Privacy

Last updated 26 September 2026

What happens to what you paste

Nothing you paste into Formattr leaves your browser. Formatting, validation, detection and conversion run inside an isolated frame whose security policy blocks every outgoing network request. We never receive your input or output, and there is no server that could store it.

Local processing

The editor and every formatter are served as static files from a separate origin, ws.formattr.com. Once loaded, that frame can only fetch more of its own static files — the formatter for a language you use for the first time, for example. Its Content Security Policy sets connect-src 'self', and that origin has no endpoint that accepts data, so there is nowhere for content to go.

  • Your content lives in the memory of the current tab. When you move between tools with Next actions it is handed over in memory.
  • To survive a reload, a copy of up to 2 MB is kept in the frame's session storage. The browser deletes it when you close the tab.
  • If you switch on Remember my last input for a tool, that input is kept in the frame's local storage on this device until you clear it. It is off by default.
  • Content is never put in a URL. Links you copy from the address bar carry settings such as indent or dialect, never content.

The two-origin design

Formattr is two static sites. formattr.com serves the pages you read, search, and — on some pages — ads and privacy-friendly analytics. The workspace is a cross-origin iframe from ws.formattr.com. The two talk through a small, validated message protocol that carries tool ids, settings and analytics event names. Content is never part of a message.

The two-origin designThe formattr.com page contains an isolated frame from ws.formattr.com. They exchange only tool ids, settings and analytics event names. The frame cannot reach the network. The page can reach ad and analytics servers, but it cannot read the frame.Your browser tabformattr.comPages, search, favourites, ads, analyticsws.formattr.com — isolated frameEditor, formatters, detection, workersYour contentIn tab memory only.Reload copy in sessionstorage (≤ 2 MB), clearedwhen the tab closes.Security policyconnect-src 'self'default-src 'self'No endpoint exists onthis origin to send to.Ad & analyticsserversPage views and toolids — never contentAny other serverRequests from the frameare blockedpostMessage: ids, settings, event names
The page and the workspace run on different origins. The browser's same-origin policy keeps the page — and anything it loads — out of the frame.

What is stored, and where

DataStored?WhereRetention
Pasted input and outputNo persistent storageFrame memory; session storage only for reload recovery (≤ 2 MB)Until the tab closes
Tool settings, theme, splitter position, word wrapYesLocal storage on ws.formattr.comUntil you clear it
Recent and favourite tools (tool ids only)YesLocal storage on formattr.comUntil cleared with “Clear history”
Analytics eventsYesPrivacy-friendly, cookieless analytics12 months, aggregated
Ad dataPer Google AdSenseformattr.com pages only, never the frameGoverned by your consent choices

Verify it yourself

You do not have to take our word for it. In Chrome, Edge or Firefox:

  1. Open any tool, for example the JSON Formatter.
  2. Open the developer tools (F12, or ⌘ ⌥ I on a Mac) and choose the Network tab.
  3. Clear the list, then paste something, format it, change settings, convert it with a Next action and copy the result.
  4. Filter the list by ws.formattr.com. You will see no requests at all, or only static .js files the first time a new formatter loads — never a request carrying your data.
  5. Optionally, switch the Network tab to Offline after the page loads. Formatting keeps working.

Analytics

We use cookieless, privacy-friendly analytics on formattr.com to learn which tools are used and whether they work. Events are restricted to an allow-list of ids, enums and size buckets — for example “JSON Formatter ran, result ok, input under 10 KB”. Input, output, file names, error messages and search text are never recorded; the code drops any event that does not match the list. There is no cross-site tracking.

Advertising

Some pages show Google AdSense ads below the workspace. Ads run on formattr.com only and cannot see into the workspace frame. There are no ads inside the editor, no pop-ups and no interstitials, and the universal formatter has no ads at all.

Formattr itself sets no cookies. Where ads are shown, visitors in the EEA, the UK and Switzerland see a consent message from a Google-certified consent platform before personalised ads are used. If your consent status is unknown, ads are requested as non-personalised. You can change your choice at any time from the privacy settings link shown with the consent message, and clearing this site's data resets it.

Your choices

  • Clear recent and favourite tools with “Clear history” on the homepage.
  • Clear all stored settings by clearing site data for formattr.com and ws.formattr.com in your browser.
  • Block ads or analytics with your browser or an extension. The tools work the same.

Contact

Questions about privacy go to hello@formattr.com.