Input handling
- The selected file or pasted SVG is read in browser memory and is not uploaded or stored by the site.
- The SVG is parsed as inert XML, never inserted into the document, and never rendered.
- External references in SVG input are rejected and are not fetched.
- An optional SHA-256 is calculated locally with WebCrypto when available.
- A JSON report is downloaded only after you choose the download action; your browser controls that local file.
Page delivery
There are no analytics scripts, tracking pixels, cookies, input telemetry, or third-party page dependencies. Loading the hosted page still creates ordinary same-origin requests for HTML, CSS, and JavaScript. A host may process routine request metadata needed to deliver those assets; SVG content is not part of those requests.
Following an external source link leaves SVGViewport and is subject to the destination publisher's practices.
Search-only measurement boundary
A future operator may verify exact-host ownership and submit the one-root sitemap in Google Search Console and Yandex Webmaster, then inspect aggregate organic-search windows. That is a packaging plan, not proof of enrollment, indexing, traffic, or human task completion. It does not add page analytics or transport SVG input.