Browser-first does not mean “no network.” It means the sensitive transform happens on the user agent unless explicitly outsourced. PracticalKit applies three patterns:
Pattern A — paste and compute: text tools keep input in memory, output to textarea or clipboard. Clear on navigation is best-effort; users handling classified data should close the tab explicitly.
Pattern B — file pick and transform: PDF/image/RGBV3D use FileReader and WASM. Files never hit our origin. Large files may swap to disk-backed implementations in future; we will update docs if that changes.
Pattern C — optional remote fetch: retired in most tools. When reintroduced for finance or translation, pages will show provider name, data categories sent, and retention disclaimers before input focus.
Threat model boundaries: browser-first protects against PracticalKit logging payloads, not against malware on the device, compromised extensions, or shoulder surfing. We document that limit plainly.
For developers embedding similar tools: prefer Subresource Integrity on WASM, avoid sending telemetry with payload snippets, and never log clipboard events. Our rebuild removed thin pages that violated those norms without adding educational value.
Draw the three patterns on an architecture diagram: A is in-memory string transforms; B is File/Blob plus WASM heap; C is explicit outbound HTTPS. Ask whether inputs can enter logs, analytics properties, or error breadcrumbs—if yes, change code or copy. Privacy policy covers cookies and ads; this article covers where tool transforms run. Both pages should cross-link with consistent wording. Practical habits: use local-labeled tools for secrets, close tabs when finished, and treat API tools as visible to a provider. Those habits only work when page copy matches reality.
2026-05-14