← All tools

Privacy Policy

MoldChem Tools is built to collect as little personal data as technically possible. There are no accounts, no logins, no cookies, no advertising, and no cross-site tracking. This page explains, precisely and verifiably, the limited data that is nonetheless processed when you use the Site.

Last updated 17 June 2026 · Governing law: Republic of Moldova (with EU GDPR applied to visitors in the European Economic Area).

1. Who we are (data controller)

This website, MoldChem Tools (tools.moldchem.com, the “Site”), is operated by:

  • Operator: Vladislav Postica, acting as a private individual in the Republic of Moldova. The Site is a free, non-commercial beta and is not yet operated through a registered company.
  • Contact for privacy matters: [email protected]

A Moldovan limited liability company (SRL) is in the process of being established. Once it is registered, that company will become the operator and data controller of record; this Policy will then be updated with its legal name, registered address and registration number, and the “Last updated” date revised.

For the purposes of the EU General Data Protection Regulation (GDPR) and the Law of the Republic of Moldova No. 133 of 8 July 2011 on the Protection of Personal Data (Law 133), the Operator is the data controller for personal data processed through the Site. The Operator is the single point of contact for any question about this Policy or any request to exercise your rights (see Section 11).

2. Our privacy approach, in one paragraph

MoldChem Tools is a set of free, browser-based chemistry utilities. It is built to collect as little personal data as technically possible. We set no cookies. We run no advertising, marketing, or cross-site tracking. We do not sell or share your data. We have no user accounts. The chemistry lookups you run are sent to public scientific databases through a server-side proxy that shields your IP address and identity from those databases and adds no logging of its own. The sections below describe, precisely and verifiably, the limited data that is nonetheless processed when you use the Site.

3. What data we process, why, and on what legal basis

3.1 Search terms you type into the tools

When you use a lookup tool (for example, resolving a chemical name, formula, or CAS number), the text you enter is forwarded by our server-side proxy (/api/chem.php) to the relevant public chemistry database so it can return a result. See Section 6 for the list of databases and Section 7 for the international-transfer implications.

  • What is sent: the query text only. Our proxy does not attach your IP address, identity, cookies, or any other personal data.
  • Important: these search boxes are designed for chemical identifiers, not personal information. Please do not type names, contact details, health information, or other personal or sensitive data into a search field, because that text will be transmitted to the relevant database and may be reflected in a shareable URL (see Section 5.2).
  • Legal basis: Art. 6(1)(b) GDPR (performance of the service you request) and Art. 6(1)(f) (our legitimate interest in operating a functional lookup service).

3.2 Technical connection data (hosting and security)

To deliver the Site and protect it from abuse, our hosting and security providers automatically process standard technical data, including your IP address, the requested URL, timestamp, user-agent string, and similar request metadata. This is the normal operation of any website served over the internet.

  • Purposes: delivering the Site reliably, maintaining security, preventing abuse and denial-of-service, and diagnosing faults.
  • Legal basis: Art. 6(1)(f) GDPR — our legitimate interest in a secure, available service. We have balanced this interest against your rights and limited the processing to what is necessary for security and delivery.

3.3 Rate-limiting and abuse prevention

Requests to our proxy endpoints (/api/*) are rate-limited. The rate limiter and web application firewall are keyed by IP address to identify and throttle abusive traffic.

  • Purpose: protecting the Site and the upstream databases from misuse.
  • Legal basis: Art. 6(1)(f) GDPR (legitimate interest in security and service integrity).

3.4 Analytics (cookie-free)

The Site uses two privacy-first, cookie-free analytics services: Cloudflare Web Analytics (provided by our hosting provider, Cloudflare) and Umami (Umami Cloud, by Umami Software, Inc.). Each records only anonymous, aggregate metrics — such as page views, referrers, and basic performance timings — without setting any cookie, without any tracking identifier, and without building a profile of you. No personal data is collected for analytics, and the metrics cannot be linked back to an individual. Because both are cookie-free and strictly aggregate, they require no consent banner under the ePrivacy Directive (and PECR in the UK). The legal basis is Art. 6(1)(f) GDPR (our legitimate interest in understanding aggregate usage of the Site). See Section 8 for the provider disclosures.

3.5 Data we do not process

For the avoidance of doubt, the Site as currently deployed does not:

  • set any cookies, or use advertising, marketing, or cross-site tracking pixels;
  • use Google services (Analytics, Tag Manager, Fonts, reCAPTCHA, Maps) — fonts are self-hosted;
  • embed social-media widgets, A/B testing, or session-replay tools;
  • offer user accounts, logins, or payments;
  • access your camera, microphone, or geolocation (these device APIs are hard-disabled by our Permissions-Policy header).

4. Device and browser signals

To improve performance on lower-powered devices (for example, by reducing animation), the Site reads two coarse browser-provided values — navigator.deviceMemory and navigator.hardwareConcurrency. These values are read locally in your browser and are not transmitted to us or to anyone else. We do not use them to identify or track you.

5. Cookies, local storage, and shareable links

5.1 No cookies; only functional browser storage

The Site sets no cookies. It uses your browser's localStorage and sessionStorage only for strictly functional purposes that you control:

  • mc-legal-ack (localStorage) — records that you dismissed the one-time terms-acknowledgment notice, so it is not shown to you again;
  • mc-chem:<op>:<query> (sessionStorage) — caches a chemical lookup for the current browser tab so repeating it costs nothing; it is cleared automatically when you close the tab.

Neither contains personal data or advertising identifiers, and neither is used for tracking, profiling, or advertising. Because they are strictly necessary to provide functionality you have requested, they do not require a consent banner under the ePrivacy Directive / PECR. Full detail is in our separate Cookie & Storage Notice.

5.2 Shareable links (URL state)

Many tools mirror your inputs into the page URL so you can bookmark or share a deep link to a result. This means a link you share or bookmark may reveal what you entered (for example, a chemical name). This data stays in your browser and in any link you choose to share; it is not separately collected by us. Avoid sharing links that contain anything you consider sensitive.

6. Third-party chemical databases (data recipients)

The lookup tools resolve chemical identifiers, hazards, exposure limits, and properties by proxying your query through our server to the public scientific databases below. The browser never contacts these databases directly (our Content-Security-Policy prevents it); our server makes the request on your behalf using our own egress IP, so your IP address and identity are not disclosed to them. Only the query text is transmitted. Each provider operates under its own terms and privacy practices:

DatabaseProviderJurisdiction
PubChem (PUG REST / PUG-View / SDQ)U.S. National Library of Medicine, National Center for Biotechnology Information (NIH)United States
NCI/CADD Chemical Identifier Resolver (CIR)U.S. National Cancer Institute, CADD GroupUnited States
OPSIN (Open Parser for Systematic IUPAC Nomenclature)EBI mirror / University of CambridgeUnited Kingdom
EPA CompTox / CCTEU.S. Environmental Protection AgencyUnited States
CAS Common ChemistryCAS (a division of the American Chemical Society)United States

These databases are data recipients, not processors acting on our instructions; they receive only the query text. Where we hold API keys for a provider (EPA CompTox and CAS Common Chemistry), those keys are server-side secrets and are never exposed to your browser.

7. International data transfers

Because the databases above are located in the United States and the United Kingdom, the query text you type is transferred internationally when a lookup is performed. Our hosting and security provider, Cloudflare, also operates a global edge network that may process technical connection data outside your country.

Under Chapter V of the GDPR and the corresponding provisions of Law 133, such transfers require a safeguard. The Operator relies on the applicable transfer mechanism for each recipient (for example, the UK adequacy status, the EU–US Data Privacy Framework where applicable, and/or Standard Contractual Clauses with its infrastructure providers). Because the only personal data that could be transferred in a lookup is whatever you choose to type, the practical exposure is minimised by not entering personal data into search fields (Section 3.1). You may request details of the transfer mechanism relied upon by contacting us (Section 1).

8. Hosting, processors, and sub-processors

We use the following service providers to operate the Site. They process data on our behalf under data-processing terms:

  • Cloudflare, Inc. (101 Townsend Street, San Francisco, CA 94107, USA) — primary hosting, CDN, edge compute (where our proxy runs), security/WAF, and rate limiting. Cloudflare processes visitor IP addresses and request metadata and keeps standard edge logs. Optional edge caching (Cloudflare Workers KV) may store query-derived results keyed by a hash of the query; this cache contains no personal data.
  • Cloudflare Web Analytics (a Cloudflare, Inc. service) — cookie-free, privacy-first aggregate analytics (see Section 3.4). It sets no cookie, uses no tracking identifier, and processes no personal data; the metrics are anonymous and aggregate.
  • Umami Software, Inc. (Umami Cloud) — cookie-free, privacy-first aggregate analytics (see Section 3.4). It sets no cookie, uses no tracking identifier, and processes no personal data; the metrics are anonymous and aggregate.

We will name any new processor or material change in this Section and update the “Last updated” date.

9. How long we keep data

  • Query text: our proxy performs no application-level logging of queries. Cached results are content-only and keyed by a hash of the query, contain no personal data, and expire automatically (typically up to 180 days for found results, 1 day for misses).
  • Technical logs (IP/request metadata): retained by our hosting/security providers for the limited period necessary for security and operational diagnostics, in line with their standard retention, and not longer than necessary for those purposes.
  • Functional browser storage: remains in your browser until you clear it; per-tab sessionStorage clears when you close the tab.

We do not maintain user profiles or long-term records linking queries to individuals.

10. How we protect your data

The Site is engineered with privacy and security safeguards, including:

  • a strict Content-Security-Policy that prevents the browser from contacting any third party other than the same origin and the cookie-free analytics endpoints (Cloudflare Web Analytics and Umami) — so chemistry databases can only ever be reached through our shielding proxy;
  • Referrer-Policy: strict-origin-when-cross-origin to limit referrer leakage to external links;
  • Permissions-Policy disabling camera, microphone, and geolocation;
  • HTTPS everywhere (upgrade-insecure-requests), plus object-src 'none', frame-ancestors 'self', and base-uri 'self';
  • API keys held only as server-side secrets, never exposed to the browser.

No method of transmission or storage is completely secure, but these measures substantially reduce the data exposed in normal use.

11. Your rights

Subject to the conditions in the GDPR and Law 133, you have the right to: access your personal data; request rectification of inaccurate data; request erasure; request restriction of processing; object to processing based on legitimate interests; and request data portability. Where processing is based on consent, you may withdraw it at any time. You also have the right to lodge a complaint with a supervisory authority.

To exercise any of these rights, contact us at [email protected]. Note that, because we do not keep accounts and perform no query logging, we often hold little or no personal data that can be linked to you; we may need additional information to locate any data or to verify your identity before acting on a request.

Supervisory authorities:

  • Republic of Moldova: the National Center for Personal Data Protection (Centrul Național pentru Protecția Datelor cu Caracter Personal — datepersonale.md).
  • European Economic Area: the data protection authority of your country of residence.

12. California residents (CCPA/CPRA)

If you are a California resident: we do not sell or share personal information, and we use no cross-context behavioural advertising. The limited data described in this Policy is processed only for the operational and security purposes stated. You may contact us at [email protected] to exercise applicable rights to know, delete, or correct.

13. Children

The Site is a professional/technical reference tool and is not directed at children. We do not knowingly collect personal data from children.

14. External links

The Site links to external websites, including the separate moldchem.com site. Those sites are operated independently and have their own privacy policies. This Policy does not cover any processing carried out on moldchem.com or on any other third-party site. Following an external link shares only standard navigation data and a referrer, which our Referrer-Policy already restricts.

15. Changes to this Policy

We may update this Policy to reflect changes to the Site or to legal requirements. The current version is always identified by the “Last updated” date at the top. Material changes — for example, activating analytics or launching account/payment features — will be reflected here before those features process your data.

16. Contact

Questions, requests, or complaints about privacy:

MoldChem Tools — operated by an individual pending incorporation (full operator identity in Section 1), Republic of Moldova
Email: [email protected]
A registered postal address will be published here once the operating company (SRL) is established; until then it is available on request via the contact email.

Related

Privacy questions: [email protected] · Last updated 17 June 2026.