Security
Last updated: August 24, 2026
How we protect your data
- All traffic is served over HTTPS; the site and functions run on Cloudflare's network.
- Most tools run entirely in your browser and send nothing to a server.
- Sign-in sessions use HttpOnly, Secure, SameSite cookies, so they cannot be read by scripts or sent cross-site.
- We never store your full card number. Payments are handled by Polar (Merchant of Record).
- Analytics use a hashed, privacy-preserving visitor key; we do not store raw IP addresses for analytics.
- Dynamic QR edit access is protected by a high-entropy token or your signed-in account; once a code is saved to an account, editing requires signing in.
- Abuse controls: rate limits on sign-in and creation, destination-URL safety screening, and the ability to disable malicious links.
- Secrets and API keys are stored as environment secrets, never in the codebase.
Reporting a vulnerability
If you believe you have found a security issue, please report it responsibly via our contact page with enough detail to reproduce it. Please do not publicly disclose it until we have had a chance to respond.
Reporting abuse
To report a Toolember link used for phishing, malware, or other abuse, see the Acceptable Use Policy.