Payload and website data boundaries

A2UI Validator Privacy Notice

Raw A2UI payload processing is local. Website delivery, contact messages, and any future advertising have separate data boundaries explained below.

Effective July 18, 2026 · Google AdSense is not active

Privacy at a glance

Current application facts

Validation payloadProcessed in your browser
AccountsNone
Google AnalyticsAutomatic, with Analytics storage denied
Third-party advertisingNot currently enabled

A2UI payloads

The validator does not upload raw input

Input remains in the current page state and is sent to a same-origin Web Worker for parsing, schema checks, and semantic checks. The validator does not send the payload to a site API or put it in a URL, cookie, localStorage, IndexedDB, or application database. Refreshing or closing the page, or terminating the Worker, leaves no application-managed payload copy behind.

When you choose Copy result, the clipboard receives a safe diagnostic summary—not the original payload.

Email is a different path

Only share a sanitized reproduction

If you voluntarily include a payload in an email, it leaves the local validation path and is handled as part of that message. Do not email secrets, credentials, tokens, or a complete private payload. Reduce a correctness report to the minimum sanitized input needed to reproduce the issue.

Product analytics

Google Analytics measures website use

The site automatically loads Google Analytics measurement ID G-TV53PJGR16 on every route with Analytics and advertising storage set to denied. It sends cookieless page-view measurements for limited aggregate measurement and modeling. The configured page location and referrer are reduced to their origin and pathname, excluding query parameters and fragments. Google may still receive request information needed to deliver the measurement, including timestamps, browser or device metadata, and network information. Google states that Analytics does not store a client ID when Analytics storage is disabled.

This mode cannot recognize a returning visitor through Analytics cookies, and reports may be incomplete, especially while traffic is low. The nine product-funnel events remain only in the current page's in-memory window.__A2UI_EVENTS__ buffer and are not forwarded to Google Analytics. The application does not send the payload, full result, JSON Pointer, surface or component IDs, content hashes, clipboard contents, email address, or a user ID to Analytics.

Website delivery

Infrastructure may process standard request data

Vercel hosts the application and may process standard request information—such as IP address, user agent, requested path, and timestamp—for delivery, security, and fault diagnosis. Cloudflare currently provides domain and DNS services; this notice does not assume that Cloudflare proxies every HTTP request. Infrastructure data, when generated, follows the applicable provider configuration and retention settings.

Retention and security

Local payload handling is a scoped promise

The application does not persist validation payloads. That statement is narrower than claiming that a public website produces no network metadata or can guarantee absolute security. External providers and linked sites operate under their own terms and privacy notices.

Cookies and advertising

Analytics storage is always denied; advertising is not active

No Analytics prompt is shown because this release never offers or sends a storage grant. The Google tag is initialized before measurement with analytics_storage, ad_storage, ad_user_data, and ad_personalization all denied. It does not read or write _gaAnalytics cookies, and the site does not save an Analytics choice in localStorage. This is not the same as zero data transmission: the cookieless measurements described above are still sent to Google. The site does not currently serve third-party advertising. There is no Google AdSense script, publisher ID, or ads.txt record in this release.

Browser controls and future advertising

You can use browser privacy controls, a content blocker, or Google's Analytics opt-out add-on to block Analytics requests. Before advertising or a storage-enabled measurement mode is activated, this notice and the site's consent controls will be reviewed for the applicable regions. A real AdSense publisher ID will be used only after it is issued; no placeholder is published.

External links

Links to A2UI documentation, GitHub, Google, Vercel, or other sites are provided as references. Visiting them is governed by their own privacy notices and data practices.

Changes to this notice

Data-flow changes require a notice update

The original trust pages were published on July 17, 2026. This notice was last updated on July 18, 2026 and reflects automatic storage-denied Google Analytics. It must be reviewed again before advertising, accounts, persistence, or another material data flow is enabled.

Your choices and contact

Ask a privacy or correction question

You may avoid entering a payload, clear the page by refreshing or closing it, and use the contact address for a privacy or accuracy question without including private input. See About and contact guidance for a useful report format.

Production contact addresssupport@a2ui-validator.com