yamljson

Privacy Policy

The short version: we do not receive your data, because it never leaves your browser.

What we do not collect

We never receive the content you convert. The YAML and JSON you paste, type, open or drag onto this site is processed entirely by JavaScript running in your own browser. It is not uploaded, not transmitted, not logged, and not stored on any server. We could not read it even if we wanted to.

We also do not ask for or collect: names, email addresses, accounts, passwords, payment details, or any other personal information. There is no sign-up, because there is nothing to sign up for.

You can verify all of this yourself in about fifteen seconds — see how to verify nothing is uploaded.

Cookies

This site sets no cookies at all. There is no consent banner because there is nothing to consent to.

Local storage

One thing is stored on your own device: if you use the light/dark theme toggle, your choice is saved in your browser’s localStorage under the key theme, so the site remembers it on your next visit.

This never leaves your device and is never sent anywhere. Clearing your browser’s site data removes it. If you never touch the toggle, nothing is stored at all.

Files you open

When you open or drag in a file, your browser reads it locally and hands the text to the page. The file itself is never transferred anywhere, and nothing about it — not its name, size or contents — is recorded.

Analytics and third parties

We run no analytics of our own and have added no trackers or advertising. Fonts are served from this domain rather than from a font CDN, specifically so that no third party learns you visited.

One exception, stated plainly. This site is delivered through Cloudflare’s CDN, and Cloudflare injects its own analytics beacon into pages served on its free plan. We did not add it and cannot remove it from the HTML. What we can do is stop it running, and we do: the site sends a Content Security Policy that permits scripts only from this domain, so your browser refuses the beacon before it executes. You can see it being blocked in your browser console.

That same policy sets connect-src 'none', which forbids the page from making any network request at all — to Cloudflare, to us, or to anyone. It is what makes the rest of this page enforceable rather than merely promised.

Cloudflare does, unavoidably, see the network requests for the pages themselves, as any CDN or host would. It never sees what you type into the converter, because that is never transmitted.

If any of this changes, this page will be updated first, and no analytics would ever be given access to the content you convert.

Server logs

Like nearly every website, the server that delivers these pages records standard technical request information — IP address, timestamp, requested page, browser user-agent — for security and reliability. These logs concern the page request itself and never contain anything you paste into the converter. They are rotated and deleted on a routine schedule.

Children

This is a developer utility and is not directed at children. We do not knowingly collect information from anyone, of any age.

Changes

If this policy changes, the updated version will be posted on this page with a new date at the bottom.

Contact

Questions about this policy can go to [email protected], or via the contact page.

Last updated: August 2026