used to run the site, measure the audience and sell advertising space.
Your rights:
- Know what is collected, why, and who receives it. This page is that disclosure.
- Delete what we hold about you.
- Correct anything inaccurate.
- Opt out of sale or sharing.
- Not be discriminated against for exercising any of these. Nothing on this site changes because you opted out.
On "sale" and "sharing". We do not sell personal information for money. But the CPRA defines "sharing" to include disclosing personal information for cross-context behavioural advertising, and serving personalised ads through Google meets that definition. We say so plainly rather than hiding behind the fact that no money changes hands for your data specifically.
To opt out, use Google's ad settings to disable personalised advertising, or send a Global Privacy Control signal from your browser, which we and our advertising partners treat as a valid opt-out request. We do not knowingly sell or share the personal information of anyone under 16.
If you are in Brazil
The LGPD applies to visitors in Brazil, and the Portuguese version of this page is written for that audience. The rights are equivalent: confirmation of processing, access, correction, anonymisation or deletion, portability, information about with whom data is shared, and the right to withdraw consent. Use the same contact address.
Children
This network is not directed to children. The tools are aimed at adults doing work, converting a file, sizing a beam, checking a payroll number, and nothing here is designed to appeal to a child.
We do not knowingly collect personal information from anyone under 13, as defined by the US Children's Online Privacy Protection Act, and we ask that children under 13 do not use the site. If you are a parent or guardian and believe your child has provided us with personal information, email us and we will delete it. Advertising served on this site is not tagged as child-directed, which is another reason children should not be using it.
Where your data goes
Our servers and our third parties are largely in the United States, and Google, Cloudflare and Oracle all operate globally. If you are in the EEA or the UK, that means your data may be transferred outside your country. Those transfers rely on the mechanisms the providers maintain. The EU–US Data Privacy Framework where applicable, and Standard Contractual Clauses otherwise.
Security
Everything is served over HTTPS. Traffic reaches our servers through Cloudflare, and the origin only accepts connections from it. The administrative panel is behind authentication with brute-force protection. Your IP address is hashed before storage. The session cookie for CS2 skin alerts is signed, HttpOnly and Secure.
None of this is a guarantee. No site can promise it will never be breached, and a policy that claims otherwise is not being straight with you. What we can say is that the amount of personal data available to lose here is deliberately small.
Changes to this policy
If we change how the tools handle data, this page changes with them and the effective date at the top moves. Material changes, a new category of data, a new third party, will be announced on the site itself and not only by editing this page quietly. The version in effect is always the one you are reading.
Contact
For anything in this policy, including a rights request, write to us using the details on the contact page.