Technical transparency

What stays local, and what still leaves your browser.

TaskThimble is local-first, not network-free. Active tool contents are handled in browser code; coarse first-party product events may still be sent to TaskThimble's backend.

1. Active input

Pasted text, lists, CSV/TSV, supported JSON and XLSX worksheet values are read by browser JavaScript. They are not included in analytics payloads.

2. Temporary workbench

Compatible list and table results can be stored locally in your browser for up to 12 hours so another tool can continue the task.

3. Product events

Events such as starting or completing a tool, exporting a result or continuing a result in another TaskThimble tool can be sent to the first-party API with limited metadata only.

Examples of excluded content

TaskThimble analytics excludes file names, worksheet names, column names, pasted values, email addresses, URLs, cell contents and JSON values. Tool code may of course read those values locally in order to perform the requested operation.

Examples of analytics metadata

A permitted event may record which tool was used, the general input type, an approximate size or row range, whether the action succeeded, the export type and whether a result continued to another TaskThimble tool. This is enough to learn whether the product flow works without copying the user's data into analytics.

Why this matters

“Everything happens locally” can be misleading when a website still uses analytics or normal hosting infrastructure. Your active dataset can stay local while ordinary web requests and privacy-minimised product events still reach the service. TaskThimble explains that distinction instead of claiming that the website makes no network requests.

Rule-based by default

Most TaskThimble tools use clear browser-based rules rather than AI calls. If a tool uses an external AI service, the tool must explain that before user content is sent to that service.