1. Schema inputs
Paste, edit, file, and drag/drop
These input modes use browser APIs. The source remains in memory in the current tab and is discarded when the tab is closed or another document replaces it. We do not upload it to our servers.
Descriptions are rendered as inert text. The viewer does not execute HTML or script found in an OpenAPI document.
2. Explicit network boundaries
Load from URL
When you enter a URL, your browser requests that document directly from the source host. The request does not pass through our proxy and is sent without browser credentials or a referrer. The source host sees the network request and applies its own privacy policy and CORS rules.
External $ref values
External file and URL references are detected but never fetched
automatically. Internal references that begin with
#/ resolve only within the source already in memory.
Local share links
If you explicitly create a share link, a document up to 200 KB is
compressed into the URL fragment after #spec=.
Browsers do not include fragments in HTTP requests, and our
analytics configuration removes fragments from the page location.
Anyone who receives the complete link can decode the source. Chat systems, browser history, screenshots, device backups, or recipients may expose it. Do not create or send a share link for a contract that should remain confidential.
3. Product analytics
We use Google Analytics 4 to understand whether the viewer loads successfully and which product areas are useful. The site does not display a separate analytics-consent popup. Google Analytics may use first-party identifiers and process device, browser, approximate geographic, referral, and interaction information. The viewer configures Google Signals off.
Events are deliberately limited to bounded categories such as:
- input mode: file, paste, URL, drop, sample, or share;
- format, version family, and broad file/count buckets;
- parse success or a fixed non-content error reason;
- viewer tab, search category, reference navigation, copy, share, and theme actions.
Analytics does not receive schema text, file names, URLs you enter, API paths, operation IDs, model or property names, descriptions, examples, copied values, credentials, error snippets, or URL fragments.
You can block analytics with browser privacy controls, a content blocker, DNS filtering, or a browser profile configured to reject analytics scripts.
4. Browser storage
The selected warm, blue, or dark color theme is stored in
localStorage so it persists on this device. The
OpenAPI source itself is not written to local storage by the
viewer. Google Analytics may set first-party measurement cookies
or equivalent identifiers according to the user's browser
settings and Google's service behavior.
5. Support and feedback email
If you email hello@openapischemaviewer.com or support@openapischemaviewer.com, we receive the address, headers, message, and any attachment you intentionally send. A spec is never attached automatically.
Send the smallest non-confidential reproduction that explains a bug. Remove access tokens, private server names, customer data, secrets, and internal descriptions first.
6. Retention, processors, and choices
Local schema content is not retained by us. Analytics retention and deletion follow the configuration of our Google Analytics property and Google's processor terms. Web hosting and security are provided by Cloudflare, which may process ordinary request logs such as IP address, user agent, requested page, response status, and time for delivery and abuse protection.
Support email is retained only as reasonably needed to answer, investigate, prevent abuse, and maintain a useful history, then can be deleted when no longer needed. You may ask us to locate or delete support correspondence associated with your email address, subject to applicable obligations and technical limits.
This service is not directed to children, and it is designed for people reviewing technical API descriptions.
7. Contact and policy changes
Questions or requests: support@openapischemaviewer.com. Material changes will be reflected on this page with an updated date. Your continued use after a change is subject to the revised policy.