Velto
Legal

Privacy policy

Last updated: July 21, 2026

This policy sets out what Velto does and does not collect on veltotools.com. It applies to every visitor and includes specific sections for California residents as well as for visitors in the European Economic Area and the United Kingdom.

Who is responsible

Flavio Paroli, sole trader, SIRET 888 101 078 00028, 175 Chemin des Tours, 83300 Draguignan, France. Privacy questions and requests go to [email protected].

The short version

There is no account, no sign-up and no cookie. Every tool on the site works without anyone handing over personal information, which leaves very little for this policy to cover.

What you type into a tool

The tools run their calculations inside the browser. A salary, a weight, a height, a block of text or a generated password never reaches the server, so it is never stored and the operator never sees it.

Two situations work differently. Calling a tool's open API sends parameters through the server for as long as it takes to compute a response, without retaining them. Sharing a prefilled link puts the values in the URL itself, which the sender is the one passing along.

Analytics

Site statistics come from a measurement tool built in house, with no cookie and no third party service. Each recorded event holds five items of information, namely the page path, the event type (page view, click, tool use, copy, download, share), the label of the button clicked, the destination of an outbound link and the area of the page involved.

The measurement is anonymous by design. Nothing identifying gets stored, neither an IP address, nor a user agent (the technical signature a browser sends with each request), nor a session identifier. An IP address is read in memory long enough to filter bots and rate limit abuse, then dropped without being written anywhere.

No event can therefore be tied to a person, to an earlier visit or to activity on another site. These statistics serve one narrow purpose, which is knowing which pages get read and which tools actually get used, so that the right ones get improved.

Local storage on your device

A few preferences live in the browser's local storage, an area separate from cookies: light or dark theme, favourite tools, recently opened tools and the input history of certain tools.

All of it stays on the device, never travels to the server and disappears as soon as the site's browsing data is cleared.

Service providers

Personal information is never sold, rented or traded. Two technical providers take part in serving the site:

  • Scaleway SAS (France) hosts the servers, so hosted data stays in the European Union.
  • Cloudflare, Inc. (United States) delivers the pages and blocks attacks. Connection data, including a visitor's IP address, passes through its network for that purpose.

How long data is kept

Analytics events, which carry no identifying data, are kept for 25 months at most. Emails are kept for as long as the request takes to handle and no more than 3 years afterwards.

Children

The site addresses a general audience and is not directed to children under 13. No registration exists and no personal information is requested from anyone, so no information from a child is knowingly collected. Anyone who believes a child has sent personal information by email can write to the address above and have it deleted.

California residents

Velto does not sell and does not share personal information, as those terms are defined by the California Consumer Privacy Act as amended by the CPRA. It never has. No cross-context behavioural advertising, meaning advertising built from activity tracked across other sites, takes place here.

California law grants residents the right to know what personal information is collected, to request deletion or correction and not to face discrimination for exercising those rights. Since the site keeps no identifiers, there is generally nothing held about a given person to disclose or delete. A request sent to [email protected] still gets a written answer.

Visitors in the EEA and the UK

Where the GDPR or the UK GDPR applies, the legal basis for the audience measurement described above is the operator's legitimate interest in understanding how the site is used, under Article 6(1)(f). The rights of access, rectification, erasure, restriction, objection and portability are exercised at the contact address above.

One limitation is worth stating plainly. Analytics events keep no identifier, so the operator cannot connect an event to a person. An access or erasure request about those events therefore cannot be fulfilled for lack of identifiable data, as Article 11 of the GDPR anticipates.

Transfers to Cloudflare in the United States rely on the European Commission's standard contractual clauses, the template contract that binds a provider to an equivalent level of protection, together with Cloudflare's certification under the EU-US Data Privacy Framework. A complaint can be lodged with any supervisory authority, in France the CNIL at cnil.fr.

Security

Everything reasonable has been put in place to make the site as secure as possible (HTTPS enforced on every page with HSTS, a strict content security policy that blocks third party scripts, hardening headers such as nosniff and Referrer-Policy, browser permissions switched off for camera, microphone, geolocation and payment, a block on displaying the site inside a third party frame, attack and bot filtering at the Cloudflare edge, request rate limiting).

No system is perfect and the operator makes no absolute guarantee. The attack surface stays small by design, since the site holds no account, no password and no user database that could be stolen.

Changes to this policy

Any material change is published on this page and reflected in the update date shown at the bottom.