Privacy Policy

Privacy Policy

This Privacy Policy explains how GXA Technologies handles information in connection with GXA Toolbox. The platform combines browser-local tools, optional accounts, support features, hosting services, and Google Tag Manager, so it would be inaccurate to claim that no data is processed.

Last updated: 14 August 2026

Scope and service provider

This policy applies to the public GXA Toolbox website, generated tool routes, the Background Remover application, account features, and support interactions operated for GXA Toolbox by GXA Technologies.

External websites, browser extensions, downloaded files, and third-party services have their own practices. Links or embedded resources do not make GXA Technologies responsible for an external provider's policy.

Information you provide

Creating an account requires a full name, email address, and password. The password is transformed into a bcrypt hash for storage; it is not intended to be stored as plaintext. Account records also include role, status, premium status, and timestamps.

A support request can include the name, email address, and message entered in the Contact Support form. Careers, privacy, security, and other inquiries sent through that form are processed as support messages.

Files, tool inputs, and results

Many registered tools are designed to process selected files in browser memory. In those workflows, file contents are not intentionally uploaded to the account history endpoint. Results are normally made available through the browser for download.

Processing differs by tool. A tool may use browser APIs, WebAssembly, local models, or third-party code and data loaded over the network. If a tool or future feature requires server processing, the information needed for that request may be transmitted to the relevant endpoint and should be described in the tool interface.

Browser-local processing does not prevent files from remaining in browser memory, temporary object URLs, downloads, operating-system storage, backups, or other locations controlled by the user's device.

Account and processing history

For signed-in users, the service may store processing-history metadata including tool name, original and output filenames, file size, status, processing time, limited tool metadata, and timestamps. The current history schema does not contain a field for uploaded file contents.

The dashboard retrieves recent history associated with the authenticated account. Users should avoid placing sensitive personal data in filenames when they do not want that information recorded in account history.

Cookies and browser storage

Authentication uses a signed session cookie named gxa_toolbox_session. In production it is configured as HttpOnly, Secure, SameSite=Lax, and has a maximum age of seven days. The cookie supports sign-in and account access and can be cleared by signing out or clearing site data.

Local storage is used for theme preferences, favorites, recent tools, recent searches, local history compatibility, and an email address only when the user selects the remember-email option. Local storage remains on the device until the application or user clears it.

Analytics or other tags managed through Google Tag Manager may use cookies or similar technologies depending on the published container configuration and consent settings.

GXA Toolbox loads the official Google AdSense site code so the domain can be reviewed for advertising and Auto Ads can be enabled after account approval and configuration. When advertising is active, Google and its advertising partners may use cookies, identifiers, or similar technologies to deliver, limit, measure, and protect ads, subject to applicable consent requirements and the active AdSense settings.

Analytics, diagnostics, and hosting logs

GXA Toolbox includes Google Tag Manager to manage measurement tags. Google Analytics 4 may be configured through that container; the website source does not directly install a separate GA4 gtag.js loader. When enabled, measurement may include pages viewed, interactions, browser and device information, referrer information, approximate location derived from network information, and analytics identifiers, subject to the active tag and consent configuration.

Hosting and network providers may process request information such as IP address, user agent, requested path, time, response status, and diagnostic logs to deliver, secure, and troubleshoot the service.

Third-party services

The current architecture uses Netlify for hosting, functions, and database connectivity; Google Tag Manager, Google AdSense, and Google-hosted fonts; and content-delivery networks such as unpkg, cdnjs, and jsDelivr for selected libraries, workers, fonts, language data, or tool dependencies.

These providers may receive network and device information needed to deliver their resources. Their independent processing is governed by their own terms and privacy notices.

Why information is processed

  • Provide tools, account access, downloads, preferences, support, and requested service features.
  • Authenticate users, maintain sessions, display account history, and protect the service from misuse.
  • Measure usage and diagnose reliability or performance where analytics or logs are enabled.
  • Prepare, deliver, measure, secure, and limit advertising when AdSense is approved and advertising is enabled.
  • Respond to legal requests, enforce terms, and protect users, GXA Technologies, and the public where required.

Retention

Account records, processing-history metadata, and support messages may be retained for as long as reasonably needed to provide the service, maintain account records, respond to inquiries, address security or legal needs, and resolve disputes. The repository does not define one universal deletion period for every record type.

Session cookies expire or are cleared as described above. Browser local storage remains until cleared. Hosting and analytics providers apply their own configured retention periods. A verified deletion request will be assessed against operational and legal retention needs.

Security

GXA Technologies uses measures reflected in the current architecture, including HTTPS, password hashing, signed session tokens, same-origin request checks, response security headers, data minimization, and browser-local processing where appropriate.

No online system is completely secure. Users should protect account credentials, use trusted devices, review downloaded results, and avoid submitting information that is not needed for the selected task.

Your choices and requests

Users can avoid creating an account for public tools that do not require one, decline the remember-email option, clear cookies and local storage, control browser permissions, and use browser privacy controls. Blocking required storage or scripts may prevent some features from working.

Requests to access, correct, or delete account or support information can be submitted through Contact Support. GXA Technologies may need to verify identity and may retain information when required for security, legal, or legitimate operational reasons.

Children, international users, and policy changes

GXA Toolbox is a general utility service and is not intentionally directed to children who cannot lawfully consent to the relevant processing. A parent or guardian who believes a child submitted personal information should contact GXA Technologies.

Users may access the service from countries different from the locations used by GXA Technologies and its providers. This can involve international processing subject to applicable safeguards and provider arrangements.

This policy may change as the product, law, or provider configuration changes. Material revisions will be published on this route with an updated date.

Contact

Privacy question or request?

Use Contact Support and clearly state that your message concerns privacy or personal data.

Contact About Privacy