toolember

Security

Last updated: August 24, 2026

How we protect your data

  • All traffic is served over HTTPS; the site and functions run on Cloudflare's network.
  • Most tools run entirely in your browser and send nothing to a server.
  • Sign-in sessions use HttpOnly, Secure, SameSite cookies, so they cannot be read by scripts or sent cross-site.
  • We never store your full card number. Payments are handled by Polar (Merchant of Record).
  • Analytics use a hashed, privacy-preserving visitor key; we do not store raw IP addresses for analytics.
  • Dynamic QR edit access is protected by a high-entropy token or your signed-in account; once a code is saved to an account, editing requires signing in.
  • Abuse controls: rate limits on sign-in and creation, destination-URL safety screening, and the ability to disable malicious links.
  • Secrets and API keys are stored as environment secrets, never in the codebase.

Reporting a vulnerability

If you believe you have found a security issue, please report it responsibly via our contact page with enough detail to reproduce it. Please do not publicly disclose it until we have had a chance to respond.

Reporting abuse

To report a Toolember link used for phishing, malware, or other abuse, see the Acceptable Use Policy.