Privacy Policy

Last updated: September 8, 2026

Overview

DiffPeek is a browser-based diff tool. Folder, file, text, code, structured-data, and image comparisons are performed inside your browser using JavaScript. The files, images, and pasted content you compare are not sent to DiffPeek servers.

Information we collect

DiffPeek uses limited anonymous usage data through Google Analytics 4 (GA4) to understand how people use the product and improve it. Analytics is enabled by default and can be disabled at any time through Analytics settings in the footer. This may include:

Analytics events never include filenames, paths, file contents, pasted text, or individual diff output. Completion events may include the tool used, broad count buckets (such as 1–10 or 11–100), a general added/modified/deleted status, and whether the inputs matched. These aggregate signals cannot reconstruct what you compared. Google signals and advertising personalisation are disabled in our analytics configuration.

Cookies

Analytics is enabled by default. Use Analytics settings in the footer to disable or re-enable it. Your choice is stored in your browser's local storage so the site can remember it. Disabling analytics removes DiffPeek-hosted Google Analytics cookies and blocks later product events. Global Privacy Control and browser Do Not Track signals are honoured by keeping analytics off.

Your comparison content

Comparisons happen locally in your browser. Files and images you select or drag into DiffPeek are read through browser APIs and are not uploaded by DiffPeek. Pasted text and generated exports remain on your device unless you choose to save or share them yourself. Like any hosted JavaScript application, this promise depends on the code served to your browser; it is a product policy and tested design boundary, not a third-party security certification.

Third-party services

When analytics is enabled, DiffPeek uses:

Verify this boundary yourself

Use synthetic text such as DIFFPEEK-SYNTHETIC-SENTINEL-20260908, never a real secret. Clear this site's data, open the browser Network panel with Preserve log enabled, and test with analytics enabled, after disabling it, and after re-enabling it through Analytics settings.

  1. Run text, folder, JSON, CSV, and image comparisons containing the synthetic sentinel.
  2. Search request URLs, query strings, headers, request bodies, referrers, analytics calls, and console/error traffic for the full sentinel and a distinctive substring.
  3. While analytics is enabled, confirm only aggregate allow-listed event fields occur and the sentinel, filenames, paths, contents, hashes, and exact diff lines are absent. After disabling analytics, confirm later product actions make no new analytics requests.
  4. Use Save on this device on Text Compare and confirm the content appears only in the page-scoped Local Storage entry. Delete it and confirm the entry is removed.
  5. Record the browser/version, operating system, page/build version, consent state, contacted hosts, and sanitized evidence.

This inspection demonstrates what that browser session transmitted; it is not a certification and cannot account for browser extensions, device monitoring, or software that handles downloaded files.

Children's privacy

DiffPeek is a developer tool not directed at children under 13. We do not knowingly collect personal information from children.

Changes to this policy

We may update this policy from time to time. The date at the top of this page reflects the latest revision. Continued use of DiffPeek after changes constitutes acceptance of the updated policy.

Contact

If you have questions about this privacy policy, please contact us at privacy@diffpeek.com.