Colophon
How this manual handles your data
§1 Everything runs locally
Every tool is plain JavaScript running in your browser. There is no backend and no cookies.
Input is kept in the URL fragment (the part after #) so links can be shared;
browsers never send the fragment to a server. Tokens, keys, passwords and certificates are never
written there.
§2 The browser enforces it
The site ships a Content-Security-Policy that limits outgoing connections to this site, the
DNS-over-HTTPS resolvers cloudflare-dns.com and dns.google, and the
statistics service in §4. Any other request is blocked by the browser itself, so a bug or a
compromised dependency cannot quietly send data elsewhere.
§3 Network use is marked
A tool that needs the network (the DNS lookup and the SPF and DMARC checks) carries a Network stamp naming the host and what is sent. It only makes the request when you press its button, never while you type. Every other tool carries a Local only stamp.
§4 Page-view statistics
The site counts page views with a self-hosted statistics service at t.vo.rs. It
receives the page path (for example /cidr), never the part after ? or #, and never anything you type into a tool. A content blocker that blocks it does
not affect the tools.
§5 Works offline
After your first visit the whole manual is stored by your browser, so every tool except the network lookups works without a connection. You can also install it as an app from the browser menu.
§6 Type
Set in Atkinson Hyperlegible Next and Atkinson Hyperlegible Mono by the Braille Institute, chosen because they keep 0/O, 1/l/I and rn/m apart. Fonts are served from this site.