Skip to content

Effective 29 August 2026

Privacy

StackCache has no account system or tool-processing backend. Local tool inputs remain in your browser memory except for explicit encrypted-vault saves and the short-lived handoffs described below. Visiting the site still makes normal web requests to the hosting provider.

Local tool data

JSON, JWT, password, HTTP response, MQTT message, and other ordinary tool content is not sent to StackCache. Current tool input is cleared when you leave or reset the tool. The browser may cache application code, but not tool payloads.

Installed-app shares

When an installed browser sends text or a URL to StackCache while the app is closed, that plaintext may be staged in a dedicated browser database for at most five minutes. The share page consumes and deletes it immediately. It is never added to tool history, search, backups, telemetry, or offline caches. You can use the same page by pasting without installing the app.

Network tools

Public IP Lookup contacts ipify only after you press its lookup button. ipify necessarily receives your connection IP and normal browser request metadata; its simple-API documentation states that visitor information is not logged. StackCache sends no tool content, credentials, cookies, body, custom headers, or app identifier, does not proxy the request, and does not persist the result.

DNS Lookup, Bulk DNS Lookup, Email Authentication Toolkit, DNSSEC Inspector, BIMI & TLS-RPT Toolkit, and Advanced DNS Record Inspector contact Cloudflare’s DNS-over-HTTPS resolver only after you submit. Cloudflare receives the queried name, record type, connection IP, and normal HTTPS metadata; the name and type are present in each GET URL and Cloudflare handles them under its own policy. Bulk DNS Lookup sends one request for each of at most 25 unique targets with at most four in progress concurrently. A DNSSEC delegation snapshot sends DNSKEY and DS requests in parallel; other modes send one request. StackCache sends no cookies or credentials, does not proxy or retry requests, and keeps bounded results in memory only. Manual record parsing and record generation remain local and make no request; BIMI asset and certificate URLs are not fetched, and the advanced inspector does not contact certificate, location, gateway, or key targets.

RDAP Lookup sends the entered domain, IP address, or AS number to RDAP.org only after you submit. RDAP.org receives the target, connection IP, and normal HTTPS metadata and redirects the browser to the responsible registry, which receives the same data under its own policy. StackCache sends no cookies, credentials, request body, custom headers, or app identifier, does not proxy or retry the request, caps accepted responses at 512 KiB, and keeps results in memory only.

HTTP Request Builder sends the enabled method, headers, body, cookies or browser authentication selected by the credentials mode, connection IP, and normal browser metadata directly to the exact destination shown before Send. The destination handles that data under its own policy. StackCache does not receive, proxy, retry, queue, cache, or log the request or response. Definitions and responses remain in memory unless you explicitly save a named definition; that save is committed only as encrypted-vault ciphertext after unlock and becomes part of encrypted backups. A one-minute consume-once memory handoff carries the definition between the builder and vault without placing it in the URL or plaintext browser storage.

MQTT over WSS connects directly to the displayed broker after Connect. The broker receives your connection IP and WebSocket metadata, client ID, username/password when provided, subscriptions, published topics and payloads; it may retain or log them under its own policy. StackCache does not proxy, log, cache, or background the session. Credentials and the newest 200 received messages remain in memory and are cleared on disconnect/exit. Explicitly saved full broker profiles enter only encrypted-vault ciphertext and encrypted backups through the same one-minute consume-once memory handoff.

Website delivery

The hosting provider necessarily receives requests including your IP address and browser metadata to deliver pages and assets. Client analytics is not enabled in this initial implementation.

Contact

Privacy questions: support@stackcache.app.