Privacy & Cookies
Most privacy notices are long because the site is doing a lot to you. This one is short in the places that count, because this site does almost nothing to you — and specific in the one place it doesn’t.
Last updated 16 July 2026The short version
- We set no cookies. Not one — not even a “you dismissed our cookie banner” cookie. That is why you have never seen a consent pop-up here.
- We run no analytics. No Google Analytics, no tag manager, no pixel, no heatmap, no session recording.
- We store nothing in your browser. No local storage, no session storage, no IndexedDB.
- There are no accounts. Nothing to sign up for, so no name, email or password to give us.
- Your files never reach us. The applets run inside your browser. There is no server that could receive your content.
- No third-party code. Every applet loads only from this site. No CDN, no ad network, no embedded widget — so no one else learns you were here.
- Data controller
- Hayward Zhu Ltd, trading as Pivotal Hub
- Company number
- 12231837, incorporated in England and Wales
- Registered office
- 14 Hollybank Estate, CV9 3ET, United Kingdom
- Data protection
- pathfinders+GDPR@pivotalpath.co.uk
02 — What we don't collect
To be concrete, because “we respect your privacy” is worth nothing on its own. We do not collect, and have no means of collecting:
- your name, email address, phone number or postal address (there is no form and no account);
- any file, image, document, PDF, spreadsheet, token, key or block of text you load into an applet;
- any output an applet produces for you;
- behavioural or analytics data — pages viewed, time on page, scroll depth, clicks, referrer;
- a device fingerprint, advertising identifier, or any cross-site identifier;
- payment details (nothing here is for sale).
We do not sell, rent, share or otherwise disclose personal data to third parties for their own purposes, and we run no advertising. There is no data broker relationship to disclose, because there is no data.
03 — What happens to your files
Every in-browser applet on this site processes your content locally, using your own computer's processor and memory. The file you choose is read by JavaScript running in your tab. It is never uploaded, because there is no upload endpoint to send it to. This is not a policy we could quietly reverse; it is a property of how the site is built. The site is a set of static files with no server-side application behind it.
Practically, this means: your content exists in the tab's memory while you work, and is discarded when you close or reload the tab. Nothing is retained, because nothing is ever transmitted. We could not produce your file in response to a court order, a breach, or our own curiosity, because we never had it.
Two pages on the site — Bulk Blogger MCP and PRD Focus Group — are installation guides rather than tools. They process nothing at all. Software you install from those guides runs entirely on your own machine, under your control, and this notice does not govern it.
04 — No third-party code, anywhere
When you open an applet, your browser talks to this site and to nothing else. There is no content delivery network, no analytics endpoint, no font service, no embedded video, no chat widget, no social button. Every file the page needs is served from our own origin.
This is rarer than it sounds, and it is worth explaining why we bothered.
Why this matters more than cookies
Some applets need large open-source libraries to do their job — reading a PDF, building a ZIP, drawing a QR code. The normal way to include one is to load it from a public CDN. It is free, it is fast, and almost everyone does it. It also has two consequences that sit badly with a tool that markets itself on privacy.
First, it leaks you. Loading a library from a third party discloses your IP address to that third party, along with your user-agent and the page you loaded it from — automatically, on page load, before you have clicked anything. Under the UK GDPR an IP address is personal data. So a “private” tool that pulls a library from a CDN has quietly told someone else you were there, in the act of loading.
Second, and worse, it hands over control of the code. A library loaded from a CDN is code we did not serve, running on your file, inside the tab where your data is. If that CDN were ever compromised or coerced, the code it served could read what you loaded and send it somewhere. For an EXIF stripper or a PII scrubber — tools whose entire purpose is that your file stays yours — that is not a theoretical footnote. It is the exact thing the tool claims to protect against.
So we self-host every library. The versions are pinned, they are copied from the public npm registry at build time, and they are served from this origin like any other file. Nothing about how the applets behave changed; who your browser talks to did.
You can check this in about a minute. Open any applet, press F12, and look at the Network tab. Every request will be to this domain. If you ever see one that isn't, we would genuinely like to know: pathfinders+GDPR@pivotalpath.co.uk. We test this automatically across every page on the site, but a claim you can verify yourself is worth more than a claim we test in private.
The two guide pages — Bulk Blogger MCP and PRD Focus Group — link out to GitHub, but only if you choose to click. Following a link off this site is you visiting them, not us telling them about you.
05 — Hosting and server logs
This is the one place any personal data exists at all, so here it is in full.
The site is a set of static files hosted by Vercel Inc., a Delaware corporation (company number 5857312) at 440 N Barranca Ave #4133, Covina, CA 91723. Vercel's infrastructure in turn runs primarily on Amazon Web Services, so AWS is in the path of serving you this page. Vercel's full sub-processor list is published at security.vercel.com ↗.
Vercel handles that request data under a data processing addendum incorporated by reference into their terms, which binds them automatically. To be precise rather than flattering: Vercel is our processor for data processed on our behalf, but their addendum also makes them an independent controller of the operational data their platform generates about serving the site. We are telling you that because “our host is just a processor” is the comfortable version, and it isn't the whole picture.
Our domain is registered with 123-reg, who answer DNS lookups for it. They are deliberately not in the path of your request: the domain points at Vercel with ordinary DNS records rather than a registrar forwarding service, so 123-reg never receives your request and never sees your visit.
Like every web server that has ever existed, Vercel processes standard request data in order to hand you the page: your IP address, the path you asked for and any query string, your user-agent, the host, the response status, and a timestamp. It also records which edge location served you. A server cannot return a page without knowing where to send it, so this is inherent to the web rather than a choice we made.
Retention: no more than 24 hours. Vercel keeps these request logs for a short window tied to our plan and they then expire. We do not export them anywhere: we run no log drain, so no copy of them is created outside Vercel's own short-lived store.
We do not read, analyse, aggregate or profile those logs. We have not looked at them. They exist so that a server can serve a page and so that abuse can be investigated if it ever happens.
Two things we won't dress up. Vercel does not offer IP anonymisation or truncation for these logs, so for that short window your IP is processed in full and we cannot pretend otherwise. And Vercel is a US company, so section 07 explains how that transfer is handled. If either of those is a dealbreaker for you, that is a legitimate position and we would rather you knew than found out.
Our lawful basis is legitimate interests (Article 6(1)(f) UK GDPR) — serving the site and keeping it available and secure. The processing is the minimum a web server requires, it is short-lived, and it builds no profile of you, so we consider it a fair balance against your interests.
06 — Your rights
Under the UK GDPR and the Data Protection Act 2018 you have the right to: be informed about how your data is used; request access to your personal data; have inaccurate data corrected; request erasure; restrict or object to processing; and request portability of data you gave us.
We want to be straight with you about what these amount to here, rather than reciting them to look thorough. We hold no personal data about you that we could retrieve, correct, export or delete. We have no account record, no analytics profile, and none of your files. If you sent us a subject access request today, an honest and complete response would be: we hold nothing about you.
The one place personal data exists at all is in the transient server logs described in section 05. If you want to exercise rights over those, ask us and we will tell you honestly what our host retains and help you get at it.
To exercise any right, or to ask what we hold: pathfinders+GDPR@pivotalpath.co.uk. We will respond within one month, as the law requires. There is no charge.
Complaints
If you are unhappy with how we have handled your data, please tell us first — we would rather fix it. You also have the right to complain directly to the UK's supervisory authority, the Information Commissioner's Office, at ico.org.uk/make-a-complaint ↗ or 0303 123 1113. You do not need our permission and you do not need to come to us first.
07 — International transfers
We hold no personal data ourselves, so we transfer none. Our host does, and we would rather set that out than let “we transfer no data” do work it hasn't earned.
Vercel Inc. is a United States company (section 05), so the request data described there is processed by a US organisation. Vercel serves visitors from the closest edge location — a request from the UK is normally answered from their London edge — but their network is global and cache and infrastructure are not confined to the UK, so you should assume the request metadata may be processed outside it.
That transfer rests on two independent footings, either of which would be enough:
- Adequacy. Vercel Inc. is certified under the UK Extension to the EU-U.S. Data Privacy Framework (certified since May 2024, current at the date above). The UK has found the Framework adequate, so transfers to a certified organisation are permitted under Article 45 UK GDPR without further safeguards. You can check Vercel's status yourself on the official Data Privacy Framework list — we would rather point you at the register than ask you to believe us.
- Contractual safeguards. Independently, Vercel's data processing addendum incorporates the European Commission's Standard Contractual Clauses (2021/914) and, for UK transfers, the ICO's UK Addendum to those clauses. These are Article 46 safeguards and they stand whatever happens to the Framework.
We mention both because adequacy findings have been struck down before — Safe Harbour in 2015, Privacy Shield in 2020. If the Framework fell tomorrow, the contractual clauses would still be in force and this transfer would still be lawful.
Concretely, the data in question is a short-lived server log line — an IP address, a URL, a timestamp, a user-agent — and nothing else. None of your files, and nothing you typed into an applet, is in it, because none of that ever leaves your browser.
08 — Children
The applets are developer and marketing utilities not aimed at children, but there is no age gate and none is needed: with no accounts, no cookies and no data collection, a child using this site is exposed to no more processing than an adult, which is to say almost none.
09 — Changes to this notice
We may update this notice as the site changes. The “last updated” date at the top tells you when it last moved. If we ever begin collecting personal data, setting cookies, or adding tracking of any kind, we will update this page before the change goes live and flag it on the site — not quietly afterwards. The whole point of the position we have taken is that it is checkable, and a checkable claim that changes silently is worse than never having made it.
10 — Contact
Data protection and anything in this notice: pathfinders+GDPR@pivotalpath.co.uk.
General enquiries: pathfinders@pivotalpath.co.uk.
By post: Hayward Zhu Ltd, 14 Hollybank Estate, CV9 3ET, United Kingdom.
See also our Terms of Use.