Artefakt Toolbox
English

← Back to the home page

Security and trust

Here is what the toolbox does with your data, how tools are isolated and how the gallery is checked – including where the limits are.

What stays on your device

Tools, their data, your settings and backups live on your device. The app uploads none of it.

There is no account, no advertising and no tracking in the app.

What happens online

When you open it, your device loads the app and its updates from the web address. Downloading tools from the gallery is added when you pick one.

In both cases only the download happens. Your tools, data and entries are not transmitted.

How tools are isolated

Every tool runs in its own isolated area. It can neither read your library nor the data of other tools.

A tool gets the microphone or the camera only if you allow it under “Permissions”. With this extended permission the tool no longer runs isolated and could read your library and the data of other tools. Allow it only for tools you trust, for example your own. A database of its own (IndexedDB) also runs isolated. A tool may send data to other tools only with your release for exactly that pair.

How the gallery is checked

At launch only the project itself adds tools. On every build an automatic check looks for suspicious patterns such as network access, loaded files or obfuscated code, plus a size limit of 90 KB. A tool that fails appears nowhere. Every tool is also reviewed by hand and tested automatically, accessibility included.

A check is a filter, not proof. That is why every gallery tool runs just as isolated as any other and gets no extended rights without your consent.

If you find a problem

If a tool behaves wrongly, report it via the contact address in the imprint, ideally with the tool’s name, version and checksum. You find these on the tool’s page in the gallery. It will be reviewed and removed from the gallery if needed.