Your files and your privacy
Conversions run on our own servers, files are reachable only by the account that created them, and everything is deleted on a timer. Here is the detail.
Conversions run here
Files are not forwarded to a third-party conversion service. The tools that do the work — the image library, the document renderer, the media transcoder — run on our own machines, inside the same infrastructure that serves this page.
That is why the format list is what it is rather than whatever an upstream vendor happens to offer, and it is why the retention promise on the previous page is one we are able to make at all.
Files are scoped to the account that made them
Every stored file belongs to a job, and every job belongs to an account. A request for a job that belongs to somebody else is answered as though it does not exist, rather than as forbidden — telling the difference would confirm that other people's conversions exist and roughly how many.
Anonymous conversions are scoped the same way, to the browser that made them, and are the shortest-lived of all.
Uploads are streamed, never collected in memory
A file is written to storage as it arrives, in small windows, rather than being buffered whole first. Besides being the only way to accept a half-gigabyte upload without falling over, it means an upload that turns out to be too large is stopped part-way instead of being fully received and then rejected.
Deletion is on a timer, and the timer is the plan
There is no manual cleanup step to forget. Files carry an expiry stamped at the moment they are created, taken from the plan of whoever created them, and a sweeper removes everything past it — the input, the output and the job record's access to them.
You can also delete a conversion yourself at any time from your history, which removes it immediately rather than at the end of the window.
The privacy policy is the authoritative document on what we process and why. This page describes the mechanics.