Your files and your privacy

Conversions run on our own servers, files are reachable only by the account that created them, and everything is deleted on a timer. Here is the detail.

Conversions run here

Files are not forwarded to a third-party conversion service. The tools that do the work — the image library, the document renderer, the media transcoder — run on our own machines, inside the same infrastructure that serves this page.

That is why the format list is what it is rather than whatever an upstream vendor happens to offer, and it is why the retention promise on the previous page is one we are able to make at all.

Files are scoped to the account that made them

Every stored file belongs to a job, and every job belongs to an account. A request for a job that belongs to somebody else is answered as though it does not exist, rather than as forbidden — telling the difference would confirm that other people's conversions exist and roughly how many.

Anonymous conversions are scoped the same way, to the browser that made them, and are the shortest-lived of all.

Uploads are streamed, never collected in memory

A file is written to storage as it arrives, in small windows, rather than being buffered whole first. Besides being the only way to accept a half-gigabyte upload without falling over, it means an upload that turns out to be too large is stopped part-way instead of being fully received and then rejected.

Deletion is on a timer, and the timer is the plan

There is no manual cleanup step to forget. Files carry an expiry stamped at the moment they are created, taken from the plan of whoever created them, and a sweeper removes everything past it — the input, the output and the job record's access to them.

You can also delete a conversion yourself at any time from your history, which removes it immediately rather than at the end of the window.

The privacy policy is the authoritative document on what we process and why. This page describes the mechanics.