Skip to the text
makeshortwork.com Privacy Policy

Privacy Policy

This policy describes what this network of tools records, what it never records, and what you can do about it. It is written to match what the code actually does.

In effect since .

Who is responsible for your data. This site is operated by MetaSecurity LTDA, a company registered in Brazil under CNPJ 38.660.173/0001-09. It is the controller for everything described below. To exercise any right, or to ask anything about this policy, write to [email protected].

The short version

Almost every tool on this site runs entirely inside your browser. The file you drop into the SVG converter, the PDF you merge, the photo you blur. None of it is uploaded, because there is nothing on our side to upload it to. Those tools are static pages; the processing happens on your own device.

What we do record is that a page was visited, and what people type into the search box at the top. We record it without your IP address, which is turned into an irreversible hash before anything is written down. We do not ask for your name, we do not have accounts, and we do not sell anything.

The part that involves other companies is advertising. Google serves the ads that pay for the site, and Google Analytics measures the audience. Both use cookies, both are covered in detail below, and both can be switched off from your side.

Who this policy covers. Every tool published under makeshortwork.com, including all pages under a subdirectory such as /paint-calculator/. Where one specific tool behaves differently, it is named explicitly.

What never leaves your device

This is the most important section of this policy, and it is the one most privacy policies get to bury. The majority of the tools in this network are static pages with JavaScript that runs locally. There is no upload step and no server-side processing.

Concretely, when you use the SVG to PNG converter, the PDF tools, the image beautifier, the EXIF viewer, the HEIC converter, the face blurrer, the pixelator, the hash generator, the JWT decoder, the base64 encoder or any of the calculators, the following is true:

You do not have to take our word for it. Open your browser's developer tools, switch to the Network tab, and use any of those tools. You will see requests for the page itself, for the advertising scripts, and for the one-line visit beacon described below, and nothing carrying your content.

The exceptions are named, and there are only a few of them. They are listed under third parties.

What we record about visits

Every page in the network loads a small script that sends one message when the page opens. That message creates a single row in our own database. This is our analytics; it is self-hosted, and it does not use a cookie at all. Here is every field it writes, with nothing left out.

FieldWhat it holdsExample
Tool Which tool you opened, taken from the first part of the address qr-generator
Language English or Portuguese en
Path The page address within this site, without any query string we add /paint-calculator/
Referrer host Only the host name of the site you came from, never the full address. Knowing you arrived from a search engine is useful; the search you ran on someone else's site is not ours to keep. Internal navigation is stored as empty. google.com
Visitor hash A SHA-256 hash of your IP address, your browser's user-agent string and a secret salt, truncated to 32 characters. It exists so we can tell four page views by one person from four people. The IP address itself is discarded and never written anywhere. The hash cannot be turned back into an IP address. 3f9a1c…
Country A two-letter country code supplied by our CDN. Country only, no region, no city, no coordinates. US
Bot flag Whether the request looked automated, and the rule that decided it true
Load time How many milliseconds the page took to start rendering, measured in your browser 412
TimestampWhen it happened2026-08-17 14:02Z

That is the complete list. There is no field for your IP address, none for your user-agent, none for a screen size, none for a device fingerprint, and none for the full URL you came from.

The search box

The search box in the header searches our own tools. When you use it, we record the term you typed, whether it matched anything, which page you searched from, the language, and the same visitor hash. We do this for one reason: the terms that match nothing are the list of tools we have not built yet.

Please treat that box as public. It is a site search, not a private notepad. Do not type anything into it you would not want recorded.

What we do not collect

Advertising and measurement

This site is free and is paid for by advertising. Two Google products are involved, and both set cookies in your browser.

Google AdSense selects and displays the ads. Google and its advertising partners may use cookies and similar identifiers to limit how often you see the same ad, to measure whether an ad worked, and, where permitted, to select ads based on your interests and your browsing on other sites. We do not receive your identity from Google. We see aggregate figures: how many impressions a page produced and what they earned.

Google Analytics 4 measures the audience: how many people arrive, which pages they land on, roughly where in the world they are, and whether they leave immediately. It sets its own cookies to recognise a returning browser.

Google acts as an independent controller for the data it collects through these products, which means Google's own privacy terms govern it in addition to this policy. The full list of cookies, what each one is for and how long it lasts is on the cookie page.

Turning personalised advertising off

These controls are Google's, they work across every site, and they do not depend on us:

Third parties we involve

These are all of them. Where a tool calls an outside service from your browser, that service necessarily sees your IP address, because that is how the internet delivers a reply. We have flagged those explicitly.

WhoWhyWhereSees your IP
Google (AdSense, Analytics) Advertising and audience measurement Every page Yes
Cloudflare CDN and protection against attacks. Traffic passes through it, so it processes connection data and keeps short-lived operational logs. Every page Yes
Oracle Cloud The servers this network runs on Every page Yes
CoinGecko Live cryptocurrency prices Crypto profit calculator Yes
Frankfurter Reference exchange rates Currency converter Yes
ipwho.is Looks up what an IP address reveals, which is the entire point of those two tools What is my IP, My location Yes
Valve (Steam) Sign-in and item prices CS2 skin alerts Yes
Resend Delivers alert emails CS2 skin alerts No

The one tool with an account

CS2 skin alerts is the single tool in this network with a server-side component that stores something about you. Everything else is anonymous. If you sign in there, we store:

Sign-in goes through Steam's own OpenID. We never see your Steam password. Your session is a single cookie called sid, signed so it cannot be forged, marked HttpOnly so scripts cannot read it, and valid for 30 days. Signing out clears it immediately.

Alerts only start sending after you click the confirmation link in the first email. Otherwise the tool would be a way to send mail to a stranger's address. You can delete any alert from within the tool. To delete your account and everything attached to it, email us.

How long we keep things

WhatHow long
Visit records and search terms Kept for as long as they are useful for traffic analysis and for deciding what to build next. They contain no IP address and no name, so they do not identify you.
Uptime checks Deleted automatically after 30 days
CS2 skin alerts account and alerts Until you delete the alert, or until you ask us to delete the account
Emails you send us As long as needed to deal with what you wrote about, and then a reasonable period for our records
Google cookies Set by Google, governed by Google's retention, see the cookie page
Cloudflare operational logs Short-lived, controlled by Cloudflare

If you are in the EU, the EEA or the UK

The GDPR and the UK GDPR give you specific rights. The legal bases we rely on are these:

Consent for advertising. Google requires publishers whose traffic includes the EEA or the UK to obtain consent through a certified consent management platform before personalised advertising cookies are set.

This notice is not active yet. We are stating that plainly rather than describing a mechanism that is not running. Until it is enabled, do not treat this site as compliant for EEA, UK or Swiss visitors, and if you are visiting from there, use Google's own controls linked below to turn off ad personalisation. We will update this page, with a new effective date, on the day the notice goes live.

Your rights, and how to use them:

Email us using the address on the contact page and we will answer within one month.

An honest limitation. For ordinary browsing we hold no identifier that can be linked back to you. We keep a salted hash, not your IP address, and the hash cannot be reversed. So if you ask us to find and delete "your" visit records, we genuinely cannot locate them, not as a refusal, but because the design that protects you also makes you unfindable. The GDPR anticipates this: where a controller cannot identify a data subject, the access and erasure rights do not require it to collect more data just to be able to. For the CS2 skin alerts account, which does identify you, all of the rights above apply normally and we can act on them.

If you are in California

The CCPA, as amended by the CPRA, gives California residents specific rights. In the last twelve months the categories of personal information involved here were identifiers (a hashed derivation of an IP address, and cookie identifiers set by Google), internet activity (pages viewed, referring site, search terms) and coarse geolocation (country). They come from you, from your browser and from our CDN, and they are used to run the site, measure the audience and sell advertising space.

Your rights:

On "sale" and "sharing". We do not sell personal information for money. But the CPRA defines "sharing" to include disclosing personal information for cross-context behavioural advertising, and serving personalised ads through Google meets that definition. We say so plainly rather than hiding behind the fact that no money changes hands for your data specifically.

To opt out, use Google's ad settings to disable personalised advertising, or send a Global Privacy Control signal from your browser, which we and our advertising partners treat as a valid opt-out request. We do not knowingly sell or share the personal information of anyone under 16.

If you are in Brazil

The LGPD applies to visitors in Brazil, and the Portuguese version of this page is written for that audience. The rights are equivalent: confirmation of processing, access, correction, anonymisation or deletion, portability, information about with whom data is shared, and the right to withdraw consent. Use the same contact address.

Children

This network is not directed to children. The tools are aimed at adults doing work, converting a file, sizing a beam, checking a payroll number, and nothing here is designed to appeal to a child.

We do not knowingly collect personal information from anyone under 13, as defined by the US Children's Online Privacy Protection Act, and we ask that children under 13 do not use the site. If you are a parent or guardian and believe your child has provided us with personal information, email us and we will delete it. Advertising served on this site is not tagged as child-directed, which is another reason children should not be using it.

Where your data goes

Our servers and our third parties are largely in the United States, and Google, Cloudflare and Oracle all operate globally. If you are in the EEA or the UK, that means your data may be transferred outside your country. Those transfers rely on the mechanisms the providers maintain. The EU–US Data Privacy Framework where applicable, and Standard Contractual Clauses otherwise.

Security

Everything is served over HTTPS. Traffic reaches our servers through Cloudflare, and the origin only accepts connections from it. The administrative panel is behind authentication with brute-force protection. Your IP address is hashed before storage. The session cookie for CS2 skin alerts is signed, HttpOnly and Secure.

None of this is a guarantee. No site can promise it will never be breached, and a policy that claims otherwise is not being straight with you. What we can say is that the amount of personal data available to lose here is deliberately small.

Changes to this policy

If we change how the tools handle data, this page changes with them and the effective date at the top moves. Material changes, a new category of data, a new third party, will be announced on the site itself and not only by editing this page quietly. The version in effect is always the one you are reading.

Contact

For anything in this policy, including a rights request, write to us using the details on the contact page.