Privacy
Your input is not our business.
Nobuf is designed so the contents you paste, type, decode, or hash do not need to leave your browser.
Local processing
Tool inputs and selected files are handled by JavaScript and standard browser APIs on your device. Nobuf does not send this content to an application server.
Browser storage
The site may store interface preferences and bounded provider responses in your browser. Private file contents, JWTs, passwords, and editor documents follow the storage disclosure shown by their specific tool.
Network requests
The site has no application API or account server. Clearly marked live-data tools contact Cloudflare DNS, Frankfurter, Crossref, deps.dev, OSV, or Open-Meteo directly from your browser and show what is sent. HIBP breach checks, background-model downloads, camera access, and geolocation remain explicit opt-in requests. No third-party analytics are included.
Your responsibility
Review outputs before using them in production or security-sensitive workflows. A decoder does not validate authenticity, and a checksum alone does not prove a file is trustworthy.