Privacy Policy
Effective date: May 1, 2026 · Last updated: September 3, 2026
1. What this policy covers
This Privacy Policy describes how PrivConvert, operated by topriv ("topriv", "we", "our", "the Service"), handles information when you use privconvert.com. By using the Service you agree to the practices described below.
2. File processing
- All uploaded files are processed in volatile memory (RAM). Files are never written to permanent storage.
- Your file data is purged from memory immediately once the converted result is delivered to your browser, or after a short timeout if the download is not completed.
- We have no ability to recover, view, or access your files after processing.
- No copies, thumbnails, caches, or backups of your files are created at any point.
- Some tools run entirely inside your browser. In those cases your files never leave your device.
3. Information we collect
We are committed to collecting as little information as possible:
- No sign-up to convert - every conversion tool on the website works without registration. An account is needed only if you buy a paid API plan.
- Customer accounts (paid plans only) - if you purchase a paid plan, we create an account for you and store the minimum needed to operate it: your email address, a securely hashed password (we never store the password itself), your plan type, and account status. Account data is never linked to the files you convert and is not shared with anyone. Contact [email protected] to close your account at any time.
- API usage counters (paid plans only) - to enforce your plan's monthly quota we store a single running total per key per month, plus the date a key was last used and any label you gave it. That is all. There is no per-request log: we do not record which tools you called, when each call happened, what your files were named, or anything about their contents.
- Billing records (paid plans only) - we keep the invoices and payment records for your subscription. We never receive or store your full payment card details. See Section 8 for how long billing records are kept and why.
- Privacy-friendly analytics - we use a cookieless, privacy-respecting analytics tool to understand aggregate usage, such as page views and which conversion tools are popular. It does not set cookies, does not fingerprint your device, does not track you across other websites, and never receives your files or their contents. The data is aggregated and is not used to identify you.
- No advertising or behavioural profiles - we do not build profiles of you and do not use surveillance trackers such as Google Analytics or Meta Pixel.
- IP addresses - like every web server, ours writes a standard access log entry for each request. That entry contains the IP address the request came from, the time, what was requested, the page you came from and your browser's user-agent string. It exists so that automated systems can spot and block attacks and abuse, and for nothing else: it is not used for analytics, advertising or profiling, and it is never joined to account or billing data. Log files are rotated daily and deleted automatically by age, so no entry survives longer than 15 days. It never contains your files, their contents or their names. A temporary one-way hash of your address is also held briefly in memory for rate limiting and is then discarded. See Section 7 for the detail.
- Cookies - we set no tracking cookies of any kind, and no advertising cookies are set by anyone, because the Service carries no advertising. Signed-in customers receive one essential session cookie so the account stays logged in. Essential security cookies may be set by Cloudflare (see Section 6). The full list is in our Cookie Policy.
4. How we use information
The limited information described above is used exclusively to:
- Deliver the file conversion you requested
- Understand aggregate, anonymous usage so we can improve the Service
- Protect the Service and its users from abuse, attacks, and illegal activity (rate limiting, bot prevention)
- Maintain basic operational reliability
- Operate paid subscriptions - authenticate your account, apply your plan's quota and limits, issue invoices, and contact you about your subscription, billing, or a security matter affecting your account
We do not send marketing email to customers who have not asked for it. Where we rely on a legal basis under the GDPR, it is the performance of our contract with you for account and billing data, our legitimate interest in keeping the Service secure and available for abuse prevention, and a legal obligation for the retention of accounting records.
We do not sell, rent, or share any information with third parties for marketing or profiling purposes.
5. Advertising
The Service carries no advertising. There are no ad slots on any page, no advertising network receives a request from this site, and no advertising or measurement script is loaded. Nothing about your visit is sent to an ad platform, so there is no advertising profile of you to opt out of.
This is a deliberate choice rather than a temporary state. A file conversion service sees the documents people are least willing to hand over, and funding it with advertising would mean inviting a third party to observe the visit. We fund the Service through paid API plans instead.
6. Third-party services
The Service relies on a small number of external providers:
- Cloudflare - content delivery, DDoS protection, and bot mitigation. Cloudflare may set essential security cookies. Cloudflare Privacy Policy.
- Email delivery - a transactional email provider is used to send account and billing messages to paid customers, such as sign-in details and invoices. It receives your email address and the message, and is not used for marketing.
- Paddle - card payments for paid plans are processed by Paddle, which acts as the merchant of record. Paddle operates the checkout, receives your payment details directly, and calculates and remits any tax due in your jurisdiction. We receive only what we need to recognise your subscription and issue an invoice, and never your full card number. See our Refund and Cancellation Policy. Paddle Privacy Policy.
These providers act only on our instructions for the purposes described above. None of them ever receives your files or their contents.
Our web fonts are served from our own domain rather than from a font provider, so requesting a typeface does not tell a third party that you were here. Our analytics runs on our own server under our own subdomain rather than on someone else's platform, so the aggregate usage data described in Section 3 never leaves our infrastructure. There is no ad network, tag manager, session recorder, heatmap tool or social pixel anywhere on the site.
7. Data security
We take the security of your files seriously. All connections to the Service are encrypted using industry-standard HTTPS/TLS. Uploaded files are validated before processing, are processed in isolated environments, and potentially harmful files are rejected. We regularly review our security practices to ensure your data remains protected throughout the conversion process.
To protect the Service and other users from abuse, attacks and illegal activity, our web server keeps a standard access log. Every request writes a single line to it recording the IP address it came from, the time, the page or endpoint requested, the referring page and the browser's user-agent string. Automated tools read that log to recognise attack patterns and block the addresses behind them. Log files are rotated daily and then deleted automatically once they pass a fixed age, so no entry survives longer than 15 days and nothing older than that exists to be requested, subpoenaed or breached. It never contains your files, their contents or their names, it is not used for analytics, advertising or profiling, and it is never combined with account or billing data. Under the GDPR we rely on our legitimate interest in keeping the Service secure and available.
Requests that trigger our automated protections are additionally recorded with minimal technical detail - for example a one-way hashed identifier, an approximate country, the type of client, and the nature of the blocked request - so that repeat offenders can be blocked for longer. These records likewise never contain your files or their contents.
8. Data retention
We keep as little as possible, for as short a time as possible:
- Your files and their contents - held in memory only, for the duration of the conversion. Purged immediately once the result is delivered, or after a short timeout if the download is never completed. Nothing is retained.
- Analytics - aggregate, cookieless counts. These are never tied to an identifiable person and there is nothing in them to delete on request.
- Server access logs - the security log described in Section 7, which contains IP addresses and request details. Rotated daily and deleted automatically by age, never kept longer than 15 days.
- Security records - the minimal technical detail described in Section 7 about requests that were actively blocked, retained only for a limited period and then discarded.
- Account data - kept while your account is open and deleted when you close it.
- API usage counters - monthly totals, kept only as long as needed for quota enforcement and billing of the periods concerned.
- Invoices and payment records - retained for as long as tax and accounting law requires us to keep them, which is typically several years. This is a legal obligation and it means that closing your account does not erase past invoices. They contain your billing details and the amounts charged, and nothing about the files you converted.
9. Children's privacy
The Service is not directed at children under the age of 13. We do not knowingly collect any personal information from children. If you believe a child has provided us with personal data, please contact us and we will promptly delete it.
10. International users
The Service may be accessed from anywhere in the world. Because your files are processed in memory and never stored, the cross-border transfer concerns that usually surround a file-conversion service do not arise: there is no repository of user content in any country. The temporary, in-memory processing of files occurs on servers protected by Cloudflare's global network.
If you hold a paid account, the limited account and billing data described in Section 3 is stored and processed by us and by the providers listed in Section 6, which may be located outside your country, including in the United States. Where that data originates in the EEA or the UK, such transfers are made under the safeguards those laws require, such as the European Commission's standard contractual clauses.
11. Your rights
Depending on your jurisdiction (including under the GDPR, the UK GDPR, the CCPA, and similar laws), you may have the right to access, correct, delete, port, or restrict the processing of your personal data, to object to processing, and to complain to your data protection authority.
For ordinary use of the conversion tools your files are never stored, and the only personal data we hold about you is the short-lived server access log described in Section 7. That log is keyed to an IP address and nothing else, so in most cases we cannot connect it to a person unless you tell us the address and roughly when you visited. If you do, we can confirm what it holds and erase it. In every case it erases itself within 15 days.
If you hold a paid account, those rights apply to your account and billing data. Write to [email protected] and we will respond within the period the applicable law allows. The one limit is that we cannot delete invoices we are legally required to keep, as explained in Section 8. We never sell personal data, and we do not share it for cross-context behavioural advertising.
12. Changes to this policy
We may update this Privacy Policy from time to time. Changes will be reflected in the "Last updated" date at the top of this page. We encourage you to review this page periodically. Continued use of the Service after changes constitutes acceptance of the updated policy.
13. Contact
If you have questions, concerns, or requests related to this Privacy Policy, you can reach us at [email protected].