Legal
Privacy
Last updated 26 August 2026.
Validation still runs in your browser via WebAssembly. The CLI and library do not send artifacts unless you point them at a hosted endpoint yourself.
What we keep
When you paste, type, or validate an artifact in the
playground, pixellint.org stores a copy of that URL, JSON, or XML.
Known emails, phones, device IDs, IPs, and consent strings are stripped before storage.
Cloudflare also supplies the country and the network owner (ASN number and organization
name). We do not store the IP address. We may keep a random session id that exists only
while this browser tab is open, so artifacts from the same tab can be grouped. If you
arrived from another site, we may keep that site's hostname. If the playground URL has
utm_source or utm_medium, those values may be kept. Built-in
examples are not sent. There is no hosted MCP on pixellint.org. The local
pixellint-mcp stdio server does not send artifacts. Artifacts are used to
improve validation rules and are not published. We do not fire the pixel.
How we use stored artifacts
We may parse, cluster, and derive fixtures and rules from a submitted artifact while developing and testing pixellint. We do not request the tracking URL. We do not sell artifacts. We do not publish submitted payloads as a public gallery.
Opt out
The playground has a Don't send my artifacts control. That sets a flag in this browser
only. It stops new sends from that browser. It does not recall artifacts already stored.
The local pixellint-mcp stdio server never sends artifacts.
Analytics
The public site may use Cloudflare Web Analytics for page traffic. That is separate from artifact storage.