Top10k Tools
All Tools Categories AI Reviews
All Tools Categories AI Reviews

Privacy Policy

Last updated: September 14, 2026

Top10k Tools is a hub of free, browser-based mini tools. Privacy is built into how the tools work. This policy explains, in plain language, the small amount of data we handle and the things we never touch.

The short version: most tools process input in your browser. Tools that need live data or another network service should say so on their page. We use first-party analytics, Google Analytics 4, and privacy-first Microsoft Clarity, accept contact/request submissions, do not sell personal data, and do not require a user account.

1. What we collect

1.1 From visitors

When you visit top10k.com, our server (and Cloudflare, our CDN) records standard web request logs: IP address, user agent, requested URL, response code, and timestamp. These are kept briefly for security and debugging, then rotated out. They are not used to build a profile of you.

1.2 From tool use

Most tools calculate, convert, or generate results locally in your browser. Some tools need live data, load a library, or call another network service. Those requests can disclose your IP address and the requested data to the service involved. Check the notice on an individual tool before using sensitive input; we are auditing every tool so these disclosures match its actual behavior.

1.3 Forms and messages

If you use the contact or tool-request form, we store the information you submit so we can review and reply to it. This can include your name, email address, subject, message, requested tool details, a one-way IP hash used for abuse prevention, user-agent data, and timestamps. You can ask us to delete a submission by emailing us.

1.4 What tool use generally does not collect

  • There is no user account database or account password to create.
  • Locally processed tool input is not sent to our application server.
  • We do not sell tool input, files, contact details, or analytics data.
  • A network-enabled tool may send the data needed for its request; its page should disclose that behavior.

2. Cookies & local storage

We use a random first-party visitor cookie named t10k_v for up to 30 days to distinguish aggregate visits, plus a theme cookie/local storage to remember light or dark mode. The contact form uses a temporary session cookie for its anti-forgery token. Google Tag Manager loads Google Analytics 4 and may set or read Google measurement identifiers under Google's current configuration. Microsoft Clarity runs in no-consent mode by default and is instructed not to set analytics or advertising cookies unless a visitor has supplied a valid analytics-consent signal. Some tools use your browser's localStorage to remember your own preferences (timer settings, recent items, saved decks). That data stays in your browser and is never transmitted — clear it any time from your browser settings.

3. Analytics

We use a first-party event system to measure page views, sessions, tool interactions, downloads, approximate country, referrer/UTM fields, browser family, and engagement time. It uses a random 30-day visitor ID, a per-tab session ID, and a one-way IP hash; raw IP addresses are not stored in the analytics tables. We also use Google Analytics 4 through Google Tag Manager to understand search acquisition and engagement. We also use Microsoft Clarity to understand aggregate clicks, scrolling, navigation friction, performance errors, and page interaction through heatmaps and session playback. Form fields, generated outputs, and other result elements are masked before Clarity loads; do not enter sensitive information unless a tool explicitly requires it. Clarity is configured with advertising storage denied and analytics storage denied by default, so visits without consent use Microsoft's limited no-cookie measurement mode. Google, Microsoft, and Cloudflare process request/measurement data under their own privacy terms.

4. Third parties

Some tools load small open-source libraries from a public CDN, and a few fetch public data from a third-party API. These requests reveal your IP address and may include the query or input needed to provide the result. Individual tool pages should disclose the relevant behavior. We do not sell personal data to advertisers.

5. Security

All traffic is served over HTTPS with HSTS, and we ship a Content-Security-Policy. Local processing reduces exposure for many tools, but network-enabled tools and loaded third-party code have different risks. Found a vulnerability? See /.well-known/security.txt or email [email protected].

6. Your rights & compliance

You may ask what personal data we hold about a contact/request submission, request a correction or deletion, or raise another privacy question. Analytics identifiers and request logs are generally pseudonymous rather than account-linked. Applicable rights vary by location; contact us and we will assess the request under the law that applies.

7. Children's privacy

Top10k Tools is a general-audience service and is not directed to children. We do not knowingly collect personal data from children. Microsoft states that Clarity should not be used on websites or applications targeting people under 18; accordingly, our Clarity implementation is intended only for the general adult audience and runs with analytics and advertising cookie storage denied by default.

8. Changes to this policy

We may revise this policy as the site evolves. Material changes are noted by updating the date above, and older versions live in our public history.

9. Contact

Privacy or any other questions: [email protected] · Contact page

Top10k Tools

Most tools process input in your browser; tools that need live data or a network service disclose that on the page.

Company

About Us Request a Tool Contact

Legal

Privacy Policy Terms of Service

Connect

GitHub Facebook X / Twitter
© 2026 Top10k Tools. All rights reserved.