Legal
Privacy Policy
Read the MV Tools privacy policy, including accounts, Google and Apple sign-in, browser-based processing, server-assisted tools, cloud connections, temporary files, security logs, and account deletion.
Effective date: September 4, 2026
Overview
MV Tools provides browser-based and server-assisted utilities. This policy explains what data may be processed when you use the service.
Cloudridge Flow
Cloudridge Flow is an offline single-player game. The app does not collect, transmit, share, or sell personal data.
The app does not use advertising, analytics, tracking, accounts, or third-party data collection services. Game progress and settings are stored locally on the user’s device and are not transmitted to MV Tools or any third party.
For privacy questions, contact hi@mv.tools.
Rollision
Rollision is an offline single-player game for iPhone and iPad.
Rollision does not collect, transmit, share, or sell personal data. The game does not use advertising, analytics, tracking, user accounts, cloud saves, online multiplayer, or third-party data collection services.
Game settings, collected stars, unlocked balls, selected balls, tutorial status, and game records are stored only on the user’s device. This information is not transmitted to MV Tools or any third party. It remains on the device until the app or its local data is deleted. MV Tools cannot remotely access, restore, or delete this locally stored information.
Rollision includes an optional tilt-control mode. Motion sensor information is processed locally and in real time only to control gameplay. It is not stored, transmitted, or used for tracking.
Downloads and payments are handled by Apple under Apple’s own privacy practices. Rollision does not receive or store payment card information.
If Rollision’s data practices change in a future version, this policy and the App Store privacy information will be updated accordingly.
For privacy questions, contact hi@mv.tools.
Local browser processing
Some tools run entirely in your browser. For these tools, your input is not intentionally sent to the MV Tools server.
User accounts
You may create an account with an email address, password, and optional display name. Passwords are stored as hashes, not plaintext. Login sessions are used to keep you signed in and may be revoked from the account page.
Email and service messages
MV Tools may send verification codes, password reset emails, and account or security messages. These emails are used only for service operation and account security.
Feedback and contact requests
If you send feedback through the feedback form or by email, MV Tools may keep your message, email address if provided, related page, locale, IP address, and user agent so we can respond, fix issues, and prevent abuse.
Server-assisted processing
Some tools require server processing. Submitted content, URLs, keys, passwords, or files may be transmitted to the server only to complete the requested operation.
Temporary webhook endpoints store up to the latest 50 captured requests in Redis, redact sensitive headers, mask source IP addresses, and delete the data after 30 minutes or when the endpoint is destroyed.
Generated files are temporary. The default retention period is 30 minutes.
Login and security data
To protect the service, MV Tools may process IP address, user agent, timestamps, login attempts, verification failures, and similar security or abuse-prevention information.
Data we do not intentionally store
MV Tools does not intentionally store uploaded files, generated files, encryption passwords, private keys, plaintext, or decrypted output in a database beyond what is needed to complete the requested task.
Technical data
Infrastructure logs may include IP address, request path, user agent, timestamps, status codes, and error information. These logs are used for troubleshooting, security, and abuse prevention.
Google Analytics and optional cookies
With your permission, MV Tools uses Google Analytics to measure page views, language, device type, approximate region, and limited interactions such as starting a tool, reaching a result, downloading a result, or saving to cloud storage. Google Analytics may set cookies such as _ga.
MV Tools does not send tool inputs, submitted URLs, file names or contents, email addresses, cloud account details, or result links to Google Analytics. Advertising features and ad personalization signals are disabled. You can refuse or withdraw permission at any time through Cookie settings in the footer.
Third-party services
Requests may pass through DNS, CDN, hosting, or proxy providers. Target websites may receive requests from MV Tools infrastructure.
Connected cloud storage
If you connect Google Drive or Dropbox, MV Tools stores the provider type, provider account ID, email or display name, granted scopes, token expiry, and encrypted access or refresh tokens. A file is sent only when you manually choose to save it.
Removing a connection requests provider authorization revocation and then deletes stored credentials and folder mappings. Files already uploaded remain in your cloud account. Google and Dropbox apply their own policies, and limited security logs may be retained.
Account deletion and retention
You may request or start account deletion when that feature is available. Account deletion removes or disables core account data, but limited logs may be retained temporarily for security, abuse prevention, or legal reasons.
Your choices and requests
You can use browser-only tools without sending data to the server, delete your account, revoke sessions, and contact hi@mv.tools for privacy or deletion questions.
Your responsibilities
Do not submit sensitive information unless you understand that server-assisted tools require transmission to the server.
Scope of this policy
This policy covers the mv.tools website and its web services. Cloudridge Flow and Rollision are separate offline games, not MV Tools website features; their local-only practices are described above only to provide the disclosures used for those apps. The games do not use the MV Tools website account, analytics, or cloud storage.
Google and Apple sign-in
MV Tools offers optional Google sign-in and Sign in with Apple. When you choose a provider, it sends a stable provider user identifier and a verified email address; Apple may provide a private relay address and an optional name. MV Tools uses these claims to create, link, and authenticate your account, verify the email address, and send essential account or security messages.
MV Tools stores the provider identifier and email association needed for account login. We do not store your Google or Apple password, and OAuth access or refresh tokens used during sign-in are not stored in the account database. Short-lived authorization state and security values are discarded after the sign-in flow expires or completes. Google and Apple process authentication under their own policies. You can stop using a provider or manage its authorization through that provider.
Tool usage records
For server API tool requests, MV Tools may record a user or anonymous identifier, tool name, request and output byte counts, IP address, success or failure, failure reason, and timestamp. These records support quotas, service operation, aggregate usage reporting, security, and abuse prevention.
The tool-usage record does not intentionally contain the submitted file contents, plaintext inputs, or generated file contents. Usage and security records may be retained for as long as reasonably needed, including limited records that remain after account deletion.
Current server-assisted tools and retention
Current server-assisted tools include media and public-content downloads; image, PDF, OCR, audio, and video processing; document and design-file preview or conversion for CDR, PUB, VSD/VSDX, PPT/PPTX, EPS/PS, XPS/OXPS, PES/DST, EPUB, and EML; webpage-to-PDF and other URL tools; and temporary FTP, SFTP, Redis, MySQL, ownCloud, and Webhook services.
Uploaded files and generated outputs are normally cleaned automatically, with a default retention period of 30 minutes. Remote-download jobs can keep a completed result for up to 6 hours and a failed result for up to 30 minutes under the current configuration. Cloud-save job status is temporary and is normally cleaned after about 1 hour. Retention settings may change as the service evolves.
URL, media, and public-content tools
URL download, webpage-to-PDF, video, Instagram, and remote-download tools send the URL or requested public media to the relevant target website or external processing provider. Those targets may receive requests from MV Tools infrastructure and apply their own policies.
Use these tools only for public or authorized content. Do not submit private, internal, access-controlled, or sensitive URLs. You are responsible for copyright, privacy, terms-of-service, and other permissions related to content you request.
Cloud Transfer connections
Cloud Transfer is separate from the Google Drive or Dropbox save-to-cloud feature and from the remote-download connection. It currently supports Dropbox and pCloud and may add other providers. When you connect a cloud account, MV Tools stores the provider, provider account identifier, email or display name when supplied, granted scopes, expiry information, API host when needed, and an encrypted OAuth token. If you provide your own cloud app, its client ID and app metadata are stored with the app record, while the client secret is stored in encrypted form.
For a transfer, the server uses a short-lived, user-specific transfer configuration to copy the single file and paths you select between your connected cloud accounts. Temporary task state and path or file metadata may be held in server memory and are cleaned after completion or failure, normally within about 1 hour. The file is transferred to the cloud providers you selected; provider policies and permissions apply. Disconnecting an account removes its stored credentials, and deleting your MV Tools account removes its Cloud Transfer accounts and user-created app records.
Traffic balances and abuse safeguards
MV Tools maintains an account traffic balance and ledger of credits, debits, reserved amounts, system reasons, related tool or temporary task identifiers, manual adjustment notes, check-in state, and timestamps. This data is used to show balances and activity, avoid duplicate charges, operate requested transfers, resolve service issues, and prevent abuse. Traffic records do not intentionally contain file contents.
For anonymous download limits, MV Tools sets a necessary random visitor cookie for up to 30 days and may use hashed visitor and IP identifiers for quota and abuse controls. Cloudflare may process IP address and browser or security signals for rate limiting and bot verification under its own policies. After account deletion, MV Tools retains a one-way hash of the former email address for 10 days to prevent immediate repeat registration bonuses. The former balance cannot be accessed; limited traffic and security records may remain associated only with a deleted internal account record.
Google advertising and consent
If MV Tools enables Google advertising, advertising choices for visitors in the EEA, United Kingdom, and Switzerland are managed through a Google-certified consent management platform configured in Google AdSense Privacy & messaging. The advertising script is not enabled until that configuration is in place.
The footer Cookie settings control optional MV Tools analytics only. Advertising consent, withdrawal, and partner choices are provided through the advertising consent message when Google advertising is active.
Changes
This policy may be updated as the service changes.