Toolcrow hosts code that other people run in their browsers. That only works if it is safe: for you, for the people you share with, and for your account. Here is exactly what we do, in plain language. Want the technical version? Flip the switch.
Prefer the technical details? Switch to the developer view.
The tools you build run other people's browsers. Here is how we make sure sharing one never puts you or your visitors at risk.
Each tool you share runs in its own isolated space, walled off from your account and from everyone else's tools. Whatever the code does, it can never reach your login or your data.
A new tool is visible only to you. Making it public is always a deliberate step you take, never something that happens by accident.
Lock any tool behind a password and decide exactly who gets in. Change the password and every link you handed out before stops working instantly.
Too many wrong password attempts on a tool and further tries are blocked for a while, so a weak password can't be cracked by hammering at it.
Behind the tools sits the platform itself: your account, your files and the database. This is how that stays yours and yours alone.
The people who open your tools are not tracked by us. No cookies, no logging of their address, and no third-party trackers running on your tools.
Whatever your tool saves for one visitor stays in that visitor's own browser, not on Toolcrow's servers. Only what your tool explicitly saves as shared is stored for the tool: in your own Google Sheet once you connect one, otherwise in Toolcrow's built-in database. You stay the owner of your data.
No one can pull other people's tools, emails or passwords through the app. The database only answers the server, never the public app key that lives in every browser.
Access is invitation-only, your session is verified on every page, and you can only ever touch your own tools, never someone else’s.