Welcome to RexaKit! With 13+ local-first tools, we respect your privacy and represent a new era of software: Client-Side Sovereignty. This document outlines exactly how we handle (or don't handle) your data.
1. THE ZERO-DATA PHILOSOPHY
RexaKit is built on a "Local-First" architecture. This means:
- No Server Storage: Whatever you type, calculate, or play with stays on your machine. We have no database to store your Todo lists, birth dates, or game high scores.
- No Accounts Required: You don't need to sign up, sign in, or give us your email to use our tools.
2. LOCAL STORAGE, INDEXEDDB & COOKIES
We use standard browser technologies to enhance your experience:
- LocalStorage: We may save preferences (like dark mode or your last Todo list items) directly in your browser's LocalStorage. This data persists on your device but is never sent to us. Clearing your browser cache will wipe this data.
- IndexedDB: Certain tools (Link Vault, Trading Journal, PDF Lab) use IndexedDB for structured data storage. This data stays entirely in your browser and is never transmitted to our servers.
- Cookies: We do not use tracking cookies. Technical cookies may be used strictly for network performance (e.g., Cloudflare or similar CDNs).
3. REXAVAULT & GOOGLE DRIVE BACKUP
We offer a secure, optional synchronization system called RexaVault to back up and restore your tool data:
- Sovereign Cloud Storage: If you choose to sync your data, it is saved directly to your personal Google Drive account in a designated JSON file (
rexakit_backup.json). We do not own, maintain, or have access to any external databases where this backup is stored. - Per-Tool Granularity: You can select exactly which tools' data to include in the backup — Todo, Quick Note, Expense Tracker, Decision Matrix, Movie Hub watchlist, Infinity Canvas, Link Vault, Trading Journal, PDF Lab documents, and your workspace layout.
- Scoped Access (drive.file): When connecting your Google Account, RexaKit requests authorization only for the
drive.file scope. This grants us permission to view, edit, and delete ONLY the specific backup files created by RexaKit. We cannot see, access, or modify any other files, folders, or documents on your Google Drive. - Direct Browser-to-Cloud Sync: The backup synchronization process is executed entirely on the client side (within your browser). Your credentials and access tokens are managed via Google Identity Services, stored only temporarily in your browser's local state, and are never routed through or sent to our servers.
- User Control: You can select your auto-sync frequency (daily, weekly, monthly, or manual), trigger updates, or completely disconnect your Google Account and wipe all local or cloud data at any time.
4. THIRD-PARTY SERVICES
While the core app is local, we use some external services:
- Fonts: We use Google Fonts to deliver our retro typography. Your browser may make a request to Google's servers to fetch these font files.
- Analytics: We use Google Analytics (GA4) for basic, anonymized page view counting. No personal data, PII, or behavioral tracking is collected. Data is used only to understand aggregate traffic and improve the experience.
- Google Identity Services: Used exclusively for RexaVault's optional Google Drive backup feature. Authentication happens entirely client-side.
- TheTVDB API: The Movie Hub tool fetches movie metadata from TheTVDB for search and discovery. No personal data is sent to TheTVDB.
5. SECURITY
Because your data never leaves your device (unless synced to your own Google Drive via RexaVault), the security of your data is largely dependent on the security of your own device and Google Account. LocalStorage and IndexedDB data is sandboxed per browser origin and cannot be accessed by other websites. We recommend keeping your browser, OS, and Google Account security up to date.
6. CONTACT US
If you have questions about how RexaKit handles your data, reach out: