Every one of the ten free tools on this site computes inside your browser. What you type into them is not sent to a server, not written to a database, and not seen by us. The calculation happens on your machine, in the page you already loaded.
That is an easy sentence to write and a cheap one to fake, which is why the more interesting half of this article is the part where you check it. It takes about thirty seconds and needs nothing installed.
The ten tools
Five aimed at the compliance side of an AI project, five at the engineering side. All free, no account, no gate.
| Tool | What it does |
|---|---|
| EU AI Act Risk Classifier | Answer a few questions, get your risk tier, the obligations that attach, and the date each one applies from. |
| AI Data Sovereignty Checker | Pick a model provider and a deployment mode, see where your prompts and retrieved context actually travel. |
| DSGVO RAG-Readiness Scorecard | Nine questions on what really blocks a rollout on internal documents — residency, impact assessment, processing agreement, works council, retention, audit. |
| AI Vendor Residency Lookup | A filterable reference of where common AI vendors host and process data, and what that exposes them to. |
| DPIA / AVV Starter | Generates the structure of a data-protection impact assessment or a processing agreement, to take to your officer and counsel. |
| RAG Cost & Self-Hosting Calculator | Size the metered cost of a retrieval system and watch it move with usage. |
| Token & Cost Visualizer | Paste text, see how it splits into tokens, price it at your own rate. |
| Chunking & Retrieval Playground | Move the sliders and watch how chunk size and overlap reshape what a retriever can find. |
| Embedding Cost Estimator | Cost out the first pass over a document corpus, and the re-runs nobody budgets for. |
| Context-Window Calculator | Check whether your prompt plus retrieved context fits a model’s window, and what to do when it does not. |
A note on terms, since two appear above and both get used loosely. RAG — retrieval-augmented generation — means an AI system that looks up passages from your own documents and answers from them, rather than from memory. A token is the unit models are billed and measured in, roughly three-quarters of a word in English.
How to check the claim yourself
Every browser ships with a panel that records the requests the page makes. It is the browser’s record, not ours, which is what makes this worth doing rather than reading.
Thirty seconds, no installation
- Open any tool on this site, then press F12 (Windows) or Cmd + Option + I (Mac).
- Select the tab labelled Network. It lists every request the page makes.
- Click the clear button — usually a circle with a line through it — so the list is empty.
- Now use the tool. Type into it, change the options, get a result — but leave the optional email form at the bottom alone for now.
- Watch the list. Nothing appears carrying what you typed. The answer arrived without a round trip, because it was computed where you are sitting.
If you want the sharper version of the test, turn off your network connection entirely and use the tool offline. It still works.
What “runs in your browser” means technically
Concretely: the tool logic itself makes no network call. Whatever you type into a classifier or a calculator is read by JavaScript already loaded in the page, computed there, and rendered back to you. There is no request to send, so there is nothing to intercept, log or retain. There is also no analytics script on this site at all — not a self-hosted one, not a third-party one — so there is no beacon recording that you used a calculator or what you put in it.
The two boundaries of that claim, drawn by us rather than found by you
Here is the part a marketing page would leave out. The claim above is about what the tool does with what you type. It is precise and it holds. The page around it does other things, and if you run the network test properly you will see them.
| On a tool page | Does it transmit anything? |
|---|---|
| The tool itself | No. Your input and its result stay in the page. |
| The optional email form, if you submit it | Yes — your address, which tool you were on, your consent flag. To this domain. Not your inputs or results. |
| The AI Assistant and AI Search widgets | Yes, on page load, to an origin that is not ours. Whatever you type into them reaches them. |
| The cookie-consent notice | Sends nothing, but writes one key to your browser’s local storage when you dismiss it. |
One: the optional email form. Below the result on each tool there is a form offering to send you a copy. It is optional and it sits below the answer rather than in front of it — but if you fill it in and submit, that is a request, to an endpoint on this same domain. What it carries is your email address, which tool you were on and your consent flag. It does not carry your inputs or your results; those stay in the page. If you never touch the form, nothing is sent at all.
Two: the assistant and search widgets. The pages also carry our own AI Assistant and AI Search widgets, and those are currently served from an origin that is not ours. You will see requests to that origin on page load, before you have done anything, and anything you type into the assistant does reach it.
The last row is in the table because “nothing is written to your browser” would have been the tidier sentence, and it would have been wrong.
We could have written “nothing on these pages calls a third party” and been mostly right. Mostly right is the failure mode this whole site exists to argue against, so: the narrower claim, and the open item stated in public.
Why they are not behind a form
A gated calculator converts better. Put an email field in front of a cost estimator and a measurable share of people will fill it in, and you get a list.
We decided against it on grounds that were not entirely noble — a list of people who wanted a number badly enough to trade an email for it is not a list of buyers — but mostly because of the contradiction. It is not possible to argue that a company should be able to inspect what its AI vendor does, and simultaneously require a company to identify itself before it may use a token counter. One of those positions would have to be the marketing one.
So the tools have no gate, and they are worse lead magnets than they could be. That was the trade.
Three ways people actually use them
A compliance lead scoping a project. Start with the risk classifier to establish which tier a planned system falls in and which date attaches to it — that alone resolves most of the phantom urgency in AI planning, because a great deal of material written in 2025 still carries superseded dates. Then the readiness scorecard, which asks the nine questions that actually stall internal rollouts.
A developer sizing an idea before proposing it. The token visualiser to understand what a document costs to process, the embedding estimator for the first pass over a corpus and the re-runs after that, and the chunking playground to see why retrieval quality moves so much with parameters that look cosmetic.
A buyer comparing vendors. The residency lookup and the sovereignty checker together answer a question most questionnaires never quite ask: not where is the data stored, but who can reach it and under whose law. The figures carry a date stamp on the page — read it, and treat the tool as a map of the questions rather than a current answer on any single vendor.
What they deliberately do not do
They do not make determinations. The risk classifier gives you a tier, the obligations attached to it and the date each applies from — it does not tell you that your system is or is not high-risk, because that depends on facts about your deployment that a five-question form cannot see. The DPIA and AVV starter produces a structure, not an assessment, and the structure is there so the first conversation with your data-protection officer starts further along than a blank page.
None of the ten is legal advice, and the two that come closest say so on the page.
The honest summary
Ten tools, no account, and a claim you can check without trusting us: what you type into them is computed where you are sitting and goes nowhere.
The claim stops at the tools, and we have said where. If you run the test and find something we have not described here, tell us — a claim you can check is only worth making if being wrong about it is expensive for the person who made it.
Frequently asked questions
Do I have to sign up or give an email address to use the tools?
No. There is no account, no gate and no email wall on any of the ten — you get the full answer without identifying yourself. There is an optional form below each result offering to email you a copy, and it does send your address to us if you fill it in and submit. It sits below the answer rather than in front of it, and your inputs and results stay in your browser either way.
How do I actually verify that nothing is sent?
Open your browser's developer panel — F12 on Windows, or Cmd + Option + I on a Mac — and select the Network tab. Clear the list, then type into a tool and change its options. Watch the list: no request appears carrying what you entered. You are watching the browser's own record of its traffic, not ours, which is the point.
Does the page as a whole make no requests, then?
No — and we would rather say so than have you find it. The tool logic makes no request. Two other things on the page do. The optional email form at the bottom of each tool posts to an endpoint on this same domain if you fill it in and submit — it carries your email address, which tool you were on and your consent flag, not your inputs or results. And our own AI Assistant and AI Search widgets load from an origin that is not ours, on page load, before you have done anything; whatever you type into those reaches them. There is also one cookie-consent key in local storage. The narrow claim — that what you enter into a tool and what it produces go nowhere — holds, and it is the only one we make.
Are the vendor and price figures in the tools current?
They are dated on the page, which is the honest form and also a warning. The vendor residency and sovereignty data carries a June 2026 stamp, so at the time of writing it is a quarter old — useful for the shape of the question, not authoritative on any one vendor today. Model prices and context-window sizes in the developer tools are dated the same way and are editable, so you can put your own contracted rate in rather than trusting ours. The EU AI Act dates in the classifier were rechecked against Regulation (EU) 2026/1744 before this article was published and are current.
Can I use the DPIA/AVV starter as our actual documentation?
No. It produces a structured starting point — the sections a data-protection impact assessment or processing agreement needs, in an order that makes sense for a retrieval system. It is something to take to your data-protection officer and your counsel so the first conversation starts further along. It is not the assessment and it is not legal advice.
Sources & further reading
- RAGSuite — free tools hub — all ten, no account required
- EUR-Lex — Regulation (EU) 2026/1744 (Digital Omnibus on AI) — the instrument the risk classifier's dates were rechecked against
- Chrome DevTools — Network features reference — how to read the network panel, if you have not opened it before