Privacy
Last updated 26 September 2026
What happens to what you paste
Nothing you paste into Formattr leaves your browser. Formatting, validation, detection and conversion run inside an isolated frame whose security policy blocks every outgoing network request. We never receive your input or output, and there is no server that could store it.
Local processing
The editor and every formatter are served as static files from a separate origin, ws.formattr.com. Once loaded, that frame can only fetch more of its own static files — the formatter for a language you use for the first time, for example. Its Content Security Policy sets connect-src 'self', and that origin has no endpoint that accepts data, so there is nowhere for content to go.
- Your content lives in the memory of the current tab. When you move between tools with Next actions it is handed over in memory.
- To survive a reload, a copy of up to 2 MB is kept in the frame's session storage. The browser deletes it when you close the tab.
- If you switch on Remember my last input for a tool, that input is kept in the frame's local storage on this device until you clear it. It is off by default.
- Content is never put in a URL. Links you copy from the address bar carry settings such as indent or dialect, never content.
The two-origin design
Formattr is two static sites. formattr.com serves the pages you read, search, and — on some pages — ads and privacy-friendly analytics. The workspace is a cross-origin iframe from ws.formattr.com. The two talk through a small, validated message protocol that carries tool ids, settings and analytics event names. Content is never part of a message.
What is stored, and where
| Data | Stored? | Where | Retention |
|---|---|---|---|
| Pasted input and output | No persistent storage | Frame memory; session storage only for reload recovery (≤ 2 MB) | Until the tab closes |
| Tool settings, theme, splitter position, word wrap | Yes | Local storage on ws.formattr.com | Until you clear it |
| Recent and favourite tools (tool ids only) | Yes | Local storage on formattr.com | Until cleared with “Clear history” |
| Analytics events | Yes | Privacy-friendly, cookieless analytics | 12 months, aggregated |
| Ad data | Per Google AdSense | formattr.com pages only, never the frame | Governed by your consent choices |
Verify it yourself
You do not have to take our word for it. In Chrome, Edge or Firefox:
- Open any tool, for example the JSON Formatter.
- Open the developer tools (F12, or ⌘ ⌥ I on a Mac) and choose the Network tab.
- Clear the list, then paste something, format it, change settings, convert it with a Next action and copy the result.
- Filter the list by
ws.formattr.com. You will see no requests at all, or only static.jsfiles the first time a new formatter loads — never a request carrying your data. - Optionally, switch the Network tab to Offline after the page loads. Formatting keeps working.
Analytics
We use cookieless, privacy-friendly analytics on formattr.com to learn which tools are used and whether they work. Events are restricted to an allow-list of ids, enums and size buckets — for example “JSON Formatter ran, result ok, input under 10 KB”. Input, output, file names, error messages and search text are never recorded; the code drops any event that does not match the list. There is no cross-site tracking.
Advertising
Some pages show Google AdSense ads below the workspace. Ads run on formattr.com only and cannot see into the workspace frame. There are no ads inside the editor, no pop-ups and no interstitials, and the universal formatter has no ads at all.
Consent and cookies
Formattr itself sets no cookies. Where ads are shown, visitors in the EEA, the UK and Switzerland see a consent message from a Google-certified consent platform before personalised ads are used. If your consent status is unknown, ads are requested as non-personalised. You can change your choice at any time from the privacy settings link shown with the consent message, and clearing this site's data resets it.
Your choices
- Clear recent and favourite tools with “Clear history” on the homepage.
- Clear all stored settings by clearing site data for formattr.com and ws.formattr.com in your browser.
- Block ads or analytics with your browser or an extension. The tools work the same.
Contact
Questions about privacy go to hello@formattr.com.