Privacy Policy
What we collect
We do not collect, store, or transmit the contents of your files. Files processed on your device (the client-side tools) never leave your browser. Files processed by the heavy video tools are uploaded to a private processing server over an encrypted connection and deleted within 1 hour of processing. We log anonymized telemetry events only, and never filenames, file contents, or your identity.
In concrete terms, the two paths work like this:
Client-side tools (all image converters, HEIC conversion, JPG to PDF, audio converters, image compression and resizing): your file is read and processed entirely by code running in your browser. No copy ever reaches our infrastructure, so there is nothing on our servers to breach, subpoena, or delete.
Server-side tools (video compression, video conversion, and video metadata removal for files over 100 MB): the file uploads directly to storage via a short-lived signed link, is processed by the worker, and both the input and the output are deleted automatically within an hour of processing. The web server itself never receives a copy of your file.
What we consider personal data
We treat personal data as anything that identifies you: your name, your email, an account, or the contents of your files. We never ask for these and never see your files. There are no accounts on this site, so there is no profile to build on you.
The cookie identifiers used on this site are random values that cannot identify you, and the analytics services we use (only if you accept them) receive anonymous usage statistics, never file data.
Rate limiting
To protect the service from abuse, we record a per-IP processing limit. IP addresses are used only for rate limiting, are stored transiently, and are not used to identify you, profile you, or shared with third parties.
Cookies
We set one necessary session cookie (sid) that ties your jobs and processing limits to this browser, and one necessary cookie (mk_consent) that remembers your cookie choices. Analytics cookies from Google Analytics and Microsoft Clarity load only if you accept them in the cookie settings. Advertising cookies exist only when ads are shown, and are only personalized if you accept ads.
If you decline analytics and ads, the only cookies present are the two necessary ones described in the table below.
The cookies we set
| Cookie | Kind | Expiry | Purpose |
|---|---|---|---|
| sid | Necessary | 30 days | Anonymous session token. Ties your jobs and processing limits to this browser. Set by us. |
| mk_consent | Necessary | 180 days | Remembers your cookie choices so we do not ask again. Set by us. |
| _ga, _ga_* | Analytics | Up to 2 years | Google Analytics: anonymous visit and tool-usage statistics. Only set if you accept analytics. |
| _clck, _clsk | Analytics | 1 year / 1 day | Microsoft Clarity: anonymous usage heatmaps. Only set if you accept analytics. |
| Google AdSense cookies | Marketing | Up to 2 years | Ad measurement and (with consent) ad personalization. Present only when ads are shown and you accept ads. |
Who processes your data
Client-side tools process files entirely on your device. Server-side tools process files on our private infrastructure and erase them automatically.
When you accept analytics, two third-party processors are involved: Google (Analytics) and Microsoft (Clarity), each under their own privacy policy. If advertising is added later, Google (AdSense) would be involved and may serve personalized advertising where consent allows. If you accept nothing, no third-party processor receives anything beyond what is technically unavoidable (for example, your connection to the site itself).
Data retention
File data: deleted within 1 hour of server-side processing, and never stored at all for client-side tools.
Job records: a processing job is stored as a database row (status, timestamps, and file size) so the site can show progress and enforce limits. The row carries no file contents and no personal identity. Old job rows are purged automatically.
Telemetry: anonymized events (which tool ran, whether it succeeded, error codes) are kept in aggregate to fix bugs. They never contain filenames or file contents.
Server logs: standard operational logs may exist briefly for debugging. We do not put user filenames or file contents in logs.
Your rights
Because we hold no personal data beyond anonymous cookies and rate-limit records, most data-protection rights (access, portability, erasure of your data) are trivially satisfied: there is nothing that identifies you to access or erase.
If you are in the EEA, UK, or another jurisdiction with data-protection law, note that the legal basis for the two necessary cookies and transient rate limiting is legitimate interest (keeping the service working and safe), and that analytics cookies are set only with your consent, which you can withdraw at any time from the cookie settings.
Children
The site is a general-audience tool and is not directed at children under 13. We do not knowingly collect any personal information from anyone, including children, because there is no collection of personal information at all.
Changes to this policy
If the data practices described here change (for example, a new analytics provider or a new processing path), this page is updated and the change is described in plain language rather than buried. Continued use of the site after a change means you accept the updated policy.
Contact for deletion requests
Because files are automatically deleted and we keep no file contents, there is nothing to delete on our end. For any privacy question that this page does not answer, contact us via the contact page.