privacy

Your HTML,
and how data is handled.

Rendering happens in your browser. This page explains local storage, sharing, analytics and requests made by the site or your document.

What we collect

There is no account, and we do not ask for a name or email to use the viewer. The site uses hosting infrastructure and PostHog analytics. Analytics excludes your editor content and share-link fragments.

PostHog — cookieless by default

PostHog measures page views and feature use. By default it runs cookieless, without storing an analytics identifier on your device. PostHog processes request information on its servers to group cookieless activity; this is still data collection.

Accept enables an analytics cookie and a stable browser identifier to measure return visits. Decline keeps analytics cookieless; it does not turn off counting. You can change this choice below.

Your choice is remembered in localStorage. Our PostHog project uses its EU ingestion service, reached through the site’s /ingest proxy.

What it does receive

Excluded from analytics

What stays on your device

Clearing this site’s browser storage removes local drafts and preferences. Download a file to keep a separate copy. Clearing local storage does not delete analytics already received or copies you have shared.

How share-links work

Share compresses the editor source into the URL fragment after #. The browser does not include that fragment in its HTTP request to our server. Anyone receiving the full link can decode the document. It contains source, not live JavaScript state or form values. Sharing through another service gives that service the full link.

Third-party requests

The sandbox restricts access to the parent page; it does not block all network activity. Only open code and external resources you trust.

Updates

Last updated 2026-09-10. Material changes are announced in the changelog.