Legal

Privacy Policy

Kernel DevTools is built on a simple principle: your data belongs to you. This policy explains exactly what we collect — and what we don't.

Last updated: September 4, 2026

What we collect

Almost nothing. Kernel DevTools does not collect, transmit, or sell any personal data. There is no analytics SDK, no crash reporter, no A/B testing framework, and no usage tracking of any kind.

The only exception is the optional ad-unlock flow described below, which stores an anonymous token on our server for up to 24 hours.

What is stored on your device

The following data is stored locally on your device only using chrome.storage.local and is never transmitted anywhere except where noted:

  • Mock API rules — URL patterns and response definitions you create in the Mock tab. Stored locally; never sent to any server.
  • API collections — request collections and environment variables you build in the API Tester tab. Stored locally only.
  • Device ID — a randomly generated UUID created the first time you use the extension. It is not linked to your identity and is used only to associate an unlock token with your device during the ad-unlock flow.
  • Unlock state — if you claim an ad-unlock, the expiry timestamp is stored locally so the extension knows your unlock is active without making repeated server requests.
  • Daily export count — a counter (reset each day) tracking how many exports you have used. Stored locally only.

All other data displayed in the panel (console logs, network requests, cookies, localStorage, DOM snapshots) is read directly from the locally inspected browser tab and shown only to you. It is never stored persistently or transmitted anywhere.

Ad-unlock flow

Some advanced features can be unlocked for 24 hours by viewing an ad on kerneltools.dev. When you choose to do this:

  • The extension generates a one-time random token (UUID) and opens kerneltools.dev/unlock in a new tab, passing the token, your device ID, and the feature name in the URL.
  • When you click "Claim 24h unlock", that token is written to our server (Cloudflare D1) with a 24-hour expiry. Only the token, device ID, feature name, and expiry timestamp are stored — no name, email, or IP address is retained.
  • The extension polls our server to detect when the token has been claimed, then stores the unlock expiry locally and closes the polling loop.
  • Tokens are automatically deleted after expiry. You are never required to use this feature.

Network requests made by the extension

Kernel DevTools makes network requests only when you explicitly trigger a tool that requires it:

  • Certificate Inspector — queries crt.sh and hstspreload.org with the hostname you enter to fetch public certificate data.
  • DNS Leak Checker — queries api.ipify.org to retrieve your public IP address for comparison.
  • Ad-unlock flow — when you choose to unlock a feature, the extension polls kerneltools.dev/api/check-unlock until the token is claimed, then stops. No requests are made in the background when you are not using the unlock flow.

No other background network requests are made.

PII Leaks audit

The PII Leaks tab is off until you start it for a specific tab. While it runs, it checks that page's outgoing requests, beacons, image URLs, WebSocket messages and storage writes for the test values you enter and for values typed into email, phone, password, card, Aadhaar and PAN fields. The test values and typed values are matched inside your browser and are never sent to kerneltools.dev or anywhere else. Findings show only a masked sample (for example ca•••@example.com) and the destination without its query string, and they stay in the extension until you clear them, close the tab, or end the browser session. Scripts on the audited page can see the test values while the audit runs, so use fake values.

Browser permissions used by the extension

The extension requests the following Chrome permissions. Each is used only for the purpose stated below:

  • host permissions (<all_urls>) — Required to intercept and inspect network requests, response headers, cookies, and security policies on any webpage you are actively debugging. Access is limited to the tab open in the DevTools panel and is never used for background data collection.
  • scripting — The chrome.scripting API injects a lightweight content bridge into the inspected tab. This bridge relays console messages, DOM mutations, WebSocket frames, and storage change events to the DevTools panel in real time. No code is injected into tabs you are not actively inspecting.
  • storage — chrome.storage.local stores mock API rules, unlock state, layout preferences, and export counters locally on your device. See "What is stored on your device" above for the full list.
  • tabs — The chrome.tabs API is used to identify the active tab being inspected, retrieve its URL for the Network and Security panels, and reset panel state when you navigate to a new page.
  • alarms — chrome.alarms fires a periodic check to verify whether an ad-unlock token has expired. This keeps the panel badge accurate without requiring a page reload. No alarm data is transmitted externally.
  • remote code execution (inspectedWindow.eval) — The extension uses chrome.devtools.inspectedWindow.eval(), the standard Chrome DevTools API, to read DOM state, retrieve storage values, and relay console output from the inspected page's JavaScript context. All evaluated strings are generated locally within the extension; no code is fetched from any remote server.

Kernel Ludo (kerneltools.dev/ludo)

Kernel Ludo is a website feature, not part of the extension — everything above this section describes the extension itself, which Kernel Ludo has no access to and never touches. Playing a live multiplayer game means real-time data has to leave your device by design, so this section is separate and explicit about exactly what that involves.

  • What's sent — the display name you're shown with, and your connection's IP address (inherent to any live connection, not something we choose to log beyond what Cloudflare's own infrastructure sees to route the connection). No account, email, or persistent identity is created or required.
  • What's stored — nothing durable. A room's state (who's connected, whose turn it is) lives only in that room's server memory for as long as the room is active, and is gone once everyone leaves or the room is closed. There is no database of past games, players, or room codes.
  • Voice chat — Kernel Ludo has optional voice chat between players in the same room, connected directly peer-to-peer (WebRTC) rather than routed through our server — our server only ever relays the connection-setup handshake, never the audio itself. This means each player's real IP address becomes visible to the other players they're in a room with, for as long as voice is connected — a standard characteristic of peer-to-peer voice/video, not something unique to how we've built this. Voice is off by default: it's only ever turned on by an explicit click, and you can mute your own mic at any time, or turn it off entirely by leaving the room.

PDF tools and PDF Editor (kerneltools.dev/pdf-tools)

Every PDF tool on kerneltools.dev — including merge, split, compress, convert, OCR, sign, redact, protect, and the PDF Editor — processes the files you select entirely in your browser tab. Your documents, images, page order, rotations, passwords, and notes are not uploaded to Kernel’s servers. Closing or refreshing the page clears the session unless you download the result.

The “Was this PDF edited?” checker (kerneltools.dev/pdf-edit-checker) also reads your PDF only in your browser. If the file is password-protected, the password you type stays in your browser tab too, and that page loads no ads or advertising scripts.

The one exception is the PDF Editor’s optional “Process compatible replacements in source PDF” action. Only when you click it, the PDF and the text replacements you entered are uploaded to private storage so the edit can be applied on our server. The job is reachable only with an access token held by your browser tab, expires after 24 hours, and is then deleted automatically.

Case converter (kerneltools.dev/case-converter)

Text you paste into the case converter is converted in your browser tab. It is not sent to Kernel’s servers, stored, or saved between visits, and that page loads no ads or advertising scripts.

Kernel Split (kerneltools.dev/split)

Kernel Split groups are end-to-end encrypted. When a group is created, your browser makes a secret key for it, and every link to the group carries that key after the “#”, a part of the address browsers never send to us. Everything you type is encrypted with it in your browser before it is uploaded: the group name, the names you enter for each person, optional UPI IDs and PayPal, Revolut or Venmo usernames, every expense and payment (amounts, dates, notes, who paid and how it was split), repeating expenses such as monthly rent, the activity log’s details and the text of notifications. Our server stores only that encrypted data, so we can’t read it, and only people with a link to the group can. To run the group, the server does see some details in the clear: random ids for the group, each person, each entry and each repeating expense; who is an admin; which entries are payments and who received each one (for “confirm you got it”); which people each expense and repeating expense involves; how often each repeating expense repeats and its next date; the group’s time zone and payment-confirmation setting; when things were created or changed; and how large each encrypted record is. There are no accounts. Each person has a private link, and anyone holding that link can see the group and act as that person, so share each link only with its owner. An admin can cancel a link at any time. We store only a one-way hash of each link’s access code, so we can’t recover or show a link again, and we never have the group’s key. If you set up recovery, your browser makes a recovery key for you to save; we store only a keyed code made from your email (not the email itself), the group key locked with your recovery key, and a check value, so we can email you a one-hour link when you enter the same email, and only your recovery key opens the group again. Groups that nobody opens or changes for 12 months are deleted automatically, and a group admin can delete a group at any time, which permanently removes it for everyone. If you turn on notifications for a group, we store your device’s push address and its public encryption keys (removed when you turn them off, when the address stops working, or with the group), and your device keeps the group key so it can show them; each notification is encrypted with the group key and again for your device, so neither we nor your browser maker’s push service (Google, Mozilla, Apple or Microsoft) can read it, and it never contains your private link. The quick split on the landing page is not saved. To suggest a currency for a new group we use the country Cloudflare reports for your connection; it is not stored. Exchange rates come from the free currency-api dataset, fetched by our server; nothing about you is sent to it. Kernel Split pages load no ads or advertising scripts. If you add Kernel Split to your home screen, your device keeps a small offline page for it, and if you close the "Add to home screen" suggestion, your browser remembers that for 30 days; neither is sent to us.

Finance calculators and rent receipts (kerneltools.dev/calculators)

The EMI, SIP, FD and old vs new tax regime calculators work out every figure in your browser tab; the amounts you enter are not sent to Kernel’s servers. The rent receipt generator builds its PDF in your browser too: the tenant and landlord names, address and landlord PAN are never uploaded, stored, or saved between visits, and that page loads no ads or advertising scripts.

Third-party services

Kernel DevTools does not integrate any third-party analytics, advertising, social, or tracking services inside the extension.

The kerneltools.dev/unlock web page displays an advertisement served by Google AdSense. When the unlock page loads, Google may collect your IP address and browser information as part of serving and measuring ads. Google's privacy practices are governed by the Google Privacy Policy. You are only exposed to Google AdSense when you choose to open the unlock page — it is never loaded inside the extension itself.

The only other third-party network calls are the user-triggered ones listed above (crt.sh, hstspreload.org, ipify.org) — all of which send only the minimum data needed to answer your query.

Changes to this policy

If this policy ever changes, the updated version will be published at this URL and the "Last updated" date at the top will be changed.

Contact

Questions? Report an issue or email privacy@kerneltools.dev.