JSON inputs
JSON you paste, type, or open is processed in a browser worker. The current site does not intentionally upload, transmit, or store that JSON on our servers. Inputs are held in browser memory and are removed when you clear them, close the tab, or refresh the page.
Because browser extensions, managed devices, screen-capture tools, and other software outside PayloadPair may observe page content, you should still follow your organization’s data-handling rules.
Local preferences
PayloadPair currently stores only your light or dark theme preference in browser local storage. It does not store your JSON, comparison results, array rules, ignore rules, or exports there.
Share links and exports
A shared configuration link places rule settings in the URL fragment after #. It excludes both JSON inputs and result values. Rule paths and key names can still reveal the shape or vocabulary of a system, so inspect the link before sharing it. Although fragments are not included in ordinary HTTP requests, the full link can remain in local or browser-synced history and is visible to anyone who receives it.
Comparison reports exclude before-and-after values and source file names by default. They still contain JSON paths, property names, match keys, and rule metadata, which can reveal identifiers or system vocabulary and are not inherently sanitized. If you opt into source file names or displayed value previews, those fields can also contain sensitive data. Long values can be truncated in previews. PayloadPair checks the serialized report for several common secret patterns before export, but that check cannot identify every secret. Inspect every copied, downloaded, or printed report before sharing it.
Exact JSON Patches are separate, inherently value-bearing artifacts because add and replace operations contain payload values. PayloadPair labels those copy and download actions and runs the same best-effort secret check.
Analytics, advertising, and logs
PayloadPair uses Google Analytics 4 only after you select Accept analytics. If enabled, Google Analytics may receive the page visited, approximate location derived from an IP address, browser and device information, and referring page. PayloadPair does not send JSON text, filenames, rule paths, comparison output, or exported values as Analytics event properties. Google signals, advertising storage, and ad personalization signals are disabled in the site configuration.
Your choice is stored in local browser storage under payloadpair-analytics-consent. You can reopen Analytics settings from any page and change that choice. Declining prevents the Google Analytics script from loading. Revoking a previous acceptance disables Analytics storage and attempts to remove PayloadPair’s Google Analytics cookies.
The site is deployed through OpenAI Sites and its delivery infrastructure may use Cloudflare. Those providers may process ordinary request data such as IP address, user agent, timestamp, and requested URL to deliver the page, mitigate abuse, and maintain the service. They can process data in the locations where they operate and retain operational logs according to their policies, service terms, and operator controls. PayloadPair does not set or promise a separate provider-log retention period.
The site does not currently load display advertising. If advertising is introduced, this policy and any required consent controls will be updated before or when that technology is enabled.
Aurelian Syndicate is identified on this site as the operator of PayloadPair. Requests to access, correct, or delete personal information held by the operator can be sent to the contact address below. We may need enough information to verify and respond to the request. Hosting-provider log requests may be limited by the provider’s controls and legal obligations.
Contact and changes
Privacy questions can be sent to support@aureliansyndicate.com. Do not include confidential JSON. Material changes will be shown by the updated date on this page.