Last updated June 23, 2026
Toolumen is built so that, wherever possible, your data never leaves your device. Most of our tools — including the Contrast Checker, HEIC Converter, and the in-browser PNG to SVG Vectorizer — run entirely in your browser. The files you process with them are decoded, converted, and rendered locally and are never uploaded to our servers.
There are a small number of named exceptions where data must reach a server to deliver the feature you asked for:
Outside of these exceptions, the contents of the files you work with stay in your browser.
All connections to Toolumen are encrypted with HTTPS using TLS. This applies to page loads, authentication, payments, and every request to the server-side tools listed above. We do not serve any part of Toolumen over unencrypted HTTP.
Authentication and account management are handled by Clerk. Clerk manages your credentials and sessions; Toolumen does not store your password. Sessions are issued and validated through Clerk, and session tokens are transmitted only over HTTPS. You can sign out at any time to end a session.
Payments are processed by Stripe, a PCI-compliant payment provider. When you subscribe to a paid plan, your card details are collected and stored by Stripe — Toolumen never sees, handles, or stores your full card number. We retain only a record of your subscription status, plan, and billing history.
If you generate an API key to use a server-side feature such as the Elite vectorize API, that key is shown to you only once at the moment of creation. We store only a SHA-256 hash of the key, never the raw value. Because we cannot recover the original key, you should store it securely when it is shown; if you lose it, generate a new one and revoke the old one.
Toolumen is hosted on Webflow Cloud, which runs on Cloudflare Workers at the edge. Our code executes across Cloudflare's distributed network, which provides TLS termination, DDoS mitigation, and edge delivery close to where you are. We rely on this infrastructure for the availability and network-level security of the site.
The tools that run entirely in your browser do not send the contents of your files, or telemetry about them, back to us. There is no background upload of the data you process locally. The only information that reaches our servers from those tools is what is necessary to load the page itself.
We rely on a small set of trusted service providers to operate Toolumen:
Each provider maintains its own security practices for the data it handles on our behalf. For more on what data reaches these providers, see our Privacy Policy.
We welcome good-faith security research and value reports from the community. If you discover a vulnerability, please email us at apps@stacklumen.com with enough detail for us to reproduce and investigate the issue.
While researching, please act in good faith: do not access, modify, or delete data that does not belong to you, do not degrade the service for other users, and give us a reasonable opportunity to respond before any public disclosure. We will not pursue action against researchers who follow these principles.
We retain account, billing, and subscription data for as long as your account is active or as needed to provide our services and meet legal obligations. If you would like your data deleted, contact us at apps@stacklumen.com or apps@stacklumen.com, or use our contact page, and we will process your request in accordance with applicable law. See our Privacy Policy for more detail on retention.
We may update this Security & Trust page from time to time as our practices and infrastructure evolve. When we make material changes, we will update the "Last updated" date at the top of this page.
For security questions or to report a vulnerability, reach our security team at apps@stacklumen.com. For general help, contact apps@stacklumen.com or use our contact page.
This document is a general template provided for convenience and is not legal advice. Have it reviewed by qualified counsel before relying on it. Questions? Contact us.