Skip to the tool
OnPageKit

Privacy

Last updated: 4 September 2026.

Your drafts stay in the tab

Nothing typed into a tool on OnPageKit is uploaded, and the reason is architectural rather than a promise. This domain serves pre-built files, and no tool on it has any counterpart running elsewhere. When you fill in a meta tag form or paste a block of markup for checking, the whole operation — parsing, counting, assembling the output — happens in that tab. A URL you enter is not fetched from our end either, so an unlaunched or password-protected site can be worked on here safely.

One endpoint on this domain does run server-side, and it is set out in full immediately below. It belongs to the two feedback forms, it is idle unless you press one of their send buttons, and no tool touches it.

The two forms

The bug report at Report a bug and the request at Suggest a tool are the sole route by which anything leaves your browser here. They fire once, on submission. Typing in them sends nothing; abandoning them sends nothing.

Submitted, they carry:

From the endpoint the submission becomes an email to whoever maintains OnPageKit, routed through an Amazon Web Services queue and a mail provider. No database records it; the queue keeps it only long enough to hand it over. Afterwards it exists as one message in a mailbox, treated like any other letter. Any address you supplied serves to reply to you — it joins no list and is disclosed to nobody.

Storage on your device

A couple of preferences are kept in localStorage, which belongs to your browser rather than to us. Nothing there is sent anywhere, and wiping site data in your browser settings deletes it for good.

Our promos are drawn at random each time a page loads, so nothing about them is written to your device.

Cookies are not used anywhere on this site.

About the panels promoting our own work

OnPageKit carries no third-party advertising. The panels you see are ours, and they lead to Revin, the consultancy that pays for this site to exist. We label them with rel="sponsored" — declaring a commercial link is exactly the sort of on-page detail this kit is about, and it would be a poor look to skip it here. The creative is a static file served from this domain: no ad network, no tracking pixel, no cookie, no audience segment.

Each of those links ends in UTM parameters — utm_source, utm_medium and utm_campaign. Their entire job is to tell Revin which site the visit came from, at the level of a total. They contain no identifier for you, and deleting them from the URL takes you to the same page.

Where this site is hosted

Vercel serves these files. Any host sees the requests it answers, and Vercel may keep ordinary access logs containing things like an IP address and a browser user agent, used for delivering the site, protecting it from abuse and producing aggregate traffic counts. We do not receive per-visitor logs and cannot tie a request to a person. For retention periods and the legal detail, Vercel publishes its own privacy notice.

UK GDPR and what you can ask for

The law gives you the right to request a copy of your personal data, to correct it and to have it deleted. For ordinary use of this site the request resolves to an empty set: no accounts, no analytics profile and no server-side storage, so there is no file bearing your name to produce or to erase. The exception is a form you chose to submit with your address on it. That message lives in a mailbox and can be deleted on request — submit the request through the bug form, mentioning the address you wrote from so the message can be located. Anything you have sent to Revin through their own channels falls under the notice published there.

Getting in touch

No email address appears anywhere on this site, and that is a decision rather than an oversight: a published address is a scraped address. Anything you want to raise about this policy can travel through the bug form, which lands with the same person, or via Revin.