Privacy Policy

Your data stays yours

JSONLab doesn't track you, doesn't collect your data, and doesn't send your JSON to any server. This policy explains exactly what we do — and don't — do.

Last updated: January 2026

The short version: We don't collect anything. Your JSON never leaves your browser. There's no analytics, no tracking, no advertising. That's it.

1. What we collect

Nothing. JSONLab does not have a backend server. There is no database of user data, no analytics platform, no advertising network. We do not collect IP addresses (we can't — we never see your requests), we do not set cookies for tracking purposes, and we do not use browser fingerprinting.

The only data stored on your device is what you explicitly create: the contents of your text inputs (saved to your browser's localStorage so you can resume your work), your theme preference, and your pinned tools. All of this lives on your device, under your control, and is never transmitted to us or anyone else. You can clear it at any time by clearing your browser's site data.

2. How the tools work

Every tool on JSONLab runs entirely in your browser using JavaScript. When you paste JSON into the formatter, that text is processed by JavaScript code running on your device — it is never sent to a server. The formatted output you see is generated locally, on your machine, by your browser. We have no way to see what you're working on, even if we wanted to.

You can verify this yourself: open your browser's DevTools (F12), go to the Network tab, and use any tool. The only network requests you'll see are for the initial page load (HTML, CSS, JavaScript, and font files). After your first visit, even those requests are cached by the service worker — you can use JSONLab completely offline.

3. The Share feature

The Share tool lets you generate a URL that contains your JSON. This URL is created entirely in your browser: your JSON is compressed with gzip, base64-encoded, and placed in the URL's hash fragment (the part after #). The URL itself is not sent to our server — when someone visits it, their browser decodes the hash locally.

This means shared URLs are peer-to-peer: you give the URL to someone, they open it, and their browser decodes the content. We never see the URL or its contents. If you share a URL via email, chat, or any other channel, that channel's privacy policy applies — we have no involvement.

4. Cookies and local storage

JSONLab does not set any tracking cookies. We use the browser's localStorage and IndexedDB APIs to store your preferences and tool state on your device. Specifically, we store:

  • Tool state — the contents of your text inputs in each tool, so you can resume work after closing the tab.
  • Theme preference — whether you prefer light, dark, or system theme.
  • Pinned tools — the list of tools you've starred for quick access.
  • Recent files — names and sizes of files you've uploaded (file contents are not stored, only the metadata).
  • Layout preferences — for tools with resizable panes, the saved layout proportions.

All of this data lives on your device and is never transmitted anywhere. You can clear it at any time through your browser's settings (look for "Site data" or "Storage" in your browser's privacy controls) or by clicking the Clear button in any tool's toolbar.

5. Third-party services

JSONLab loads fonts from Google Fonts (fonts.googleapis.com and fonts.gstatic.com). Google's privacy policy applies to those requests. We use Google Fonts because it's the most reliable way to deliver high-quality open-source fonts (Inter and JetBrains Mono) without bundling them in the page weight. After your first visit, fonts are cached locally and no further requests are made.

Other than Google Fonts, JSONLab does not load any third-party resources. There are no analytics scripts (no Google Analytics, no Plausible, no Fathom), no advertising networks, no error reporting services, no CDN-side tracking. The only requests are to jsonlab.app itself.

6. Service worker and offline use

JSONLab registers a service worker that caches all HTML, CSS, JavaScript, and font files locally. This enables offline use after your first visit — you can use every tool without an internet connection. The service worker only stores static assets; it does not store your JSON content (that's stored in localStorage as described above) and it does not communicate with our server in any way.

You can remove the service worker through your browser's DevTools (Application tab → Service Workers → Unregister) or by clearing site data.

7. Children's privacy

JSONLab is not directed at children under 13, and we do not knowingly collect any information from children. Since we don't collect any information from anyone, this is naturally the case — but we state it explicitly for clarity. If you believe a child has provided information to us (which would require them to email us directly), please contact us and we'll delete it.

8. Changes to this policy

If we ever change this privacy policy, we'll update this page and bump the "Last updated" date at the top. We will never weaken this policy — if we ever add any data collection (which we have no plans to do), it will be opt-in, clearly disclosed, and limited to what's strictly necessary for the feature being added.

For transparency, the previous version of this policy is archived in our source control history. You can compare versions to see exactly what changed.

9. Contact

If you have questions about this privacy policy or JSONLab's data practices, please reach out through our contact form on the About page. We'll respond within a reasonable timeframe, usually within a few days.

For takedown requests, copyright concerns, or reports of security vulnerabilities, please use the same contact form with a clear subject line indicating the nature of your request.

Still have questions?

If anything in this policy is unclear, or if you'd like to verify any of our claims, please reach out. We're happy to explain in more detail or point you to the relevant source code that proves what we say here.

Contact us →