Trust

Compliance pack

Architecture notes and privacy receipts for agencies, freelancers, and security-minded teams.

Processing model

OneDevToolkit tool engines execute in the browser using JavaScript (including pdf-lib / Canvas / Web Crypto). File bytes used by tools are not uploaded to OneDevToolkit for processing.

Privacy receipts

Users can download a Processing Receipt JSON with tool identity, timestamps, and client-computed SHA-256 hashes when the tool UI provides file handles.

Processing receipts include tool identity, timestamps, and client-computed SHA-256 hashes when the tool UI provides file handles.

What servers may store

  • Account credentials (hashed)
  • Favourite / recent tool slugs

Servers do not receive vault file contents or recipe file payloads in the local-first model.

Suggested contract language

“Vendor processes Customer files in the Customer’s browser. Vendor does not receive Customer file contents for tool execution. Customer may export a processing receipt with cryptographic hashes generated client-side.”

Privacy policy · Recipes · Vault