- VoidTools does not operate a central database containing your workspace files, scans, reports or tool inputs.
- Your account and sign-in are provided by Clerk, which necessarily processes account and session data.
- Application settings, histories and outputs are generally stored locally on your Windows device.
- The public website has no first-party advertising or analytics tracker, but GitHub Pages and Google Fonts receive technical requests.
- Features you choose to run may contact third-party APIs or targets and disclose the submitted input and your network address to them.
1. Scope and who is responsible
This Privacy Policy applies to voidtools.software, the VoidTools desktop application, VoidTools accounts and related downloads, updates and support channels (the “Services”). The Services are operated under the VoidTools name by kixo_oio, who is the controller for personal data processed for VoidTools’ own purposes (“VoidTools”, “we”, “us” or “our”).
Some providers process information under their own policies or on our behalf. In particular, Clerk provides identity and account management. This Policy does not control independent websites, APIs or services that you choose to use through a link or feature.
2. No central VoidTools application database
We do not operate our own remote database for user profiles, workspace content, tool inputs, scan history, reports, backups or application settings. We do not receive a copy of local working data merely because you use the application.
This does not mean that no data is processed anywhere. Clerk stores the information required to provide your account. Hosting, font, download, identity and any feature-specific provider may process technical or submitted information as described below. Your device also stores local application data.
3. Public website and download data
You can browse the public website without creating an account. The website does not contain a contact form and we do not place our own advertising or analytics tracker on it.
The website is hosted by GitHub Pages. When you visit, GitHub logs and stores the visitor IP address for security purposes and may process request time, requested URL, browser or device headers and related operational logs under the GitHub Privacy Statement. When you request a release or update, GitHub also receives the information necessary to deliver that file.
The website loads DM Mono and Manrope from Google Fonts. The browser therefore sends Google the IP address, requested resource URL and HTTP headers such as user agent and referrer. Google states that the Google Fonts Web API does not set or log cookies and does not use this information to profile end users or for targeted advertising. See the Google Fonts privacy FAQ.
4. Accounts, authentication and subscriptions through Clerk
The desktop application uses Clerk, Inc. for registration, sign-in, session management, profile management and, where available, subscriptions. Depending on how you sign in and configure your profile, Clerk may process:
- account identifiers, email address, name, username, profile image and authentication factors;
- information received from an identity provider you select, such as Google;
- session tokens, IP address, device, browser/WebView, approximate location, timestamps and security events;
- plan, subscription, billing status and transaction-related information where a paid plan is used.
VoidTools does not receive or store your password or full payment-card details. The application receives a signed session token and validates it locally using Clerk’s public signing keys so it can confirm that a session is authentic. Account and subscription details shown inside the application are retrieved through Clerk.
For customer account data, VoidTools determines the purpose of using Clerk for authentication and Clerk acts as a processor or service provider as applicable. Clerk may also process certain information for its own security, service and legal purposes. Review the Clerk Privacy Policy, GDPR notice and Data Processing Addendum.
5. Data stored locally by the application
Depending on the features you use, VoidTools may store settings, interface preferences, recent-file or recent-program history, backup records, scan history, generated reports, logs and cached application state on your device. Storage can include Windows Local AppData, other folders you select, and WebView/browser local storage.
Tool inputs and outputs—including source code, domains, IP addresses, OSINT queries, file paths, reports and backups—are generally processed and stored locally unless you deliberately use a feature that contacts an external service or target. You control the device and are responsible for access permissions, encryption, backups, retention and secure deletion.
Signing out or deleting your Clerk account does not necessarily delete local files. Uninstalling may also leave reports, backups, settings or caches. You can remove local information using the application’s available reset/delete controls and Windows file-management tools. Deleting backups or local application folders can be irreversible.
6. Feature-initiated network requests
VoidTools includes features that may contact a website you specify, GitHub update endpoints, Clerk, public information sources, media/catalogue providers, geolocation services, DNS/WHOIS infrastructure, QR services or other third-party APIs. The exact provider depends on the feature and may change as services evolve.
When you initiate such a feature, the receiving service can see your IP address and request metadata and may receive the value required for that request, such as a domain, IP address, username, public email address, search term, media identifier or text encoded into a QR request. A target you scan or test can also observe and log the request. Do not submit personal data, confidential information or a target unless you have a lawful basis and authorisation.
Third-party services determine their own logging, retention, security and international-transfer practices. VoidTools is not responsible for their independent processing. Review the provider’s policy before using a feature if the data is sensitive.
7. Support and Discord communications
If you contact us through Discord, we receive the information you choose to send, your Discord account details visible to us and the surrounding message metadata. We use it to respond, provide support, investigate abuse or security issues and keep necessary records. Discord independently processes communications under its own terms and privacy policy.
Do not send passwords, session tokens, private keys, payment-card data, unredacted logs containing secrets, or personal data you are not authorised to disclose.
8. Purposes and legal bases
Where data-protection law requires a legal basis, we process limited personal data as follows:
- Contract: to create and secure your account, authenticate sessions, provide requested features, manage an eligible subscription and deliver support.
- Legitimate interests: to secure the Services, prevent fraud and abuse, diagnose faults, protect legal rights, maintain releases and improve reliability, provided those interests are not overridden by your rights.
- Legal obligation: to comply with valid legal requests, accounting, tax, consumer-protection or security obligations where applicable.
- Consent: where we specifically ask for it. You may withdraw consent at any time without affecting earlier lawful processing.
We do not sell personal data. We do not use account data for third-party behavioural advertising. We do not make decisions producing legal or similarly significant effects solely by automated means.
10. Retention
Because VoidTools has no central workspace database, we do not centrally retain your tool inputs, reports or local settings. Local information remains until you delete it, overwrite it, clear the relevant storage or remove the device, subject to your own backups.
Clerk retains account and security information according to its contractual settings, policies and legal obligations. GitHub, Google, Discord and feature-specific providers retain technical or submitted information under their own policies. We keep direct support or legal correspondence only as long as reasonably necessary to answer the request, protect rights, resolve disputes and meet legal obligations.
11. Your privacy rights and choices
Depending on your location, you may have the right to request access, correction, deletion, restriction, objection or portability; withdraw consent; and complain to a competent data-protection authority. These rights may be limited by lawful exceptions and apply to personal data—not anonymous information or files held only by you.
You can manage much of your Clerk profile and eligible subscription through the in-app account panel. For a request relating to VoidTools-controlled account data, contact us using Section 14. We may need to verify your identity. If the information is controlled independently by GitHub, Google, Discord or another provider, send the request to that provider. You can delete local application data directly from your own device.
You can reduce website disclosures by blocking third-party fonts, avoiding external links or downloads, and using browser privacy controls, although parts of the Services may not work correctly.
12. Security and your responsibilities
We use measures appropriate to the Services, including provider-managed authentication and local verification of signed session tokens. However, no device, transmission, software or third-party service is completely secure. We cannot guarantee absolute security.
You are responsible for securing your Windows account and device, installing trusted updates, protecting sign-in methods, restricting access to local reports and backups, and removing secrets before sharing logs. Notify us promptly if you believe a VoidTools account or Service has been compromised.
13. Children and policy changes
The Services are not intended for anyone under 18, and we do not knowingly offer accounts to children. If you believe a child has provided account information, contact us so the issue can be investigated with Clerk.
We may update this Policy when the Services, providers or law change. The date at the top identifies the current version. We will provide additional notice of material changes where required by law.
14. Contact
For privacy questions or to exercise a right concerning data controlled by VoidTools, contact kixo_oio through the official VoidTools Discord and clearly mark the message “Privacy Request”. Do not include secrets or unnecessary identity documents in the first message.
For Clerk’s independent processing or Clerk-specific support, use the contact details in the Clerk Privacy Policy. You may also lodge a complaint with the data-protection authority competent for your place of residence or work where applicable.