Privacy Policy
This page describes exactly what happens when you use SORO — which network requests your browser makes, what data is and isn't collected, and where the boundaries are.
Last updated: January 2026Your files never leave your device. There are no accounts, no tracking pixels, no third-party analytics, and no cookies for anything except (in the future) serving ads. Everything you read below is the detailed version of that.
Your files
Files you load into any SORO tool are never transmitted anywhere. They are opened by your browser using the File API, processed in memory by JavaScript running on your device, and — if you choose to download — written back out by your browser. No file content, filename, or metadata is sent to us or to any third party.
This is enforced by the architecture, not by policy. SORO has no backend, no API, and no storage. There is no server-side code that could receive a file even if we wanted it to. The tools are single static HTML files served from a CDN.
You can verify this yourself at any time: open your browser's developer tools, switch to the Network tab, and drop a file into any tool. You will see no outgoing request related to that file.
What data SORO does not collect
- No file contents, filenames, or file metadata
- No account information (there are no accounts)
- No email addresses or contact details
- No IP-address logs on our side
- No behavioral tracking, session recording, or heatmaps
- No advertising identifiers (before ads are enabled)
- No fingerprinting of any kind
What network requests actually happen
When you load any page on SORO, your browser makes a small number of predictable requests. Here's the full list:
| Request | Purpose | Contains |
|---|---|---|
| soroflix.xyz | Loads the HTML page and assets for the tool you opened | Standard HTTP request. Nothing about your files. |
| fonts.googleapis.com | Loads the Inter typeface used for the UI | Your IP and User-Agent (Google's standard font CDN behavior) |
| cdnjs.cloudflare.com / jsdelivr.net | Loads small open-source libraries a specific tool needs (e.g. pdf-lib, qrcode-generator) |
Standard CDN request. Nothing about your files. |
These are the same requests any static website makes. None of them involve your files, and none of them can see what you do inside a tool.
Analytics
SORO uses Cloudflare Web Analytics for basic traffic counting — how many people visited, which pages are popular, which countries the visits come from. This service is:
- Cookieless — it does not set cookies on your device
- Anonymous — no individual user is tracked across sessions
- Aggregate-only — we see counts, never individual sessions
- GDPR/CCPA-compliant by design, with no banner required
We use this to know which tools people are actually finding useful, and to spot broken pages. If a specific tool has zero traffic, we can either improve it or replace it. That's the whole purpose.
Cookies
Currently, SORO sets no cookies. You can verify this by opening DevTools → Application → Cookies on any page. Nothing will be listed.
If we later add advertising to cover hosting costs, we may need to allow the ad network to set a single cookie for frequency capping and (if you consent) personalization. If that happens:
- The policy will be updated on this page before any ad is served
- A minimal consent banner will appear for visitors in regions that require it
- Non-personalized ads will always be available as a default
- No tool functionality will ever be gated behind ad consent
Third-party services
The list is deliberately short. Right now it consists of:
- Cloudflare Pages — serves the static site and provides cookieless analytics
- Google Fonts — serves the Inter font used for the UI
- cdnjs / jsDelivr — serve small open-source JavaScript libraries that some tools depend on
If we ever add a new third-party service, it will be listed here before it goes live, with its purpose stated plainly.
Local storage and IndexedDB
A few tools use browser storage for convenience. This data stays on your device and is never transmitted:
- IndexedDB (
sorodatabase) — used to hand a file from the homepage to a specific tool when you drop it there. The file is deleted from IndexedDB as soon as the target tool picks it up. - sessionStorage — used to pass a URL or a piece of text from the homepage to the relevant tool. Cleared automatically when you close the tab.
You can clear both at any time via your browser's privacy settings. Nothing depends on them for the tools to work — they're just a convenience for the homepage-to-tool flow.
Your rights
Because SORO does not collect personal data, there is very little for you to exercise rights over. But for completeness, under GDPR, CCPA, and similar frameworks:
- Right to access: we hold nothing about you to access
- Right to deletion: nothing to delete
- Right to portability: nothing to export
- Right to object: you can object to the cookieless analytics by using a tracker-blocking browser extension; the tools will continue to work identically
- Right to lodge a complaint: contact your local data protection authority if you believe we've mishandled anything
Children
SORO is a general-purpose utility site and does not knowingly collect data from anyone, including children under 13. Because no data is collected from anyone, there is nothing to specially protect.
Changes to this policy
If the policy ever changes, the updated version will appear on this page with a new "Last updated" date at the top. Material changes — anything that would meaningfully alter how your data is handled — will be announced at the top of the homepage for at least two weeks so regular visitors can see them.
What will never change: your files stay on your device. That is the entire point of the project, and it will not be quietly walked back.
Open for inspection
The site is entirely static HTML, CSS, and JavaScript. You can view the complete source of any page by pressing Ctrl+U (or Cmd+Option+U) in your browser. There is nothing hidden — every request, every library, and every operation is in plain text.
Questions about this policy?
If anything here is unclear, or you've found a discrepancy between this page and what the site actually does, please reach out so it can be fixed.
The best place to raise an issue is via the contact link in the footer of the homepage.