Privacy notice
Many of the tools here never send your document anywhere. This notice explains the exceptions, what an account stores, how long anything is kept, and how to have it deleted.
This notice is incomplete: the operator's name, address and contact address are not configured for this deployment.
Who is responsible
[—], [—], is the controller for the processing described here.
Write to [email protected] for any data-protection question, including access, correction, deletion or portability. General support is at [email protected].
Tools that never upload your file
Many tools run entirely inside your browser. The document is read into a worker in the page, processed there and offered back to you as a download. No copy is transmitted to us, so there is nothing for us to store, read or disclose. Closing the tab discards the working copy.
Tools that need a server
Some formats need engines that cannot run in a browser. Those tools upload the file to private object storage using a short-lived signed link, run it through an isolated worker, and return a result you download through another short-lived link. Links expire after 15 minutes.
Uploaded files, the results and the working copies are deleted automatically: after 1 hour without an account, and after 7 days for work owned by an account. Deletion is by scheduled sweep, not on request only, and you can delete any job yourself before then.
What an account stores
An account holds your email address, a hash of your password, the sessions you have open, the record of server jobs you ran while signed in, and any workflows you saved. Your password itself is never stored, and neither is anything that could be replayed as a session.
An account is optional. Every browser tool, and every server tool, works without one.
Why we are allowed to process this
Running the tool you asked for and operating your account is performance of a contract with you. Rate limits, quotas, malware scanning and security logging rest on our legitimate interest in keeping the service available and safe. Anything optional, such as advertising, runs on consent and nothing else.
Who else is involved
The infrastructure that hosts the application, its database and its object storage processes data on our instructions. A transactional email provider receives your address only when a password-reset or address-confirmation message has to be sent. Document content is never sent to an email provider, an analytics service or an AI service.
Our transactional email provider is established in the United States, so your address leaves the European Economic Area when a reset or confirmation message is sent. That transfer is covered by the European Commission's standard contractual clauses. A content delivery network sits in front of the site to carry traffic and absorb abuse. It is also established in the United States and its transfers rest on the same clauses. It relays requests rather than storing them, but the bytes of an upload and of a download pass through it. Apart from these two, nothing about your account and no document is transferred outside the European Economic Area.
What is kept in logs
Operational logs record the request method and path, a request identifier, the response status, and for a server job its identifier, the operation and any error code. File names, document content and the addresses you submit to URL-based tools are never written to them; session identifiers and cookies are redacted, and your network address is not logged at all.
Your network address is used while the request is being served, to apply the rate limits, and is stored against a server job so the daily allowance can be counted. That column is cleared after 48 hours - long after it can affect an allowance, and long before it becomes a record of you.
Your rights
You can ask for a copy of your data, correct it, have it erased, restrict or object to processing, and receive it in a portable form. You can delete your account and everything stored for it yourself, from the account page, without asking us.
If you believe we have handled your data unlawfully you may complain to the supervisory authority in [—] or where you live.
Security
Connections are encrypted. Passwords are stored with a memory-hard key-derivation function and session tokens only as digests. Uploads are scanned for malware before any engine parses them. Document engines run as an unprivileged user in an isolated container with a read-only root filesystem.
Changes
If this notice changes in a way that affects you, the new version is published here before it takes effect.