Privacy Policy
Effective Date: September 17, 2026 • Last Reviewed: September 2026
Our Core Commitment: Zero Server Transmission
Every operation on SAMLDecoder.com — including SAML decoding, deflate inflation, XML formatting, X.509 certificate parsing, and claims inspection — runs 100% locally in your web browser. Not a single byte of your SAML payload, user identity, certificate, or cryptographic key is ever sent to our servers or any third-party.
1. Information We Do Not Collect
Unlike legacy developer utilities that rely on server-side processing (such as PHP backends), SAMLDecoder.com was architected specifically to eliminate data exposure risks for enterprise teams:
- No SAML Payloads: We do not log, store, inspect, or transmit any raw SAML requests, SAML responses, XML assertions, or metadata you paste or upload.
- No User Identity Data (PII): Employee email addresses, usernames, display names, telephone numbers, group memberships, and session indices remain strictly in your browser's runtime memory.
- No Cryptographic Materials: Private certificates, public keys, and signatures are processed using the native W3C WebCrypto API and are instantly released from memory when you close or refresh the tab.
2. Local Storage and Browser State
SAMLDecoder.com uses the browser's standard localStorage API exclusively for user interface preferences:
theme: Stores your chosen visual mode (lightordark) to prevent flickering when reloading pages.
We do not store SAML tokens, history, or credentials in persistent browser storage. All inputs are cleared upon page refresh unless intentionally retained in your active browser session.
3. Cookies, Tracking & Analytics
We believe developer tools should be fast, quiet, and respect user privacy:
- We do not set tracking cookies or advertising pixels.
- We do not sell, rent, monetize, or share your usage data with data brokers or marketing platforms.
- Standard web server hosting logs may record high-level, anonymized network metadata (such as IP address, browser user-agent, and requested asset path) strictly for network DDoS protection, CDN asset caching, and infrastructure stability. These server logs never contain SAML payload data.
4. Enterprise Compliance (GDPR, SOC 2, HIPAA)
Because SAMLDecoder.com does not collect, process, or store personal data on remote servers, using this tool does not create an external data processor relationship under European General Data Protection Regulation (GDPR) Article 28, nor does it violate HIPAA or SOC 2 confidential data boundaries.
Security analysts, penetration testers, and identity architects can safely debug real production tokens containing employee records without triggering enterprise data leak prevention (DLP) alerts.
5. Third-Party External Links
Our site may contain links to external specifications, standards bodies (such as the OASIS SAML 2.0 specifications), or browser extension marketplaces. We are not responsible for the privacy practices or content of external third-party domains.
6. Updates to This Privacy Policy
We may update this policy occasionally to reflect service improvements. Any modifications will be posted here with an updated revision date. Our core commitment to 100% client-side zero-transmission processing will remain absolute.
7. Contact Us
If you have any questions or security concerns regarding this privacy policy, please reach out to us at privacy@samldecoder.com or visit our Contact Page.