Privacy Policy

Kebijakan Privasi

Last updated: September 2026

Terakhir diperbarui: September 2026

Short version: One Code uses no tracking cookies, advertising, or analytics. Most tools run entirely in your browser and what you type stays there. A minority of tools contact the network — each says so on its page — and six of them go through our own API. What those send, and that we store none of it, is listed in section 4.

1. Data We Collect

In this policy, “we” means PT Lancar Inovasi Digital, the company that operates One Code at code.lancar.id and is the data controller for it. You can reach us at contact@lancar.id.

We collect no personal data for its own sake. No account is needed to use the tools, and nothing you type is uploaded by One Code unless the tool you are running exists to send it (section 4). Our API's web server may keep standard access logs (IP address, request path, time) to operate and protect the service, and the diagnostic endpoints count requests per address in memory for rate limiting; that count is not written to disk and is gone when the service restarts.

The following data is not collected:

  • Your name, email, or any identifying information — the public tools have no accounts
  • The content you enter into a tool, except what a network tool sends for that one request (section 4)
  • Browser fingerprint or device information
  • Usage patterns or session recordings

Your IP address reaches our API only when you use a tool that calls it (section 4), and then only as any web server sees the address of a request.

2. Browser Storage

To improve your experience, some tools save state between sessions using your browser's localStorage. One Code does not upload this data; it leaves your device only when you run a tool that sends it — for example, the REST client sends the request you compose.

What is stored

  • Editor content — your last input in viewer tools (JSON, CSS, HTML, etc.)
  • Theme preference — Light or Dark mode selection
  • Language preference — EN or ID
  • Active tab state — which pill tab was last selected per tool
  • REST API Client — saved environments, request history, and collections

Encryption

All localStorage values (except theme and language preference) are encrypted using AES-256-GCM via the browser's native WebCrypto API before being written to disk. The encryption key is derived from a random salt using HKDF-SHA256 and is tied to your browser session and origin — it cannot be read by other websites.

How to clear

You can clear all stored data at any time through your browser's developer tools (Application → Local Storage → code.lancar.id → Clear All).

3. Cookies & Cache

Cookies

The public tools set no cookies — not for tracking, analytics, or any other purpose. They use browser localStorage instead, which is scoped to the origin and never transmitted with HTTP requests. The administration panel, which is for our staff only, uses one session cookie to keep an administrator signed in; it is never set for visitors.

Browser Cache

Your browser may cache static assets (JavaScript, CSS, fonts, images) to speed up subsequent visits. These are standard HTTP cache mechanisms controlled by your browser settings. No personal data is stored in the cache.

Service Workers

One Code registers a Service Worker that caches the application's own files (scripts, styles, fonts, pages) so tools load faster and keep working offline. It caches no API responses and nothing you enter. Your browser's site-data controls remove it.

4. Network Use and Third-Party Services

Every tool that uses the network is marked on its own page. They fall into two groups.

Tools that go through the One Code API

Six tools send what you enter to api.lancar.id, which acts on it for that one request and stores none of it:

  • What Is My IP, IP Geolocation — your address, or the address you enter, is looked up by the API and by the geolocation provider an administrator has configured.
  • SSL Checker, Port Open Checker — the hostname and ports you enter; the handshake or connection attempt is made from our server, to public addresses only.
  • SMTP Testing — the host and port, and the username and password if you enter them, used for one authentication attempt. No message is ever sent.
  • AI API Key Tester — the key you enter is used for one request to that provider.
  • Translate PDF — your own provider key and the text to translate are forwarded once to the provider you choose.

Services your browser contacts directly

These requests go from your browser to the third party, which handles them under its own policy:

  • DNS-over-HTTPS resolvers you choose (Cloudflare, Google, Quad9) — the names or addresses you look up in the DNS, SPF/DKIM, MTA-STS, reverse and bulk lookup tools.
  • RDAP registries via rdap.org — the domains, networks or AS numbers you look up in WHOIS and ASN lookup.
  • speed.cloudflare.com — the speed and latency tests.
  • The servers you name in the REST client, HTTP Header Inspector, CORS Tester, Load Test and the HTML → PDF URL fetch. We do not proxy, log, or inspect these requests.
  • Public CORS proxies (allorigins.win, codetabs.com, corsproxy.io) — fallbacks for the JSON Viewer's URL fetch when the target refuses cross-origin requests.
  • YouTube's image CDN — thumbnails in the YouTube Thumbnail tool.
  • cdn.jsdelivr.net — the OCR engine and its language data, downloaded on first use of the OCR tools.
  • Google Fonts — fonts are loaded from fonts.googleapis.com and fonts.gstatic.com. Google may log requests to their servers in accordance with their own privacy policy. If you prefer complete isolation, you can block these requests in your browser — the application will fall back to system fonts.

No advertising networks, analytics platforms, or tracking pixels are used.

REST API Client

When you use the REST API Client to send HTTP requests, those requests are made directly from your browser to the target server you specify. We do not proxy, log, or inspect these requests.

JSON Fetch Feature

The JSON Viewer's URL fetch feature may use public CORS proxy services (allorigins.win, codetabs.com, corsproxy.io) as fallbacks when the target URL does not allow cross-origin requests. These services are third-party and subject to their own privacy policies. No personal data is included in these requests.

5. Children's Privacy

One Code is a developer tool intended for users aged 16 and above. We do not knowingly collect any data from children.

6. Changes to This Policy

We may update this Privacy Policy from time to time. Changes will be reflected by updating the "Last updated" date at the top of this page. Continued use of the application after changes constitutes acceptance of the revised policy.

7. Contact

If you have any questions about this Privacy Policy, contact PT Lancar Inovasi Digital at contact@lancar.id, or visit lancar.id.

Ringkasan: One Code tidak menggunakan cookie pelacak, iklan, atau analitik. Sebagian besar tool berjalan sepenuhnya di browser Anda dan apa yang Anda ketik tetap di sana. Sebagian kecil tool menghubungi jaringan — masing-masing menyebutkannya di halamannya — dan enam di antaranya lewat API kami sendiri. Apa yang dikirim, dan bahwa kami tidak menyimpannya, tercantum di bagian 4.

1. Data yang Kami Kumpulkan

Dalam kebijakan ini, “kami” berarti PT Lancar Inovasi Digital, perusahaan yang mengoperasikan One Code di code.lancar.id dan bertindak sebagai pengendali data. Anda dapat menghubungi kami di contact@lancar.id.

Kami tidak mengumpulkan data pribadi untuk kepentingan kami sendiri. Tidak diperlukan akun untuk memakai tool, dan apa yang Anda ketik tidak diunggah oleh One Code kecuali tool yang Anda jalankan memang ada untuk mengirimkannya (bagian 4). Web server API kami dapat menyimpan log akses standar (alamat IP, path permintaan, waktu) untuk mengoperasikan dan melindungi layanan, dan endpoint diagnostik menghitung permintaan per alamat di memori untuk pembatasan laju; hitungan itu tidak ditulis ke disk dan hilang saat layanan dimulai ulang.

Data berikut tidak dikumpulkan:

  • Nama, email, atau informasi identitas Anda — tool publik tidak punya akun
  • Konten yang Anda masukkan ke tool, kecuali yang dikirim tool jaringan untuk satu permintaan itu (bagian 4)
  • Browser fingerprint atau informasi perangkat
  • Pola penggunaan atau rekaman sesi

Alamat IP Anda sampai ke API kami hanya ketika Anda memakai tool yang memanggilnya (bagian 4), dan hanya sebagaimana web server mana pun melihat alamat sebuah permintaan.

2. Penyimpanan Browser

Untuk meningkatkan pengalaman Anda, beberapa tool menyimpan status antar sesi menggunakan localStorage browser Anda. One Code tidak mengunggah data ini; ia meninggalkan perangkat Anda hanya ketika Anda menjalankan tool yang mengirimkannya — misalnya REST client mengirim permintaan yang Anda susun.

Apa yang disimpan

  • Konten editor — input terakhir Anda di tool viewer (JSON, CSS, HTML, dll.)
  • Preferensi tema — pilihan mode Light atau Dark
  • Preferensi bahasa — EN atau ID
  • Status tab aktif — pill tab mana yang terakhir dipilih per tool
  • REST API Client — environments tersimpan, riwayat request, dan koleksi

Enkripsi

Semua nilai localStorage (kecuali preferensi tema dan bahasa) dienkripsi menggunakan AES-256-GCM melalui WebCrypto API native browser sebelum ditulis ke disk. Kunci enkripsi diturunkan dari salt acak menggunakan HKDF-SHA256 dan terikat pada sesi browser dan origin Anda — tidak dapat dibaca oleh situs web lain.

Cara menghapus

Anda dapat menghapus semua data tersimpan kapan saja melalui developer tools browser (Application → Local Storage → code.lancar.id → Clear All).

3. Cookie & Cache

Cookie

Tool publik tidak memasang cookie — tidak untuk pelacakan, analitik, atau tujuan lain. Mereka memakai localStorage browser, yang terbatas pada origin dan tidak pernah dikirimkan bersama permintaan HTTP. Panel administrasi, yang hanya untuk staf kami, memakai satu cookie sesi agar administrator tetap masuk; cookie itu tidak pernah dipasang untuk pengunjung.

Cache Browser

Browser Anda mungkin melakukan cache aset statis (JavaScript, CSS, font, gambar) untuk mempercepat kunjungan berikutnya. Ini adalah mekanisme cache HTTP standar yang dikendalikan oleh pengaturan browser Anda. Tidak ada data pribadi yang tersimpan dalam cache.

Service Workers

One Code mendaftarkan Service Worker yang menyimpan cache berkas aplikasi sendiri (skrip, gaya, font, halaman) agar tool dimuat lebih cepat dan tetap bekerja offline. Ia tidak menyimpan cache respons API maupun apa pun yang Anda masukkan. Kontrol data situs di browser Anda menghapusnya.

4. Penggunaan Jaringan dan Layanan Pihak Ketiga

Setiap tool yang memakai jaringan ditandai di halamannya sendiri. Ada dua kelompok.

Tool yang lewat API One Code

Enam tool mengirim apa yang Anda masukkan ke api.lancar.id, yang memprosesnya untuk satu permintaan itu dan tidak menyimpan apa pun:

  • What Is My IP, IP Geolocation — alamat Anda, atau alamat yang Anda masukkan, dicari oleh API dan oleh penyedia geolokasi yang dikonfigurasi administrator.
  • SSL Checker, Port Open Checker — hostname dan port yang Anda masukkan; handshake atau percobaan koneksi dilakukan dari server kami, hanya ke alamat publik.
  • SMTP Testing — host dan port, serta username dan password bila Anda memasukkannya, dipakai untuk satu percobaan autentikasi. Tidak ada pesan yang pernah dikirim.
  • AI API Key Tester — key yang Anda masukkan dipakai untuk satu permintaan ke penyedia itu.
  • Translate PDF — key penyedia milik Anda sendiri dan teks yang diterjemahkan diteruskan sekali ke penyedia yang Anda pilih.

Layanan yang dihubungi langsung oleh browser Anda

Permintaan ini berjalan dari browser Anda ke pihak ketiga, yang menanganinya menurut kebijakannya sendiri:

  • Resolver DNS-over-HTTPS yang Anda pilih (Cloudflare, Google, Quad9) — nama atau alamat yang Anda cari di tool DNS, SPF/DKIM, MTA-STS, reverse, dan bulk lookup.
  • Registri RDAP lewat rdap.org — domain, jaringan, atau nomor AS yang Anda cari di WHOIS dan ASN lookup.
  • speed.cloudflare.com — tes kecepatan dan latensi.
  • Server yang Anda sebutkan di REST client, HTTP Header Inspector, CORS Tester, Load Test, dan pengambilan URL HTML → PDF. Kami tidak mem-proxy, mencatat, atau memeriksa permintaan ini.
  • Proxy CORS publik (allorigins.win, codetabs.com, corsproxy.io) — fallback pengambilan URL di JSON Viewer bila target menolak permintaan lintas origin.
  • CDN gambar YouTube — thumbnail di tool YouTube Thumbnail.
  • cdn.jsdelivr.net — mesin OCR dan data bahasanya, diunduh saat pertama kali tool OCR dipakai.
  • Google Fonts — font dimuat dari fonts.googleapis.com dan fonts.gstatic.com. Google dapat mencatat permintaan ke server mereka sesuai dengan kebijakan privasi mereka sendiri. Jika Anda menginginkan isolasi penuh, Anda dapat memblokir permintaan ini di browser — aplikasi akan menggunakan font sistem sebagai fallback.

Tidak ada jaringan iklan, platform analitik, atau tracking pixel yang digunakan.

REST API Client

Ketika Anda menggunakan REST API Client untuk mengirim permintaan HTTP, permintaan tersebut dibuat langsung dari browser Anda ke server target yang Anda tentukan. Kami tidak mem-proxy, mencatat, atau memeriksa permintaan ini.

Fitur Fetch JSON

Fitur fetch URL pada JSON Viewer dapat menggunakan layanan proxy CORS publik sebagai fallback ketika URL target tidak mengizinkan permintaan lintas origin. Layanan ini adalah pihak ketiga dan tunduk pada kebijakan privasi mereka masing-masing. Tidak ada data pribadi yang disertakan dalam permintaan ini.

5. Privasi Anak-Anak

One Code adalah tool developer yang ditujukan untuk pengguna berusia 16 tahun ke atas. Kami tidak secara sengaja mengumpulkan data dari anak-anak.

6. Perubahan Kebijakan

Kami dapat memperbarui Kebijakan Privasi ini dari waktu ke waktu. Perubahan akan tercermin dengan memperbarui tanggal "Terakhir diperbarui" di bagian atas halaman ini. Penggunaan aplikasi yang berkelanjutan setelah perubahan berarti penerimaan kebijakan yang direvisi.

7. Kontak

Jika Anda memiliki pertanyaan tentang Kebijakan Privasi ini, silakan hubungi PT Lancar Inovasi Digital di contact@lancar.id, atau kunjungi lancar.id.