Privacy policy
Local where possible. Explicit when not.
Ordinary tool input stays in the current tab. Connected tools identify what must leave the browser, why, and which service receives it.
Local tool state
The application uses no account, application cookie, local or session storage, IndexedDB, analytics, or application database. Tool values and outputs live in current-tab memory. Uploaded JWT certificates and public keys disappear when the page is refreshed or closed. Copy actions use the clipboard only after your click.
Static site delivery
Loading any page necessarily sends ordinary web-request metadata, such as an IP address, requested path, time, and browser headers, to the hosting and network infrastructure that delivers the static files. odmin.biz does not add analytics or intentionally create application request logs. Infrastructure providers may process security and delivery metadata under their own policies.
Search visibility
Public documentation pages may appear in search engines. The operator may use Google Search Console or Bing Webmaster Tools to receive search-result data such as query, page, country, device, impressions, clicks, and average position. Those services derive the reports from their own search products; odmin.biz embeds no analytics script, advertising tag, or search-console cookie and sends no tool input to them. Never put a credential, private key, token, database host, or other sensitive value into a search query.
No durable tool history
The connected MySQL page may consume an explicit #mysql? fragment containing its reviewed direct or SSH non-secret preset fields, then removes it immediately; other tool input is not placed in a URL. Its generated read-operation history, including debug results capped at 32 KiB per entry, is bounded to the current session in React memory and is erased on disconnect or page refresh.
DNS, HTTP, TCP, and TLS transit
HTTP cURL/fetch import and export happen in current-tab memory and initiate no request. A successful import clears the original pasted source after copying its allowed fields into the editor; blocked credential and reserved browser fields are discarded with warnings. Direct HTTP GET/HEAD sends the URL and allowed headers from your browser to the selected destination with credentials omitted; CORS controls whether the response is readable. Server HTTP or HTTPS sends the URL, method, allowed headers—including a user-entered Origin, Referer, or User-Agent—bounded text body, redirect choice, and one-time token to https://http-client.odmin.biz/. DNS values transit /dns-api, while one host or IP, port, and token transit /port-api. A TLS diagnostic sends one host or IP, port, operation label, and one-time token to the same exact HTTP gateway. Every protected request requires a fresh Turnstile token, keeps its input in request memory only, and clears its token reference after verification. DNS and TCP destinations see shared Cloudflare-hosted infrastructure; protected HTTP and TLS destinations see the odmin.biz Kubernetes gateway rather than the visitor's device IP.
TCP banner and TLS metadata
The TCP Worker sends no application bytes. It may return up to 4 KiB of passively received server-first data, base64-encoded with its byte count and truncation state, alongside one checked address and bounded connection metadata; the browser strips control characters before displaying or copying the transcript. The TLS gateway sends no application data and returns the checked address, connection and verification state, available certificate/identity, protocol, cipher, ALPN, ephemeral-key and byte-counter fields, plus a sanitized failure description and applicable TLS alert number when the attempt fails. Any peer certificate captured on a failed path is returned only as explicitly unverified diagnostic data. These values remain in request and current-tab memory only and are intentionally omitted from application logs; the selected service and infrastructure may retain ordinary connection metadata.
MySQL and SSH transit
An optional #mysql? fragment on the canonical https://odmin.biz/tools/mysql-client page can prefill unique direct fields route, host, port, username, and database, plus a combined ssh=username@host, sshPort, and optional sshHostKeySha256 only for route=ssh. URL fragments do not enter HTTP requests or referrers, and the browser removes this fragment immediately after parsing; anyone who receives or captures the original preset link can still read all of those fields. Passwords, private keys, passphrases, TLS settings or identity, consent, and tokens are not accepted there. A fingerprint delivered with the same link is not independently trusted and should be checked separately. On Connect or a connection diagnostic, the hostname or IP, port, relevant connection fields, password when needed, transport choice, optional verified-TLS certificate hostname, Turnstile token, structured operations, metadata, server-generated definitions, and rows first cross the authenticated WSS/TLS connection from the browser to the odmin.biz MySQL gateway at mysql2.odmin.biz. Fresh Turnstile is required for every connection attempt and SSH diagnostic; structured reads are accepted only inside that verified session, which ends after at most one hour.
If user SSH is selected, the public SSH endpoint, username, public key, supplied or observed host-key fingerprint, MySQL forwarding target, bounded authentication challenge, and signature also cross WSS and exist transiently in gateway memory. Without a supplied pin, the browser displays the observed fingerprint and requires explicit confirmation before signing. The private-key file you select and its passphrase remain on your machine in current-tab browser memory and are never sent to odmin.biz. A failed attempt or diagnostic retains them there for explicit retry; success, disconnect, unexpected close, or tab close releases them. Test SSH tunnel opens the exact forwarding channel and closes it without a MySQL payload; Test database connection performs the normal read-only initialization and initial metadata read before closing. Browser code validates the SSH authentication message before signing, although it cannot independently interpret the opaque SSH session identifier and therefore trusts the reviewed gateway to bind it to the selected host. Verified MySQL TLS protects and authenticates the database, unverified TLS encrypts without authenticating it, and plaintext provides no MySQL-layer protection beyond any SSH channel. Application state remains in browser and gateway-process memory only and is intentionally omitted from application logs. Kubernetes ingress and selected SSH or database operators may retain ordinary connection metadata or their own authentication, audit, and generated-query logs.
The recommended Real demo sends only a fixed connectDemo request and one-time token from the browser. Its dedicated MySQL credentials and optional dedicated SSH private key/passphrase are held in an owner-managed Kubernetes Secret and gateway memory, never frontend code or WSS, and cannot be overridden by browser fields. Kubernetes and its control plane remain outside the application's no-persistence guarantee and may retain Secret or operational state under the cluster operator's configuration. The local Sample data demo makes no gateway or database request. Loaded child counts, database and object definitions, row pages, and the adjustable sidebar width remain current-session UI state.
Hosted demos and capacity
The connected static export embeds no demo catalog or URL. After hydration, your browser requests the public catalog from the selected control plane at mysql.odmin.biz immediately and whenever the page regains focus or visibility, with caching disabled and without credentials, a referrer, or background polling; ordinary request metadata such as your IP address still reaches the control-plane hosting infrastructure. The browser disables existing links before each request and accepts only validated random HTTPS links under that same selected domain for ready Adminer, phpMyAdmin, DbGate, CloudBeaver, and MySQL Shell GUI demos. The catalog is kept only in current-tab React state, and missing, invalid, or unavailable responses leave the images disabled. No database or SSH credential enters the request. Clicking an image sends ordinary browser request metadata to that isolated tool and its hosting infrastructure; all tools use a dedicated non-sensitive read-only Sakila account, and you should not enter private data.
Production defaults to mysql.odmin.biz. An explicit local or hosted staging build may select only mysql-staging.odmin.biz; arbitrary domains fail the build. Static client-guide links make no request until you click them and contain no connection fields or launcher capability. The destination then receives ordinary browser request metadata under its own Privacy Policy.
Check availability loads Turnstile only after your click. A fresh one-time token is sent with no credentials or connection fields to https://mysql.odmin.biz/api/availability. The returned public capacity and conditional launcher URL are accepted only at that selected origin root, remain in current-tab memory, and disappear on refresh. The launcher is not present in the initial page or browser storage.
Turnstile and Cloudflare
Connected DNS, TCP, TLS, and MySQL pages load Turnstile so a fresh token is ready before the protected action. The HTTP page loads it only when Server request is enabled or required; the private-instance availability action loads it only after Check availability is clicked. Cloudflare says Turnstile processes security signals such as the client IP address, TLS fingerprint, user-agent header, site key, and associated origin to distinguish people from bots. See Cloudflare's Turnstile Privacy Addendum. Direct browser HTTP GET/HEAD and opening a hosted demo link do not use Turnstile.
Your choices
You can use the local-only tools without submitting tool input to an application endpoint. In the connected profile, do not open a connected tool or submit its action if you do not want the disclosed transit. You may also block third-party resources, but protected features will then be unavailable. Applicable privacy and consumer rights are not limited by this policy; because the application has no accounts or durable tool history, it will usually have no stored tool record to retrieve or delete.
Contact and privacy requests
For questions, access or deletion requests, and other privacy contact, use the public operator profile at github.com/hitrov. Never include a password, private key, session token, or other secret in a public issue or message.