Privacy & data handling
The data used by the service depends on the tool and the settings you choose.
Last updated: 7 October 2026.
On-device processing
On-device tools read and process the selected file in your browser. Their processing workflow does not upload the file. The separate, sandboxed tool frame has a security policy that restricts network requests. These controls reduce exposure but are not a guarantee against every browser, device or software vulnerability. See Verify it yourself for ways to inspect the behavior.
Cloud processing
Cloud tools upload the file after you start the cloud operation. The interface shows the processing location before upload. The server receives file contents, selected options, type and size, and calculates a checksum to process the request and check the transfer. The application uses a generated job identifier; the original file name stays in the page to name your download.
Jobs run in separate containers with restricted network access, permissions, memory and execution time. Uploaded content is used to carry out the selected operation. Review the result before relying on it, especially for sensitive or important documents.
Retention and deletion
The application schedules cleanup from job creation, including time spent uploading and waiting. The default period is 60 minutes; the interface also offers 15 minutes or deletion after the result is transferred to the browser. A preview may perform that transfer before you save a download. The input is scheduled for removal when processing ends. You can also request deletion with the server-delete control.
Expired jobs are intended to stop and their results become unavailable. Cleanup depends on running services and storage; interruptions or faults may delay physical removal. This is temporary processing, not a file-storage or backup service. Keep your original files and download any results you need.
An active job record contains the tool, options, file type, size, checksum, times and status. After file deletion, a reduced record with the tool, status, times and a hash of the access key is retained for 24 hours by default. Application logs are restricted to operational fields such as job IDs, tool names, codes, durations and rounded sizes. The default deployment rotates about 30 MB of logs per service; this is a size limit, not a fixed time period.
Service operation and abuse prevention
Network requests expose an IP address and browser request headers to the server. They are processed to deliver the service, enforce limits and protect availability. For rate limiting, the application uses salted hashes of the IP address or network prefix. The salt changes daily and on API restart; these rate-limit values are held in memory, with counters lasting up to 24 hours and an active-job association while needed.
Optional usage statistics
Usage statistics are sent only after you confirm consent in the first-visit panel or the analytics settings opened from the footer. The panel’s initially enabled switch is a proposed choice, not active collection; opening its settings or continuing to browse does not give consent. This choice is separate from permission to upload a file. Statistics help assess tool usage, errors and navigation. You can disable them again; Do Not Track or Global Privacy Control also disables collection.
When enabled, short messages include catalog page keys, tool steps and error codes, site and browser language, device class, referrer domain and an optional utm_source label. The server derives browser and operating-system families and approximate country from request information. Country lookup uses a local database. The analytics payload excludes file contents, original file names, file sizes and option values.
For visitor estimates, the server transiently processes the IP address or prefix and browser header using keyed hashes. These feed probabilistic aggregate counters, including a counter with a stable site-specific key for estimates across days. Although stored statistics are aggregate, their calculation can involve network and browser information that is personal data under applicable law. Individual IP addresses, browser strings and hash lists are not part of the stored counters.
Aggregate daily counters are retained for 400 days by default. A short sequence of up to five catalog page keys is stored in the current tab while analytics is enabled; it stops being reused after 30 minutes of inactivity. Disabling analytics stops new messages and clears the local sequence; requests already sent may still finish. Earlier contributions cannot be separated from the aggregate counters to identify or remove a particular person’s contribution.
Browser storage and your choices
The Cookie Policy lists language, theme, saved-option, analytics-choice and tab storage, their purposes and lifetimes, and ways to manage them.
Depending on applicable law, you may have rights to information, access, correction, deletion, restriction, portability, objection and a complaint to a supervisory authority. To withdraw consent for optional analytics, open Analytics settings in the footer, turn the switch off in the panel’s settings and select Save choice. Other requests can be made through available site contact channels. We may need enough information to locate a request or verify authority; avoid sending sensitive documents solely to make a privacy request.