Local tools and input content
The core text, developer, image and ecommerce operations run in your browser. We do not automatically upload text, code, images, tables, calculator inputs or results in order to run these tools.
When you refresh or close a page, temporary free-tool content follows the browser page lifecycle. The optional QR Workspace is a separate server-hosted product. Free-tool input is not saved to an account unless you register and actively use the workspace.
When you actively select “Save tool,” localStorage key kit_favorites_v1 stores at most 24 public tool IDs, titles and site paths so the home page can restore your favorites. It contains no tool input, result, visitor identity or timestamp and is never sent to the server. Clear favorites or this site’s browser data to delete it.
Strictly same-origin anonymous visits and completions
Each page load may send only two boolean flags, u and d, to the same-origin /v endpoint. They count page views, current-tab session visitors and Pacific-calendar-day visitors; no page path is sent. Valid tool completions continue through the isolated /e endpoint with fixed event, tool, language, coarse source and session-first fields.
Visit and completion logs never record or transmit a name, email, tool input, result, free text, raw IP address, User-Agent, full referrer, cookie, fingerprint or visitor ID. /v stays isolated from /e, suggestions, AI, advertising, feedback and profit evidence. Raw visit and event logs are kept for no more than 90 days and produce identifier-free aggregates only.
sessionStorage key kit_seen stores only whether this tab has counted one session visit. localStorage key kit_day_seen stores only one YYYY-MM-DD Pacific date and is overwritten on a later day. Bots, release checks, Global Privacy Control, Do Not Track and this tab’s opt-out are excluded. QR Workspace and billing use separate user_id, subscription and quota records. Anonymous history is never backfilled into or joined with an account.
QR Workspace account, content and billing data
When you actively create a QR Workspace account, 321Kit stores the account email, display information, a one-way password hash, irreversible session and verification-token digests, workspace membership, and the QR codes, hosted pages, forms, media, submissions, version history and aggregate statistics that you choose to create. Plain passwords are not stored. Never send a password or verification code to support.
When Pro checkout is enabled, 321Kit stores the Paddle customer, transaction, subscription and adjustment identifiers needed to verify workspace entitlements, together with plan, status, amount, currency, billing period and event timestamps. Paddle is the Merchant of Record and handles checkout, payment methods and applicable transaction taxes. 321Kit does not receive or store full card numbers or security codes. Paddle processes buyer and payment data under its published policies and checkout terms.
Account and workspace data is used to provide, protect, recover and support the server features you select. Billing records are used to grant or revoke entitlements, handle refunds and disputes, reconcile state, prevent duplicate processing and meet legal obligations. Data is retained as needed to provide the service, resolve disputes and comply with applicable law. Use the Support page to make an applicable data-rights request.
The support form collects the reply email, issue type and message that you actively enter, then sends them through the 321Kit mail service to a private support inbox so the request can be answered. Form content is not written to the QR Workspace database. Email copies are retained as needed to handle the request, resolve disputes and comply with applicable law. Do not submit passwords, verification codes, full card numbers, identity documents or secrets.
QR Workspace destinations and scan aggregates
Only when you actively create a code in the workspace does 321Kit store its HTTPS redirect destination or hosted-page relationship, state, lifetime scan total and UTC-day aggregates. No-account static QR generation remains entirely in the browser and uploads no content.
Workspace QR codes never store individual scan records, IP addresses, User-Agents, referrers, cookies, device information, fingerprints or visitor IDs. A redirect code returns a direct 302 to your HTTPS destination without an advertising or waiting page.
Codes are managed through account sessions and workspace authorization, not the former Beta private #fragment link. Permanent deletion keeps a non-reusable public-code tombstone that returns 410 forever.
Optional anonymous feedback
You may choose only a predefined feedback reason or actively add a note of up to 200 characters. Tool input is never attached automatically. Do not put names, email addresses, order numbers, tool input or other personal information in a note.
Optional notes go to a separate same-origin endpoint on 321kit.com. Raw anonymous suggestions are kept for no more than 30 days and used only to fix and improve tools. Summaries are not presented as public ratings, revenue or completion counts.
If advertising is enabled later
321Kit publishes a google-adsense-account meta tag and a root ads.txt seller declaration for Google AdSense site review. These static identifiers do not load advertising code, display an ad unit, set advertising cookies or activate a CMP prompt.
321Kit currently loads no third-party ad script. Reserving a possible ad placement does not itself send data to an ad platform. Ads can only be enabled separately after publisher, slot and applicable consent-management requirements are complete.
If third-party advertising is introduced, an ad or consent provider may process an IP address, device and browser information, approximate region, the current page URL, ad interactions, and cookies, local storage or similar identifiers—depending on applicable law and your choices—for delivery, frequency control, measurement, fraud prevention or, with consent, personalization. 321Kit will not intentionally pass tool inputs or outputs to the ad provider.
Where consent is required, a clear control will be presented before optional advertising storage or personalized processing and will let you accept, reject or later change eligible choices. Before ads go live, this page will identify the provider, purposes, retention and choice control.
Optional AI enhancement beta (only when you choose it)
The current beta includes JSON/YAML repair. Local validation, regex testing and every ecommerce calculation remain independently usable. Whitelisted content goes to MiniMax through the 321Kit same-origin proxy only after you open the relevant AI panel, review that request's send list, consent again and actively send it.
JSON/YAML requests send at most 10,000 characters. Regex sends only a requirement or expression up to 500 characters and excludes test text by default. Ecommerce diagnosis sends only frozen structured result metrics calculated locally—not currency, store information, raw form text or free text. Do not send keys, tokens, passwords or personal information.
AI suggestions never overwrite local results automatically. Regex and data repair are locally validated, and ecommerce suggestions cannot alter the formula. The 321Kit proxy does not cache or log prompts, responses, input content or input hashes. Standard security logs may record the request IP and /ai/ path, but not the POST body. MiniMax processes received content under its applicable policies.