Interactor (“we”, “us”) operates the tools at tools-inter.actor and 77.tools — Telegramer, The Archiver, Social Search, Sonar, the 2FA Code tool, the Metadata Remover (website, Chrome extension, and macOS app), QR Studio, the Crypto Suite, the Fingerprint Inspector, File Drop, File Request and Encrypted Paste. In short: we collect as little as possible, we don’t sell data, and there are no third-party trackers.
Several tools are built so that we cannot see your content even if we wanted to: File Drop, File Request and Encrypted Paste encrypt in your browser and we only ever hold ciphertext; the 2FA Code tool and Social Search run entirely on your device and send us nothing at all.
The team tools use a username and password. We do not require an email address. Passwords are stored only as a salted hash — never in plain text. A single session cookie keeps you logged in; it is essential to the service and is not used for tracking.
When you connect a Telegram account, its session is stored encrypted and used only to perform the actions you request (inviting, extracting, safety checks). We do not read your private messages.
On the website and Chrome extension, files are processed in memory only: a cleaned copy is returned and both the original and result are discarded immediately — nothing is written to disk or stored. The macOS app runs entirely on your device and uploads nothing.
Dynamic QR codes record scan analytics for the link’s owner. These are privacy-preserving: we store a one-way hash of visitor info (not a raw IP address), an approximate country from an offline database, and basic device/browser type — never precise location or personal identifiers.
The Crypto Suite reads public blockchain data from third-party APIs to show fund-flow graphs and sanctions screening. We don’t retain the addresses you look up beyond your session. It is intended for research, compliance, and safety — not for profiling individuals.
When you archive a channel or account, we fetch the posts and media you asked for and store them so you can browse, search and download them. An archive is visible only to the account that created it, and you can delete it at any time — deletion removes the stored messages and media from our server.
Please note that an archive contains other people’s content. You are responsible for having a legitimate reason to collect it, for handling it lawfully, and for deleting it when you no longer need it. We do not publish archives, index them, or use their contents for anything other than serving them back to you.
Social Search builds a query URL and hands it to you; the search then runs in your own browser session on the platform itself. We do not receive, store or see your results. Two helper lookups (resolving a Facebook ID and finding an Instagram location ID) are performed by our server on your behalf and are rate-limited; we keep the resolved identifier only briefly in a cache.
Setup keys and codes are computed entirely in your browser. A plain share link keeps the key in the
part of the URL after the #, which browsers never transmit, so it never reaches our server or our
logs. If you create a password-protected short link, we store only the encrypted blob: the password never
leaves your browser, so we cannot decrypt it. Those links expire on the schedule you choose.
Sonar searches a collection of third-party breach and leak records. It runs on its own dedicated server and shares your Interactor login. Searches are rate-limited and recorded in an audit log (who searched, what identifier, when) so the service can be kept accountable and protected from abuse; that log expires automatically. Sonar is provided for security research, compliance and checking your own exposure — not for profiling or targeting people.
Content is encrypted in your browser with AES-GCM-256 before upload. The key lives in the part of the share
link after the # and is never sent to us, so we store ciphertext we cannot read — not your
text, filenames or file contents. Items self-destruct at their expiry, or after the first view if you choose.
Encrypted Paste can be used without an account. If you opt in to a “short link”, the key is
stored on our server so the short URL can rebuild it — that specific option is not zero-knowledge, and the
interface says so at the point of choice.
The browser-fingerprint measurements run on your device and are not uploaded. The network checks (IP details, VPN/proxy detection, DNS-leak test) necessarily involve your IP address and use offline databases plus, if enabled, a reputation lookup. We do not keep a record of your results.
If you write to us through the contact form, we store the email address and message you submit, plus the sending IP address for abuse prevention. It is kept privately for our team to read and reply to — it is not forwarded to any third party, mailing list or external mail service. Ask us and we will delete it.
To keep the service available and prevent abuse, our server keeps minimal, short-lived request logs (e.g., IP address, timestamp, response status), used only for security and rate-limiting. They do not contain your files.
No advertising, no third-party analytics or trackers, and we do not sell, rent, or share your data. Outbound requests happen only to the services needed to run a tool you actively use.
Our Metadata Remover clients are open source (MIT) so you can verify these claims: github.com/InterActorAi-tools.
The service is not directed to children and does not knowingly collect information from them.
We may update this policy; the effective date above reflects the latest version.
You can delete your archives, pastes, drops and QR codes yourself at any time, and ask us to delete your account or any message you have sent us. Because several tools are zero-knowledge, some things simply cannot be recovered or handed over — if you lose the key in a share link, the content is unrecoverable, including by us.
Questions, or a deletion request: use our contact form.