Privacy
The short version: what you type into a tool on this site stays on your computer.
Tool input is never sent to us
Every tool on SudoStuff is implemented in JavaScript that runs in your browser. There is no endpoint that accepts tool input, which means your JSON payloads, JWTs, passwords, API keys, source code and private text are never transmitted to our servers — not to be processed, and not to be stored.
You can confirm this yourself: open your browser’s developer tools, switch to the Network tab, and use any tool on this site. You will see the requests that load the page and its assets, and nothing else.
What we store in your browser
SudoStuff writes two keys to your browser’s local storage:
sudostuff:recent— the names of up to eight tools you opened recently, with the time you opened them.sudostuff:favorites— the names of tools you starred.sudostuff:theme— whether you chose light, dark or system appearance.
These hold tool names only. No tool input is ever written to local storage, session storage, cookies or IndexedDB. All of it stays on your device and is never uploaded. Use Clear recent tools in the footer, or clear site data in your browser, to remove it.
No analytics, no trackers, no ads
There is no analytics script, no tag manager, no advertising network and no third-party embed on this site. Nothing profiles you across pages, and no data about what you do here is shared with anyone.
Server logs
Like any website, the web server records ordinary request metadata — the URL requested, a timestamp, the response status, the user-agent string. Because tool input is never part of a request, it can never appear in those logs. We do not log tool input, and there is no mechanism by which we could.
A note on shared devices
Your input stays in your browser tab, but so does everything else on the page. If you are on a shared or public machine, close the tab when you finish, and remember that generated passwords remain visible on screen until you do.