Privacy Policy
Metools collects only what it needs to run: an account if you choose to create one, a record of which tools get opened so we know what to improve, and a payment record if you upgrade to Pro. Most of our tools do all their work inside your browser and never upload anything. This page explains the rest in plain language.
What we collect
- Account details, only if you register: your username, your email address, and either a one-way hash of your password or the account identifier Google gives us.
- Tool usage: one record each time you open a tool, holding the tool name, the site language, and the date and time.
- Payment records, only if you buy Pro: the amount, the plan length, the payment method, the status, and the payment provider's reference number — plus your transfer slip image if you pay by PromptPay.
- Technical data used to prevent abuse: a one-way hash of your network address that changes every day (never the address itself), and per-day counts of how often each tool was used.
Accounts and signing in
You can use almost every tool without an account. If you register, we store your username, your email, and a one-way hash of your password — we never store or see the password itself. If you sign in with Google instead, we receive your email address and the account identifier Google issues; we store nothing else from your Google profile, and such an account has no password at all. Staying signed in works through the mt_session cookie, which holds a random token pointing at a session record on our server. It expires after 30 days, and it records no IP address and no device information.
Deleting your account
Open your account page and choose to delete your account — you confirm with your password, or by ticking the confirmation box if you signed up with Google. Deleting removes your account and, along with it, your login sessions, any password-reset tokens, and your payment records. Your past tool-usage records remain, but they are detached from you and no longer identify anyone. One thing automatic deletion does not cover: a PromptPay slip image you uploaded stays on the server as a file. Email us and we will delete it.
Payments
Card numbers never reach our server. If you pay by card through Stripe, you are sent to Stripe's own checkout page and we only learn the reference number of the finished session. If you pay by card through Omise, Omise's own script turns the card into a token inside your browser, and only that token reaches us. If you pay by PromptPay, you upload a picture of your transfer slip; it is stored outside the public web folder and only a site administrator can open it, in order to check your payment. Whichever method you use, we keep a payment record with the amount, the plan length, the method, the status and the provider's reference.
Cookies and browser storage
We set no tracking cookies. Metools uses these, all of them functional:
- mt_lang — the language you chose. One year.
- mt_csrf — a security token proving a request really came from our own pages. 30 days.
- mt_session — proves you are signed in. Set only after you sign in; 30 days.
- mt_oauth_state — a short-lived value that protects a Google sign-in from tampering. 10 minutes, and removed as soon as sign-in finishes.
Your browser also keeps a "recently used tools" list (mt_recent) and a marker for the tools already counted during this visit. Both stay on your device, are never sent to us, and disappear when you clear your browser data.
How we measure tool usage
When you open a tool, your browser sends us a short message naming that tool — once per tool per visit. If you are signed in, the record is linked to your account, and a site administrator can see which tools you used and when. If you are not signed in, the record carries no name and no IP address: only a hash built from your network address, a secret value, and today's date. Because the date is part of it, the hash changes every day and cannot be used to follow you from one day to the next, and the raw address is never written to a file or the database. We use this to see which tools people actually use and which ones deserve more work.
Tools that run entirely in your browser
117 of our 129 tools do all their work on your own device. What you type, paste or open never leaves your browser, and files are never uploaded — we only ever learn that the tool was opened, never what you put into it. Twelve tools have to ask our server, and they send exactly what the job requires:
- Meta Tag Analyzer, Heading Structure Checker, Link Analyzer, Redirect Chain Checker, Bulk HTTP Status Checker, Robots.txt Tester and Social Share Preview send the web address you entered, and our fetcher loads that page for you. The fetched page is re-used from a cache for about ten minutes, and the cached copy is cleared off our server a couple of hours later.
- DNS Lookup and Proxy Checker send the domain name, or the proxy address and port, that you asked about.
- Currency Converter sends the amount and the currencies; the exchange rates come from a public rates service.
- Random Face Generator asks a public image service for a picture. Nothing about you is sent.
- Password Breach Checker never sends your password — see below.
The Password Breach Checker deserves the detail: your password stays in your browser. Your browser hashes it and sends only the first five characters of that hash, so the breach database can be searched without anyone — including us — learning the password or even which entry you were looking for.
Advertising
The banner ads we sell are hosted on this site by us. They are plain images with a link: no third-party ad script, no cross-site tracking, and no profile of you. We count how many times each banner was shown and how many times it was clicked, as a running total per banner, never per person. A click passes through our own link so it can be counted, then sends you on to the advertiser. Pro members see no ads at all.
One honest caveat: the admin settings include fields where an outside ad network's code (Google AdSense, for example) can be pasted in, and while ads are switched on our security policy permits Google's ad domains to load. If that code is ever in use, that network — not Metools — can set its own cookies and track you across sites under its own privacy policy. While those fields are empty, no third-party ad code runs on this site.
Limits and abuse prevention
Server-side tools are rate-limited, and guests and free accounts may have a daily quota. Both are counted against your account if you are signed in, or against the daily-changing hash described above if you are not. Rate-limit records are deleted after two days.
How long we keep things
- Account details: until you delete your account.
- Login sessions: 30 days, with expired ones cleared automatically.
- Password-reset links: one hour, and they are deleted the moment they are used.
- Rate-limit records: two days.
- Web pages fetched by the URL tools: re-used for about ten minutes, and the cached copy is cleared off the server a couple of hours later.
- Server logs: up to 14 days, then deleted automatically.
- Tool-usage records: kept while the site operates. When you delete your account they stay only in a form that no longer identifies you.
- Payment records, uploaded payment slips and your daily usage counts: deleted together with your account.
Your rights under the PDPA
Thailand's Personal Data Protection Act gives you the right to ask what personal data we hold about you, to receive a copy of it, to have it corrected, and to have it deleted. You can change your own details and delete your account yourself, at any time, from your account page. Deleting your account also removes your payment records, any payment slip you uploaded, and your usage counts. For anything else — such as a copy of your data — email [email protected] and we will answer. If you believe we have mishandled your data, you also have the right to complain to Thailand's Personal Data Protection Committee.
Changes to this policy
If what we collect changes, this page changes with it. Last updated 21 July 2026.