OnlineConverter
Transparency, Security & User Privacy

Privacy Policy

Our commitment to data confidentiality, zero permanent file retention, and transparent in-browser and server conversion security.

100% Confidential Zero Permanent Storage GDPR & CCPA Aligned No Account Required

1. Overview & Core Privacy Principles

Welcome to OnlineConverter. We believe that privacy is a fundamental digital right. Our platform provides free, instant, and secure tools for document conversion, image manipulation, audio editing, video encoding, text analysis, and financial calculations.

We operate under a strict privacy-by-design architecture. Unlike traditional software platforms, we do not require user registration, email sign-ups, credit card credentials, or personal profiles to access any of our free tools.

Our Core Privacy Guarantees

  • We never sell, rent, monetize, or broker your personal data or document contents.
  • We never read, review, copy, or index the contents of your uploaded documents or text.
  • We never use your uploaded files or writing drafts for AI model training or machine learning datasets.
  • We purge temporary server-processed files immediately after conversion and download delivery.

2. Dual Processing Architecture (Client vs. Server)

To maximize both processing performance and user confidentiality, OnlineConverter implements two distinct processing pipelines depending on the nature of the utility:

Client-Side In-Browser Processing

Utilities including client-side PDF merging, image formatting, audio cutting, video muting/trimming, text statistics, and financial calculators execute 100% locally in your web browser using HTML5 Canvas, WebAssembly (Wasm), and Web Audio APIs.

Files never leave your device

Encrypted Server Conversion Pipeline

Complex document transformations (such as PDF to Word DOCX, PDF to Excel XLSX, OCR text extraction, and advanced video container transcoding) require specialized server engines. Files are transferred via encrypted HTTPS and processed in ephemeral, isolated sandboxes.

256-bit TLS Encrypted Transfer

3. Strict Zero-Retention & Automated Cleanup Protocol

For tools requiring server-assisted conversion, we enforce an automated, fail-safe file lifecycle policy:

  • Ephemeral Sandboxing: Each conversion request is assigned a unique cryptographic UUID directory. Files from different users never share directory storage or execution environments.
  • Immediate Task-Completion Purging: Files are used solely to execute the requested conversion. Once the converted output is downloaded or the session expires, the files are deleted.
  • Automated Filesystem Garbage Collection: Any orphaned temporary files or incomplete conversion fragments are automatically purged by recurring automated server cron jobs every few hours.
  • Zero Backup Storage: We do not create archival copies, tape backups, or secondary snapshots of uploaded or converted documents.

4. Information We Collect & Logging Practices

We adhere to strict data minimization principles and collect only standard technical telemetry necessary for security, rate limiting, and server health:

Standard Web Server Diagnostics

Like virtually all web services, our web servers record standard log lines including your IP address, browser user-agent, operating system, requested URL endpoint, timestamp, and HTTP response code. These logs are used exclusively for mitigating DDoS attacks, preventing automated bot abuse, and diagnosing software bugs.

Support & Feedback Communications

If you voluntarily contact us via email, we store your email address and message contents solely to assist you and resolve your inquiry. We never add support contacts to marketing distribution lists.

5. Cookies, Local Storage & User Preferences

We use standard browser storage technologies to maintain essential website functionality:

  • Local Browser Storage: We use browser localStorage to remember your UI preferences, such as light/dark mode selection and workspace layout settings. This data resides solely on your device.
  • Session Cookies: Temporary cryptographic session tokens are used to manage multi-step conversion workflows and protect against Cross-Site Request Forgery (CSRF) attacks.

You can configure your browser to block or alert you about cookies at any time. If you disable cookies, basic conversion features will remain fully functional.

6. Third-Party Services, Google AdSense & Analytics

To keep OnlineConverter 100% free for all users worldwide without requiring paid subscriptions, we display third-party advertisements and utilize web analytics:

  • Google AdSense & DoubleClick Cookies: Google, as a third-party vendor, uses cookies to serve relevant ads on our website based on a user's prior visits to our site or other websites on the internet. Google's use of advertising cookies enables it and its partners to serve ads based on your visit to our site and/or other sites on the Internet.
  • Personalized Ads Opt-Out: Users may opt out of personalized advertising by visiting Google Ads Settings or through the Digital Advertising Alliance at aboutads.info.
  • Web Performance Analytics: We may utilize privacy-friendly analytics tools to evaluate overall page visit trends, geographic performance, and browser compatibility to optimize website responsiveness.

7. User Data Protection Rights (GDPR, CCPA/CPRA)

We respect global data protection frameworks, including the European Union General Data Protection Regulation (GDPR), the UK GDPR, and the California Consumer Privacy Act (CCPA/CPRA):

GDPR / UK GDPR Rights

EU and UK residents have the right to access, rectify, port, or erase any personal information we hold, and the right to object to processing. Because we do not store user accounts or identifiable files, we hold no persistent profiles.

CCPA / CPRA Notice

California residents have the right to know what personal information is collected and to request its deletion. We do not sell or share personal information for commercial exchange or monetary consideration.

8. Children's Online Privacy Protection (COPPA)

OnlineConverter is designed for general audiences and does not knowingly collect, request, or solicit personal information from children under the age of 13 in compliance with the Children's Online Privacy Protection Act (COPPA). If you believe a child has provided personal information to us, please contact us immediately so we can remove any associated communication logs.

9. Infrastructure Security & 256-Bit TLS Encryption

We apply rigorous defense-in-depth technical safeguards to preserve server integrity and prevent unauthorized access:

  • End-to-End TLS Encryption: All data transmitted between your browser and our servers is secured using modern 256-bit TLS (HTTPS) encryption certificates.
  • Access Controls & Isolation: Conversion processes execute in unprivileged sandboxes with strictly limited filesystem visibility.
  • Continuous Security Hardening: We regularly update server operating systems, web server daemons, and conversion binaries to address emerging vulnerabilities.

10. Policy Revisions & Official Contact Information

We may update this Privacy Policy periodically to reflect technological improvements, new tool additions, or changing regulatory standards. Any changes will be posted on this page with an updated "Last Modified" timestamp.

If you have any questions, privacy concerns, or data requests regarding this Privacy Policy, please contact our data protection team:

OnlineConverter Support Team

Inquiries typically answered within 24–48 business hours.

support@onlineconverter.online

Privacy Summary

OnlineConverter is built around user trust. No files are retained, no accounts are required, and client-side processing keeps your documents private on your own device.

Effective Date: September 2026