Trust
Privacy
Your input and generated output stay in the active page’s memory. Typing and pasting trigger no analytics, error reporting, storage, URL, page metadata, or network requests.
Text stays in the browser
Text transformation and result display run in your browser. Typing, pasting, and clearing emit no analytics event or error report, write no storage, change no URL, history entry, or page metadata, and trigger no network request. Input-driven transform failures stay local to the affected result card.
The copy fallback runs locally too. Only an explicit copy action may emit the fixed copy-attempt and outcome events; LettroCraft does not send the input, generated output, clipboard contents, text length, text hash, URL, query string, referrer, DOM, raw error, or stack trace.
Published previews may load versioned same-origin CSS and content-hashed WOFF2 subsets from fonts.lettrocraft.com. Resource URLs come only from the published catalog and never contain input or generated text. Your input remains in the active page’s memory, and copying returns Unicode characters rather than the preview font.
Do not place sensitive information into decorative text merely because transformation is local. The app where you later paste the result has its own privacy practices.
The five permitted events
The event names are tool_view, style_filter_used, copy_attempt, copy_success, and copy_error. There is no input event. The fixed success rate is copy_success divided by copy_attempt; the fixed error rate is copy_error divided by copy_attempt.
Allowed common fields are event name and version, random event ID, event time, ephemeral session ID, page ID, device class, locale, and build ID. Depending on the event, the allowlist may also include preset, filter transition, visible result count, random attempt ID, style ID, category ID, copy method, latency bucket, or a sanitized enumerated error code.
A separate best-effort error reporter accepts only a sanitized enumerated code, page ID, optional style ID, and build ID. It does not accept user text, text length, clipboard contents, a URL or query, request metadata, a raw error or stack, DOM content, a text hash, Base64, or another encoded form of user text.
Cloudflare processing and retention
Cloudflare necessarily processes ordinary network metadata, such as an IP address and user-agent, when it delivers or protects a request. LettroCraft’s event payload does not include those values, and the Analytics Engine row mapping does not store them as event fields.
In production, the five permitted event types are written to the lettrocraft_events_v1 Analytics Engine dataset, and sanitized error rows are written to lettrocraft_errors_v1. Both use a three-month retention period. Missing or unavailable bindings fail closed; they never cause input or generated text to be collected.
Questions and choices
LettroCraft has no account, profile, public text URL, database, or session-replay feature in this release. An ephemeral session identifier supports aggregate funnel counting and is not a user-text field.
For a privacy question, use the currently published address on the Contact page.