No account, no cookies, uploads never stored

What Recolor stores and fetches

Recolor (recolor.page) keeps privacy simple: it has no accounts and sets no cookies. Your palettes stay in your browser; a page fetched from an address sits in Cloudflare's cache for 60 seconds; an uploaded file is never stored. Each fetch logs the site's host name, status, size and time, not the page's path or your IP address, and the previewed page runs in a sandbox that cannot reach Recolor or you.

Last updated

From the Worker (src/worker), wrangler.jsonc and the app, checked October 8, 2026
WhatWhere it is keptFor how long
The palette and its undo historyThe URL and the open tabUntil you close the tab
Saved palettesYour browser's local storageUntil you delete them, 50 at most
A page loaded by addressCloudflare's cache, as prepared60 seconds
Fonts and masks of that pageCloudflare's cache1 hour
An uploaded fileNowhere: prepared and sent backNever stored
A log line per fetchCloudflare Workers logsHost name, status, size, time
Your IP addressThe rate limiter's count per minuteNot logged by Recolor
An account or a cookieNoneNone

What stays in your browser

The palette is the address: the hex codes after the # in the URL, as the URL format shows. Undo history, locks and the Mapping settings live in the open tab and go when you close it. Saved palettes are written to your browser's local storage under the key recolor:saved, 50 at most; no other browser and no server sees them. An uploaded file is kept in the tab's memory so Retry and the Scripts switch can use it again. Recolor sets no cookies and has no sign-in.

What passes through Recolor's Worker

A page you load by address is fetched by Recolor's Worker on Cloudflare, not by your browser. The request carries a fixed user agent, described on The Recolor fetcher, and nothing of yours: no cookies, no headers from your browser. The Worker prepares the page and keeps that copy in Cloudflare's cache for 60 seconds, so a reload is quick; fonts and CSS masks it passes on are cached for an hour. An uploaded file is sent to the Worker, prepared and returned, and never cached or written down.

Recolor logs one line per fetch: the host name, the status, the bytes and the time, plus an error code when a fetch fails. It does not log the page's path, the query or your address; Cloudflare's per-request logs, which would keep each address a visitor loaded, are turned off. The rate limit of 30 page loads a minute counts per IP address inside Cloudflare's rate limiting binding, which Recolor does not log or read back.

What the previewed page can and cannot do

The page shows in an iframe sandboxed with allow-scripts and nothing more. Its scripts can run, but the frame has no origin of its own: it cannot read Recolor's storage or yours, open windows, submit forms or move the top window somewhere else. Storage and cookies inside the frame are stand-ins that live in memory and vanish with the page. Links are caught by Recolor and loaded through it; forms are cancelled.

Images, video and some fonts of the page are requested by your browser straight from the site, as on a normal visit, so the site's servers see those requests. Recolor sets its pages to send no referrer, so those requests do not tell the site that Recolor showed it. A prepared page is served as plain text with a sandbox policy of its own, so it can never act as a live page under recolor.page. How the frame and the engine work together is on How Recolor repaints a page.

What Recolor refuses to fetch

The Worker fetches only http and https addresses without a user name or password, and refuses local and private names (localhost, .local, .internal, .lan and the like) and loopback, private and reserved IP ranges, for IPv4 and IPv6. It checks every redirect before it follows it, so a public page cannot redirect it into a private network. Page loads need a header only Recolor's own app sends, so other sites cannot borrow the fetcher from a browser, and the font route passes only fonts, stylesheets and images, never HTML or scripts. A page larger than 5 MB or slower than 10 seconds is not fetched; the rest is on Limits.

Analytics

The app page at recolor.page loads Totallytics, which describes itself as cookieless and counts page views, visits, referrers and countries. The content pages, this one included, load no analytics and no script other than the Copy button on code blocks. The palettes, the pages you load and the files you upload are not part of any analytics. Loading a page explains what each way of loading sends.

Common questions

Does Recolor store the pages I load?

No, not beyond the cache: a page fetched by address stays in Cloudflare's cache for 60 seconds, then it is gone. Uploaded files are never stored.

Does Recolor use cookies?

No. There is no account and no cookie; saved palettes use your browser's local storage, which stays on your device.

Can the site I load tell that I use Recolor?

Yes, in part. The page itself is fetched by Recolor's Worker with its own user agent, so the site's logs show Recolor. Images and video are fetched by your browser, without a referrer.

Can a page's scripts read my data or other tabs?

No. The preview has no origin of its own, so its scripts cannot read Recolor's storage, your cookies or other tabs, open windows or submit forms.

Does Recolor log the addresses I load?

No. A log line has the host name, the status, the size and the time of a fetch; the path, the query and your IP address are not logged.

Can I load a staging site safely?

Yes, if it is on a public address. Recolor refuses local and private addresses; for those, upload the HTML and set the asset base URL.

Sources