Security

Sharing a tool should never put you at risk.

Toolcrow hosts code that other people run in their browsers. That only works if it is safe: for you, for the people you share with, and for your account. Here is exactly what we do, in plain language. Want the technical version? Flip the switch.

Prefer the technical details? Switch to the developer view.

Your tools

Every tool you share is kept safe

The tools you build run other people's browsers. Here is how we make sure sharing one never puts you or your visitors at risk.

Every tool runs in its own locked room

Each tool you share runs in its own isolated space, walled off from your account and from everyone else's tools. Whatever the code does, it can never reach your login or your data.

Private by default

A new tool is visible only to you. Making it public is always a deliberate step you take, never something that happens by accident.

You hold the keys, and can take them back

Lock any tool behind a password and decide exactly who gets in. Change the password and every link you handed out before stops working instantly.

Guessing doesn't pay

Too many wrong password attempts on a tool and further tries are blocked for a while, so a weak password can't be cracked by hammering at it.

The platform

Your account and data are locked down

Behind the tools sits the platform itself: your account, your files and the database. This is how that stays yours and yours alone.

We don't watch your visitors

The people who open your tools are not tracked by us. No cookies, no logging of their address, and no third-party trackers running on your tools.

Your data stays yours

Whatever your tool saves for one visitor stays in that visitor's own browser, not on Toolcrow's servers. Only what your tool explicitly saves as shared is stored for the tool: in your own Google Sheet once you connect one, otherwise in Toolcrow's built-in database. You stay the owner of your data.

The database is locked down

No one can pull other people's tools, emails or passwords through the app. The database only answers the server, never the public app key that lives in every browser.

Your account is locked down

Access is invitation-only, your session is verified on every page, and you can only ever touch your own tools, never someone else’s.