Privacy

The short version: your files never leave your device. Not because we promise to be careful with them — because they are never sent anywhere for anyone to be careful with.

What happens to your files

Everything LocalCSV does — reading, combining, cleaning, comparing, exporting — happens inside your browser, on your computer. There is no upload step, no processing server, and no account. When you close the tab, your data is gone from the page.

Two things enforce this. There is no server that accepts data — the site is static files, with nothing listening for an upload. And the pages instruct your browser to block connections to any destination other than the site's own file server (a Content-Security-Policy of connect-src 'self'), so even a bug in our code could not send your data to a third party: the browser itself would refuse the connection. The site also watches its own network activity while you work and reports the tally on every tool page.

And you do not have to take that on faith — the section below walks you through catching it in the act.

Verify it yourself, in about a minute

The strongest privacy policy is one you can check. Here is how to watch, in your own browser, that your file never leaves your device.

  1. Open any tool — the merge is a good one — but do not drop a file yet.
  2. Open your browser's developer tools and select the Network tab. Right-click the page and choose Inspect, or press F12 (on a Mac, ⌥⌘I).
  3. Tick Preserve log so nothing scrolls away, then drop a real file onto the page and run the tool.
  4. Read the list of requests. Every one goes to this site's own address — the page, its code, the engine — and you can click any request to see it carries none of your file. There is no request to another server, because the page's Content-Security-Policy (connect-src 'self') tells the browser to refuse one.
  5. For the clinching proof, turn your network off — airplane mode, or in developer tools set the throttling to Offline — and use the tool again. It keeps working, because the work was never happening anywhere but on your device.

That last step is the one that cannot be faked: a tool that phoned home could not keep working with the line cut.

What we collect

Nothing about you. No accounts, no analytics scripts, no advertising trackers, no cookies. We do not know who you are, what files you opened, or what you did with them — and we have designed the product so that we cannot know. The one thing we count is described two sections down: how many times each page was asked for each day. It counts requests, not people.

What the hosting provider sees

The site's pages and code are served by a hosting provider (currently Vercel). Like every web server, it receives the standard request for each page and asset — which page was asked for, from which network address, by which browser — and keeps transient operational logs of those requests. The site does not put your files or their contents into any request it makes, so your data does not appear in those logs.

From those logs we keep one derived record, so we can tell whether anyone visits: a daily tally of requests — the date, the page asked for, the response status, whether the request came from a browser or from a crawler, and a count. That is the entire record. The network addresses and browser details in the provider's logs are discarded, not stored: the browser's name is looked at once, to answer that one browser-or-crawler question, and then dropped with the rest. The tally contains nothing about any person, any visit, or any file, and nothing in it can be traced back to you. Your browser sends nothing extra to produce it — it is arithmetic over requests every web server already receives.

What stays in your browser

  • An offline copy of the app is cached by your browser so the tools keep working without a connection.

It lives only on your device, contains none of your data, and disappears if you clear the site's data in your browser settings.

Share links

A settings link built by the “Share these settings” feature carries your settings only — which columns to match on, which rules to apply — and never your file or any value from it. The settings travel in the part of the address after the #, which browsers do not send over the network at all.

Who we are

LocalCSV is built and operated by Riverbend Crossroads Digital LLC. Questions or concerns about this policy are welcome at feedback@localcsv.com or through the feedback page.

Changes

If this policy changes, the change will appear on this page with a new effective date. The core commitment — your files are processed on your device and never uploaded — is the product, and will not change.

Effective 6 September 2026.