Payload and website data boundaries
A2UI Validator Privacy Notice
Raw A2UI payload processing is local. Website delivery, contact messages, and any future advertising have separate data boundaries explained below.
Privacy at a glance
Current application facts
A2UI payloads
The validator does not upload raw input
Input remains in the current page state and is sent to a same-origin Web Worker for parsing, schema checks, and semantic checks. The validator does not send the payload to a site API or put it in a URL, cookie, localStorage, IndexedDB, or application database. Refreshing or closing the page, or terminating the Worker, leaves no application-managed payload copy behind.
When you choose Copy result, the clipboard receives a safe diagnostic summary—not the original payload.
Email is a different path
Only share a sanitized reproduction
If you voluntarily include a payload in an email, it leaves the local validation path and is handled as part of that message. Do not email secrets, credentials, tokens, or a complete private payload. Reduce a correctness report to the minimum sanitized input needed to reproduce the issue.
Product analytics
Google Analytics measures website use
The site automatically loads Google Analytics measurement ID G-TV53PJGR16 on every route with Analytics and advertising storage set to denied. It sends cookieless page-view measurements for limited aggregate measurement and modeling. The configured page location and referrer are reduced to their origin and pathname, excluding query parameters and fragments. Google may still receive request information needed to deliver the measurement, including timestamps, browser or device metadata, and network information. Google states that Analytics does not store a client ID when Analytics storage is disabled.
This mode cannot recognize a returning visitor through Analytics cookies, and reports may be incomplete, especially while traffic is low. The nine product-funnel events remain only in the current page's in-memory window.__A2UI_EVENTS__ buffer and are not forwarded to Google Analytics. The application does not send the payload, full result, JSON Pointer, surface or component IDs, content hashes, clipboard contents, email address, or a user ID to Analytics.
Website delivery
Infrastructure may process standard request data
Vercel hosts the application and may process standard request information—such as IP address, user agent, requested path, and timestamp—for delivery, security, and fault diagnosis. Cloudflare currently provides domain and DNS services; this notice does not assume that Cloudflare proxies every HTTP request. Infrastructure data, when generated, follows the applicable provider configuration and retention settings.
Retention and security
Local payload handling is a scoped promise
The application does not persist validation payloads. That statement is narrower than claiming that a public website produces no network metadata or can guarantee absolute security. External providers and linked sites operate under their own terms and privacy notices.
Cookies and advertising
Analytics storage is always denied; advertising is not active
No Analytics prompt is shown because this release never offers or sends a storage grant. The Google tag is initialized before measurement with analytics_storage, ad_storage, ad_user_data, and ad_personalization all denied. It does not read or write _gaAnalytics cookies, and the site does not save an Analytics choice in localStorage. This is not the same as zero data transmission: the cookieless measurements described above are still sent to Google. The site does not currently serve third-party advertising. There is no Google AdSense script, publisher ID, or ads.txt record in this release.
Browser controls and future advertising
You can use browser privacy controls, a content blocker, or Google's Analytics opt-out add-on to block Analytics requests. Before advertising or a storage-enabled measurement mode is activated, this notice and the site's consent controls will be reviewed for the applicable regions. A real AdSense publisher ID will be used only after it is issued; no placeholder is published.
External links
Other sites have their own practices
Links to A2UI documentation, GitHub, Google, Vercel, or other sites are provided as references. Visiting them is governed by their own privacy notices and data practices.
Changes to this notice
Data-flow changes require a notice update
The original trust pages were published on July 17, 2026. This notice was last updated on July 18, 2026 and reflects automatic storage-denied Google Analytics. It must be reviewed again before advertising, accounts, persistence, or another material data flow is enabled.
Your choices and contact
Ask a privacy or correction question
You may avoid entering a payload, clear the page by refreshing or closing it, and use the contact address for a privacy or accuracy question without including private input. See About and contact guidance for a useful report format.