Browser-local tools
Inputs and outputs for Base64, JWT, Kubernetes Secret, URL, timestamp, cron, hash, and other marked local tools are processed in browser memory. They are not sent to ParseNest or included in analytics events.
Server-side tools
Tools explicitly marked as server-side transmit the submitted configuration for processing. Temporary workspaces are deleted after the request. Request bodies are not written to application logs.
Trusted certificate requests
For the trusted SSL tool, the private key is generated in your browser and is not sent to ParseNest. The public CSR, requested DNS names, and temporary ACME order state are processed by ParseNest and Let's Encrypt to validate control and issue the certificate. Issued certificates are public information and may be submitted to public Certificate Transparency logs. Temporary order state expires automatically.
Temporary webhook inboxes
A webhook inbox retains request methods, query values, selected headers, source addresses, content types, and bodies in the running server's memory for up to 30 minutes. Common credential headers are redacted, inbox data is not written to SQLite or application logs, and a restart may remove it earlier. Use test data only.
Service data
We may process basic request metadata, error counts, performance information, and coarse usage events to secure and improve the service. Account and billing data will be described before those features launch.
Cookies and advertising
Essential cookies may support security and sessions. If advertising or optional analytics is enabled, consent controls will be provided where required.
Contact
Questions or deletion requests can be sent through the contact page.