Skip to main content
GARGLOO

Security & Privacy

Last updated: August 24, 2026

Trust is the product. Here is precisely how Gargloo is built to keep your data yours.

Operator note: this page contains configuration slots for legally required details (entity name, address, jurisdiction, contact emails). They are set via environment variables — see DEPLOYMENT.md. Replace every pending marker before announcing public traffic.

Your files never leave the browser

Every file tool works like a tiny app that was downloaded once: when you drop a file onto the page, JavaScript inside your tab reads the bytes, transforms them, and hands you a download. There is no upload endpoint for user files. We couldn't leak what we never receive.

Validation before trust

  • Uploaded files are checked by content signature (magic bytes), not just extension. A renamed executable won't pass as a JPEG.
  • File sizes and counts are limited per tool to protect your device memory.
  • Filenames are sanitized before reuse so nothing odd can be injected into downloads.

Hardened transport & headers

  • Content-Security-Policy restricting scripts, frames and connections.
  • X-Frame-Options DENY, nosniff, strict referrer policy, restrictive Permissions-Policy.
  • HSTS when served over HTTPS.

No accounts, no secrets client-side

There is no login to compromise. The internal admin area is protected server-side with a password and signed session cookie, rate-limited against guessing. No API keys ship in frontend code; secrets live only in server environment variables.

If server-side features ever exist

Some future tools (e.g. OCR) may genuinely need more compute than a phone can provide. If we add one, it will be labeled clearly on its page, will use encrypted transport, automatic deletion of temporary storage within minutes, and this page will be updated before launch.

Responsible disclosure

Found a vulnerability? Email To be completed before public launch. We'll acknowledge reports promptly and act in good faith on good-faith research.

Questions about this page? Contact us.