Last updated August 19, 2026
Privacy policy
This policy explains how Gypes handles information when you visit gypes.com. It should be read with our Cookie and advertising notice.
Calculator inputs
Values entered into the current calculators are processed locally by JavaScript in your browser. Gypes does not intentionally transmit or store those input values.
Anonymous message board
When you post to the anonymous message board, the optional display name, message text, publication time, visibility state, and a content hash used to reject recent duplicates are stored in the separate Gypes message-board database. Messages are public by design and may remain until an administrator hides or deletes them. Do not include personal, confidential, or sensitive information. The board does not create visitor accounts or intentionally attach a raw network address to a message.
To limit flooding, the board derives a keyed, non-reversible daily fingerprint from the requesting network address and stores that fingerprint with rate-window times and counts. The raw address is not stored in the message-board database. Expired post-limit rows are removed by later board activity, so inactive rows may remain until cleanup next runs. Administrator login protection uses a separate keyed fingerprint; failed-attempt records are cleared after a successful login or removed after seven inactive days when cleanup next runs. Ordinary infrastructure logs may still process network addresses as described below.
BBS accounts and discussions
The BBS is separate from the anonymous message board. Registration stores the selected username, a generated account identifier, a salted password digest, account creation time, moderation status, post count, and a keyed non-reversible fingerprint of the most recent login network address. The system-generated initial password is returned once to the registering browser; the BBS database does not store that plaintext password. Persistent login sessions store only a random session-token digest and expiration time.
BBS topics, replies, board proposals, and votes are stored with the member account identifier, displayed username, selected content language, and relevant board, country or region, time, visibility, and duplicate-detection values. Topics and replies are public. A signed-in member can delete their own topics and replies; deleting a topic also deletes its replies. Board votes retain the account identifier needed to enforce one vote per account.
Images, GIFs, and videos attached to BBS topics or replies are stored as files in a private server-side media directory, while the BBS database stores attachment identifiers, media type, byte size, uploader, related post, time, and moderation state. Published attachments are publicly retrievable through randomized URLs. Removing the related content also removes its attachment metadata and files. Do not upload media you are not authorized to publish.
To prevent malicious registration, credential attacks, flooding, and spam, the BBS stores keyed network fingerprints with registration and login attempt windows, risk scores, temporary blocks, and administrator-applied network bans. It does not intentionally store the raw address in the BBS database. Automated safeguards may temporarily block suspicious behavior; an administrator can review and remove a block. Administrators may mute, ban, or delete accounts and moderate public content.
GypesChat accounts and private conversations
GypesChat is separate from the BBS and anonymous message board. Registration stores the selected username, a generated account identifier, a salted password digest, account creation time, account status, and a keyed non-reversible network fingerprint used for abuse prevention. The generated initial password is returned once to the registering browser and is not stored as plaintext. Login sessions store a random token digest and expiration time in the separate GypesChat database.
Friend requests, accepted friend relationships, personal friend notes, group names, group ownership and membership, invitations, message text, displayed sender name, and message times are stored to provide the service. Friend notes are visible only to the member who created them. Direct messages are available only to the two current friends, and group messages are available only to active members of that group through the application; GypesChat does not currently provide end-to-end encryption, so authorized server operation and security processes can technically access stored message data. Do not send passwords, financial or medical records, intimate media, or other information that requires end-to-end encrypted handling.
Images, GIFs, and videos sent through GypesChat are stored as randomized files in a private server-side media directory. The database stores their random identifier, type, size, uploader, related message, time, and state. Media requests require an authenticated participant or active group member. Pending uploads that are not attached to a message are eligible for cleanup after 24 hours. Registration, login, request, upload, and message limits use keyed network or account identifiers to resist automated abuse; raw network addresses are not intentionally stored in the GypesChat database.
Media link URL analysis
When you choose dynamic URL analysis in the Media Link Detector, the public page URL and selected observation duration are sent to a same-origin Gypes service. The service opens that public URL in a fresh automated browser context, observes bounded page and network activity, returns detected media-shaped URLs, and destroys the browser context after the request. It does not receive your browser cookies, passwords, or logged-in session. A private rate-limit file records a requesting network address and request times for a one-hour usage window; expired entries are removed when the analyzer next runs, so an inactive file may remain until the next analysis. Ordinary infrastructure logs may be retained as described below.
The detector’s source, playlist, and HAR fallback runs locally in your browser and is not intentionally uploaded to Gypes. HAR files can contain sensitive request headers, cookies, and signed query tokens even when processed locally, so use a sanitized capture and do not share it.
Technical information
Our hosting, content-delivery, and security providers may process standard request information such as IP address, browser and device type, requested URL, referring page, approximate region, request time, and diagnostic or security events. This information is used to deliver, secure, troubleshoot, and understand the site.
First-party visitor counter and private analytics
Public pages use a first-party visitor counter to record the requested page, visit time, a keyed non-reversible visitor identifier derived from the network address, and the country code supplied by our trusted reverse proxy when available. Selecting a BBS board also records that board identifier so the system administrator can understand each board’s audience by country. Gypes does not send an address to a third-party geolocation lookup service for this feature. Requests identified as common automated crawlers and requests carrying Global Privacy Control or Do Not Track are not added to this counter.
The network address is encrypted with AES-256-GCM before database storage and is visible only in the separate password-protected system-administrator analytics page. Delegated BBS administrators cannot access visitor analytics. Recoverable encrypted addresses are retained for 30 days and then replaced with an expired marker; detailed hourly, daily, page, country, and board rows are retained for up to 400 days. Non-reversible per-page uniqueness keys and cumulative page-and-country counters may be retained while this analytics feature operates so the administrator can compare long-term page use; these records do not contain a recoverable network address. The public footer displays only aggregate visitor counts.
The “What is my IP address?” tool requests Gypes’ Cloudflare /cdn-cgi/trace endpoint and displays the public address and limited connection values returned for that request. Gypes does not intentionally create a separate stored copy through the tool; the ordinary infrastructure handling described above still applies.
Local files, camera, microphone, and screen capture
File-processing tools use files selected explicitly through the browser and process them locally unless a page says otherwise. The PDF editor keeps the selected document, added text, ink, signature strokes, images, and generated PDF in the current browser tab; object URLs are released when an edit becomes stale, the tool is reset, or the page is left. The image-to-text tool processes the selected image and extracted text locally with OCR resources served by Gypes; its English language model may be cached in browser site storage to make later runs faster. The text-to-PDF tool keeps entered text in the current page and passes the print-ready document to the browser or operating-system print dialog; choosing a cloud printer or online destination is governed by that provider. The QR code scanner and webcam test can request camera access only after the visitor selects “Start camera.” Selected QR images, camera frames, decoded payloads, live webcam previews, and webcam snapshots are processed in the current browser and are not intentionally transmitted to Gypes. Camera tracks stop when stopped or when the page is hidden or left; the QR scanner also stops after a successful scan or form reset.
The microphone test begins only after an explicit action and permission. It analyzes live levels and waveform samples locally without intentionally recording, playing, or transmitting the stream. Voice recording and screen recording likewise begin only after an explicit browser permission or capture choice; their media is processed for local preview and download. Browser and operating-system permission controls remain authoritative, and access can be denied or revoked there.
Cloudflare Web Analytics
Cloudflare automatically injects a lightweight real-user monitoring beacon from static.cloudflareinsights.com. It uses browser performance APIs to measure page views, page-load timing, and Core Web Vitals, and sends the report to the site’s /cdn-cgi/rum endpoint. We use these aggregated measurements to understand reliability and improve page performance.
According to Cloudflare, Web Analytics does not use cookies, localStorage, or other client-side state, and does not fingerprint or track individuals over time for analytics. Cloudflare states that the source IP received during ordinary request handling is discarded at the nearest data center rather than stored in the RUM analytics database. See Cloudflare’s RUM beacon documentation and data collection documentation.
European Central Bank reference-rate requests
When the currency converter is opened, the browser requests the latest reference-rate CSV directly from data-api.ecb.europa.eu. Standard network information, including the requesting IP address, browser headers, request time, and the Gypes origin, may therefore be processed by the European Central Bank service under its own policies. The request is the same regardless of the amount or currency pair: Gypes does not append calculator inputs, and the conversion arithmetic remains in the browser.
Correspondence
If a contact channel is offered in the future, we may use a submitted address, message, and related correspondence to respond, prevent abuse, and retain a record where reasonably necessary. Do not submit passwords, payment details, medical records, or other sensitive information.
Advertising and consent
Google AdSense account-verification code is installed on Gypes. During review and after approval, Google and its partners may process device information, IP address, browsing signals, and use cookies or similar technologies to verify the site, prevent fraud, deliver or limit ads, and measure advertising where permitted. In regions where consent is required, a Google-certified consent platform must be configured before non-essential personalized advertising technologies are enabled. The installed loader does not by itself verify that a region-specific consent message is active; that live setting must be confirmed in AdSense Privacy & messaging.
Learn how Google uses information from sites that use its services, review Google’s Privacy Policy, or manage personalization in My Ad Center.
Retention
Retention periods vary by purpose. Public message-board posts remain until an administrator deletes them; hidden posts remain stored but are not shown publicly. BBS account records remain while needed to operate the account and prevent impersonation or abuse. Public BBS content and attachments remain until their author or an administrator deletes them; hidden content remains stored but is not shown publicly. GypesChat account, relationship, group, message, and attached-media records currently remain while needed to operate the service, maintain conversation continuity, prevent abuse, and resolve security incidents; removing a friend or leaving a group stops current access but does not itself erase stored message history. Visitor-address and analytics retention is described above. Expired sessions and inactive rate-limit or risk rows are cleaned automatically during later service activity. Manual network bans remain until an administrator removes them. Security and request logs are generally retained according to our infrastructure providers’ operational settings.
Your choices and rights
You can restrict cookies through browser settings and, where available, the site’s consent controls. Depending on your location, you may have rights to request access, correction, deletion, restriction, or objection concerning personal information. You may also have the right to complain to a local data-protection authority.
Children
Gypes provides general-purpose tools and is not directed to children under 13. We do not knowingly ask children to provide personal information.
International processing
Infrastructure and advertising providers may process information in countries other than your own, subject to the safeguards and terms offered by those providers and applicable law.
Contact and changes
A public contact channel is not currently available. Any future contact method will be listed on the contact page. We may update this policy as the site, providers, or applicable requirements change. The revision date above identifies the current version.