Legal
Privacy Policy
What we collect, what we refuse to do with it, and how to get it back.
Last updated: 2026-08-28. This is a template. Replace with your own legal text or consult counsel before publishing.
What we collect
- Account data: your first and last name, email address, phone number, WhatsApp number, hashed password, and OAuth identifiers where you sign in with another provider. Name, email and both numbers are collected when you create an account. Your display name can be changed in your dashboard settings; to change or remove anything else, write to us at the address below and we will do it.
- Why we hold your phone numbers: to identify you when you contact support and to reach you about your account — a security issue, or a problem with work you have running. We do not send marketing messages to them, and we do not pass them to anyone else.
- Email verification: creating an account sends a short-lived code to your address to confirm it is yours. We keep only a one-way hash of that code, never the code itself.
- Usage data: tool slug, byte counts, success/failure, IP address, user agent.
- Visit counts, and only if you accept cookies. We record the page, the site that linked you, your country, and search terms typed into our own search box. We do not store your IP address or browser string for this: they are combined with a secret that changes every day and turned into a one-way hash, so two visits on the same day count as one person and visits on different days cannot be linked to each other. There is no analytics cookie and no third party — the counting is done by this site, on our own server.
- Files: only when a tool requires server-side processing. Deleted an hour after upload when you are not signed in, and 24 hours when you are — inputs and outputs alike. A deletion request is carried out without waiting for that clock.
- Billing data: handled by Paddle as Merchant of Record. We never see card numbers.
What we don't do
- We do not train AI models on your files.
- We do not sell or share your data with advertising networks.
- We do not use third-party processing APIs (OpenAI, Google, etc.) for your files.
Subprocessors
- Paddle (billing, MoR)
- Cloudflare (CDN + WAF)
- Hetzner Cloud (hosting, EU)
- AWS S3 (off-site backups, EU)
- Amazon SES (transactional email: verification codes, password resets, invites)
- Google Analytics and Microsoft Clarity — only where enabled, and only for visitors who accepted all cookies. Analytics counts visits and Clarity records anonymised interaction sessions to show us where pages are confusing. Neither loads before you answer the cookie notice, and choosing “Essential only” keeps both off for you.
- Google AdSense serves the ads, and it is the one third party whose script loads for every visitor. It has to: Google cannot review or serve a site whose ad code it never sees, and a crawler never answers a cookie notice. What your answer changes is what it is allowed to do. We send Google Consent Mode signals on every page: until you answer, and permanently if you choose “Essential only”, ad storage, advertising identifiers and ad personalisation are all set to denied — so you get non-personalised ads and no advertising profile is built or read. “Accept all” grants them. Either way, no ad is rendered until you have answered.
Google and its partners use cookies to serve ads based on your prior visits to this and other websites. You can turn personalised advertising off for your Google account at adssettings.google.com, and read how Google uses this data at policies.google.com/technologies/partner-sites. - Sentry (error monitoring; no file contents)
Your rights (GDPR)
You can export, correct, or delete your data at any time via the dashboard or by emailing [email protected]. We respond within 30 days. Deleting your account removes your name, email address and both phone numbers along with it.
Contact
Registered address not yet configured — set NEXT_PUBLIC_LEGAL_CONTACT before publishing.