Privacy Policy
Last updated: August 2026
The short version
Your files never leave your browser. ZipTool is a 100% client-side application. When you open an archive, it is read and parsed entirely inside your browser. The file's contents are not uploaded to, stored on, or processed by any server controlled by ZipTool.
How ZipTool handles your files
All archive parsing is performed locally in your browser using zip.js. Because there is no server-side processing, ZipTool does not receive, copy, or retain the files you open. When you close the tab, the data is gone from your browser's memory.
Information we do not collect
- We do not collect, receive, or store the files you open.
- We do not require an account, and we do not collect your name or email to use the tool.
- We do not sell personal data.
Loading files from cloud storage (optional)
ZipTool lets you optionally connect your own Google Drive, Dropbox, OneDrive, or Box account to load files directly into the viewer. This feature is entirely optional — the tool works fully without it, and no cloud connection is ever initiated automatically.
File contents are never uploaded. When you click Connect, ZipTool opens the provider's own sign-in window (Google Identity Services, Dropbox OAuth, Microsoft, or Box). The access token is minted by the provider, delivered to your browser, and saved in your browser's local storage so a connection survives a page reload (for Box, the refresh token that renews the session is saved too). Files are downloaded straight from the provider's servers to your browser using that token. The stored token is removed when it expires, when you revoke access below, or when you clear your browser's local storage.
For Google Drive, Dropbox, and OneDrive the entire connection is 100% client-side — no ZipTool server is involved at any step, and no secret ever ships to your browser. Box is the one exception: Box's OAuth requires a client secret for its token exchange, so that single exchange is routed through a serverless function that holds Box's secret server-side. The function touches only the one-time authorization code and the resulting tokens — never your files, which still download directly from Box to your browser.
For Google Drive, Dropbox, and OneDrive, ZipTool requests read-only access ( drive.readonly, files.content.read, and Files.Read). Box is different: Box does not allow a read-only token to download file contents, so ZipTool must request Box's read-write scope (root_readwrite) to download files. ZipTool only ever reads and downloads your files — it never modifies, deletes, or uploads anything to any provider.
You can revoke ZipTool's access at any time from your Google Account permissions (Google Drive), Dropbox connected apps, Microsoft account permissions (OneDrive), or your Box account settings. The provider's own privacy policy applies to the authentication process and the files accessed.
Analytics
ZipTool uses Google Analytics 4 to understand aggregate usage — which pages are visited and roughly where visitors come from. The analytics script is loaded only on content pages (such as this one), not on the tool itself: when you open and browse a zip at the homepage, no analytics script runs at all. Google Analytics uses cookies to distinguish users and sessions. The data collected is statistical and is never tied to the files you open (which we never receive). You can block analytics with a content blocker or by disabling cookies in your browser, and ZipTool will still work.
Advertising
ZipTool may display advertisements served by Google AdSense on its content pages (not on the tool itself). Google and its partners may use cookies to serve ads based on your prior visits to this and other websites. You can opt out of personalized advertising via Google Ads Settings and learn more at aboutads.info.
Cookies
Cookies used by Google Analytics and Google AdSense (when ads are shown) are set by Google under Google's privacy policy. ZipTool itself does not set its own tracking cookies.
Third-party services
- Google Analytics 4 — usage analytics.
- Google AdSense — advertising on content pages.
- Google Drive — optional file source; access is read-only and entirely client-side (no ZipTool server involved).
- Dropbox — optional file source; access is read-only and entirely client-side (no ZipTool server involved).
- OneDrive (Microsoft) — optional file source; access is read-only and entirely client-side (no ZipTool server involved).
- Box — optional file source; ZipTool only reads and downloads, but Box requires its read-write scope to permit downloads (see above). Only the one-time sign-in step routes through a serverless function that holds Box's secret; file contents are never sent to any server.
- The self-hosted fonts bundled with the page are served from the same origin, not a third-party service.
Children's privacy
ZipTool is a general-purpose utility and is not directed at children under 13, and we do not knowingly collect personal information from children.
Changes to this policy
We may update this Privacy Policy from time to time. The "Last updated" date above reflects the most recent revision.
Contact
Questions about this policy? See the contact page.