Back to Toyroom

Your data

Privacy policy

How Toyroom processes queries, stores data, and uses external services.

At a glance

  • We don't sell your data.
  • Compare Domains processes your lists in your browser.
  • Other tools may upload inputs, save results, or use external services.
  • We collect page views and tool-usage analytics.
  • DNS history, appraisal caches, and chat have separate retention periods.

Analytics

How we measure usage

We use Umami, a self-hosted analytics service, to understand which tools are useful, how people find the site, and where requests fail.

Our analytics include:

  • Visits: Page paths, referrers, browser type, and approximate country.
  • Tool activity: Submission and result counts, selected options, exports, processing times, and error messages.
  • Search events: Some tools, including Expiry and Reports, include entered search terms in their analytics events.

Analytics run on our infrastructure. Separately, our services and security providers process request metadata, including IP addresses, to operate the tools and limit abuse.

Third-Party Services

What runs under the hood

Cloudflare

Our site runs behind Cloudflare for security and performance. Cloudflare processes request metadata and may set cookies for security. Turnstile verifies requests to many tools; the AI assistant uses hCaptcha. These providers receive browser and network information during verification.

Fonts

Our fonts are hosted with the site. Your browser downloads them from Toyroom without connecting to Google Fonts.

OpenAI

The AI assistant sends conversation messages and tool results to OpenAI. The v1 AI appraisal also sends submitted domains for processing. See OpenAI's privacy policy for details on how they handle data.

Browser Storage

What we store locally

We use browser storage for preferences, saved selections, cached results, and scan access. You can remove this data in your browser settings.

DNS Scout saves a random browser key and sends it with scan requests to control access to saved jobs and results. The server stores a hash of that key. Clearing that key removes this browser's access to those scans. When storage is blocked, access lasts only for the current page. Older scans created before this key was introduced cannot be reopened; start a new scan to get updated results.

Chat keeps its session, browser fingerprint, and conversation in tab storage so a reload can continue the chat. This browser copy is separate from the server records described below. Other security and session features may also use cookies.

Your Domain Data

What happens to your domains?

Each tool handles inputs differently. Domain lookups may send the domains you submit to DNS resolvers, registries, or other data providers. Our services may retain requests and results in caches, job storage, or operational logs.

Compare Domains: Your lists are compared in your browser. The comparison does not upload their contents to our servers.

File Splitter: Selecting a file uploads it to our server to read its columns and row count. Splitting uploads the file again for processing and returns the output for download. This tool does not offer saved file history.

DNS Scout: Saved deep scans include domains, results, a hashed browser identifier, and IP address. Completed and failed scan records become eligible for daily cleanup after 30 days; unfinished jobs may remain longer. Bulk lookup result files are separately eligible for cleanup after two hours. Queue records and logs can outlast the downloadable results.

Domain Appraiser: We cache domain appraisals for reuse for 30 days. Expiration stops reuse; physical removal happens during cache cleanup. Domains and processing details can also appear in service logs.

Secure Drop: Files are encrypted on our server for operator access. By default, files expire after 72 hours and cleanup runs hourly. The upload page shows the current retention and cleanup interval.

The AI assistant (Gizmo) works differently; see below.

AI Assistant

How Gizmo handles your data

Gizmo, our AI assistant, uses OpenAI's API to help you with domain-related questions. It stores conversation history and session information to maintain context and enforce usage limits.

  • Temporary storage: Active conversation and session records expire after 24 hours without a refresh. Chat activity can extend this period. Session records include your IP address, browser fingerprint, and usage counts.
  • Service logs: Audit logs can include session identifiers, excerpts of messages, tool arguments, and processing details. Logs and backups may retain records longer than active chat storage.
  • OpenAI processing: Messages and tool results are sent to OpenAI to generate responses. Starting a new chat does not remove existing records from service logs or backups.

For details on how OpenAI handles API data, see their privacy policy.