ZipToolView zip files online — 100% private

Privacy Policy

Last updated: August 2026

The short version

Your files never leave your browser. ZipTool is a 100% client-side application. When you open an archive, it is read and parsed entirely inside your browser. The file's contents are not uploaded to, stored on, or processed by any server controlled by ZipTool.

How ZipTool handles your files

All archive parsing is performed locally in your browser using zip.js. Because there is no server-side processing, ZipTool does not receive, copy, or retain the files you open. When you close the tab, the data is gone from your browser's memory.

Information we do not collect

  • We do not collect, receive, or store the files you open.
  • We do not require an account, and we do not collect your name or email to use the tool.
  • We do not sell personal data.

Loading files from cloud storage (optional)

ZipTool can connect to your own cloud storage — Google Drive, Dropbox, OneDrive, or Box — to load files directly into the viewer; the exact set of providers offered may vary. The feature is entirely optional — the tool works fully without it, and no cloud connection is ever initiated automatically.

File contents are never uploaded. When you click Connect, ZipTool opens the provider's own sign-in window (Google Identity Services, Dropbox OAuth, Microsoft, or Box). The access token is minted by the provider, delivered to your browser, and saved in your browser's local storage so a connection survives a page reload (for Box, the refresh token that renews the session is saved too). Files are downloaded straight from the provider's servers to your browser using that token. The stored token is removed when it expires, when you revoke access below, or when you clear your browser's local storage.

For Google Drive, Dropbox, and OneDrive the entire connection is 100% client-side — no ZipTool server is involved at any step, and no secret ever ships to your browser. Box is the one exception: Box's OAuth requires a client secret for its token exchange, so that single exchange is routed through a serverless function that holds Box's secret server-side. The function touches only the one-time authorization code and the resulting tokens — never your files, which still download directly from Box to your browser.

For Google Drive, Dropbox, and OneDrive, ZipTool requests read-only access ( drive.readonly, files.content.read, and Files.Read). Box is different: Box does not allow a read-only token to download file contents, so ZipTool must request Box's read-write scope (root_readwrite) to download files. ZipTool only ever reads and downloads your files — it never modifies, deletes, or uploads anything to any provider.

You can revoke ZipTool's access at any time from your Google Account permissions (Google Drive), Dropbox connected apps, Microsoft account permissions (OneDrive), or your Box account settings. The provider's own privacy policy applies to the authentication process and the files accessed.

Analytics

ZipTool uses Google Analytics 4 in two modes, both statistical only and never tied to the files you open (which we never receive).

Content pages (like this one) load the standard Google Analytics script, which uses cookies to distinguish users and sessions, so we can see which pages are visited and roughly where visitors come from.

The tool itself — the pages where you open, preview, convert, or create archives — loads a cookieless configuration of the same service: no cookies, no browser storage, no advertising signals, and no page-view counting. It sends only an anonymous action counter, for example “an archive was opened (format: rar, outcome: success)” or “a conversion to zip finished”. These counters contain no file names, no file contents, no folder listings, no URLs, and no identifiers of any kind; they cannot be joined to you or to your files. File sizes are recorded only as a coarse bucket (for example “1–10 MB”).

You can block all analytics with a content blocker, or by enabling your browser’s Do Not Track or Global Privacy Control setting — when either is active, the tool does not even download the analytics script. Blocking analytics never affects functionality: every tool operation works exactly the same with analytics blocked.

Advertising

ZipTool may display advertisements served by Google AdSense on its content pages (not on the tool itself). Google and its partners may use cookies to serve ads based on your prior visits to this and other websites. You can opt out of personalized advertising via Google Ads Settings and learn more at aboutads.info.

Cookies

Cookies used by Google Analytics and Google AdSense (when ads are shown) are set by Google under Google's privacy policy. ZipTool itself does not set its own tracking cookies.

Third-party services

  • Google Analytics 4 — usage analytics (standard with cookies on content pages; cookieless anonymous action counters on tool pages).
  • Google AdSense — advertising on content pages.
  • Google Drive — optional file source; access is read-only and entirely client-side (no ZipTool server involved).
  • Dropbox — optional file source; access is read-only and entirely client-side (no ZipTool server involved).
  • OneDrive (Microsoft) — optional file source; access is read-only and entirely client-side (no ZipTool server involved).
  • Box — optional file source; ZipTool only reads and downloads, but Box requires its read-write scope to permit downloads (see above). Only the one-time sign-in step routes through a serverless function that holds Box's secret; file contents are never sent to any server.
  • The self-hosted fonts bundled with the page are served from the same origin, not a third-party service.

Children's privacy

ZipTool is a general-purpose utility and is not directed at children under 13, and we do not knowingly collect personal information from children.

Changes to this policy

We may update this Privacy Policy from time to time. The "Last updated" date above reflects the most recent revision.

Contact

Questions about this policy? See the contact page.