Legal

Privacy Policy

How FileMorf handles browser-first processing, secure cloud features, and the limited account data needed to run the service.

Last updated July 31, 2026Privacy-first serviceClear retention rulesReadable legal terms

Overview

FileMorf ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and safeguard your information when you use our file conversion service at filemorf.com (the "Service").

The short version: We process most files directly in your browser. We collect minimal data. We never sell your information.

1. Information We Collect

1.1 Files You Convert

Client-Side Processing: For most conversions (image format conversion, PDF merging/splitting, document conversion), your files are processed entirely in your browser. These files are never uploaded to our servers.

Server-Side Processing: Certain features (OCR text extraction, large file processing for Pro users) require server-side processing. In these cases:

  • Files are encrypted in transit using TLS
  • Files are stored in encrypted cloud storage for workspace retrieval
  • Workspace access to retained server objects expires after 7 days on free accounts and no later than 30 days on paid plans
  • Expired objects are queued for automatic cleanup; deletion is retried if storage removal fails
  • We do not access or analyze file contents except as needed for processing

1.1a Electronic Signatures (E-Sign)

When you use the e-sign feature to request or provide a signature, we collect and store, in addition to the document itself (encrypted at rest in cloud storage):

  • The signer's name, email address, and drawn or typed signature
  • The signer's IP address and timestamps for each signing event (viewed, signed, declined) — recorded in the document's audit trail and on the signing certificate page to support the audit trail
  • A SHA-256 fingerprint of the original document (tamper evidence)

1.1b Optional AI Audio Processing

Voice isolation, stem separation, and transcription are optional server features. They run only when you choose the AI action. FileMorf first renders the current audio edit in your browser, stores the job input in encrypted workspace storage, and gives fal.ai a time-limited download link so it can produce the requested result.

  • FileMorf disables storage of the fal.ai request input and output JSON for each submission
  • FileMorf configures fal.ai-hosted generated media as private to FileMorf's provider account and with a one-hour expiration preference
  • FileMorf downloads the generated media promptly; the resulting FileMorf copy follows the workspace retention described below
  • Local editing, preview, normalization, and export do not use this AI path

1.2 Account Information

If you create an account, we collect:

  • Email address
  • Name (optional)
  • Profile picture (if signing in with Google/GitHub)
  • Provider account identifier (if signing in with Google/GitHub)
  • Password hash (for email/password accounts)

1.3 Usage Data

We use a first-party, privacy-limited analytics system to understand service reliability and improve conversion flows. We automatically collect:

  • Conversion operation types and counts (not file contents)
  • Feature usage patterns
  • Generic error categories and Core Web Vitals performance metrics
  • Page paths without query values, broad device/network categories, build version, allowlisted campaign tags, and the referring site's origin only
  • A random per-tab session identifier used to connect steps in a conversion flow; it is not tied to file contents
  • IP address processed for rate limiting and security, but not stored in raw form in analytics

Analytics never includes file names, file contents, user-entered document text, full referring URLs, email addresses, URL query values, exception messages, or stack traces. Errors are stored only as an allowlisted generic category and an opaque fingerprint derived from non-content metadata.

1.3a Feedback and Support

If you submit the site feedback form, we store the category, message, the page pathname where you opened the form, and any reply email you choose to provide. When you are signed in, the submission is linked to your account so it can be removed with that account. Feedback content is available only through the authenticated administrator view; operational notifications contain only the submission ID and category.

1.4 Cookies and On-Device Storage

We use essential browser cookies for:

  • Session authentication
  • OAuth sign-in state
  • CSRF safeguards

FileMorf also stores limited product data on your device, including:

  • Theme preferences are stored in local storage until you change them or clear site data
  • Local Bench result copies use IndexedDB and have a 7-day logical expiry; expired bytes are purged when the Bench next initializes, and clearing the Bench or site data removes them sooner. Bench records and bytes are separated by the server-confirmed browser principal and stay unavailable while sign-in state is unresolved
  • PDF Editor signatures you choose to save remain in local storage until deleted in the editor, cleared at the relevant account boundary, or removed with site data. They use the same confirmed-principal separation
  • Per-tab session state can include the random analytics/acquisition record described above and in-progress recipe steps; recipe state is separated by the confirmed browser principal within that tab and can contain user-entered action settings, but not file contents
  • Local authentication and interface state can include an authentication hint, a non-authoritative principal marker used to trigger cross-tab revalidation, a short-lived OAuth return path, and preferences or dismissed notices. The server session—not the marker—determines which local namespace becomes available
  • If you use the installed PWA's operating-system Share Target, the service worker temporarily stages the shared file bytes, content type, size, and encoded file name in browser Cache Storage. The receiving page deletes each staged entry after reading it, and the next share clears leftovers first. If the handoff is interrupted, a staged file can remain until that next share or until you clear site data.

Confirmed anonymous browsing uses a browser-profile-local namespace that is never migrated into an account. Switching accounts, signing out, or deleting an account suspends access immediately and clears the departing Bench, saved-signature, and recipe namespace. Legacy browser records that predate this separation are discarded because their owner cannot be established.

We do not use tracking cookies or third-party analytics that follow you across the web.

2. How We Use Your Information

We use collected information to:

  • Provide and maintain the Service
  • Process your file conversions
  • Authenticate your account and manage subscriptions
  • Enforce usage limits (free tier: 25 conversions/day)
  • Prevent abuse, fraud, and security threats
  • Improve service performance and reliability
  • Send essential service communications (password resets, billing notices)

We do not:

  • Sell your personal information to third parties
  • Use your files to train AI models
  • Share your data with advertisers
  • Send marketing emails without consent

3. Data Retention

  • Files: Server-processed files are retained for 7days on free accounts and no later than 30 days on paid plans so they can be re-downloaded from the workspace. Access and download URLs expire at that boundary. Expired objects are queued for automatic cleanup, with deletion retried if storage removal fails. Client-side processed files never leave your device.
  • AI audio intermediates: FileMorf disables fal.ai request payload storage and configures fal.ai-hosted generated media as private to FileMorf's provider account with a one-hour expiration preference. The result copy saved by FileMorf follows the workspace retention above.
  • Account data: Retained while your account is active. Deleted within 30 days of account deletion request.
  • Operational records: Event-level analytics categories, random per-tab identifiers, Core Web Vitals, generic error categories, content-free webhook delivery metadata, and content-free operational alert metadata are retained for no more than 12 months. These records do not contain document content, file names, full URLs, query values, raw IP addresses, exception messages, or stack traces.
  • Feedback: Feedback messages, category, optional reply email, and page pathname are retained for no more than 12 months. Signed-in feedback is deleted sooner if you delete your account.
  • Billing records: Retained as required by law (typically 7 years for tax purposes).
  • Signed documents (e-sign): Completed signature requests — the signed document, its audit trail, and the signer details listed in section 1.1a — are retained even after account deletion, because both the sender and the signer may need the signed record as legal evidence. Unsigned and incomplete signature requests are deleted with your account.

4. Data Sharing

We share data only with:

  • Payment processors: Stripe processes payments. See Stripe's Privacy Policy.
  • Cloud infrastructure: Cloudflare provides the CDN and R2 object storage. Hetzner hosts the application, workers, and FileMorf-managed PostgreSQL and Redis services.
  • Transactional email: Resend receives the destination email address and message content required for password resets, signing requests, signed-document delivery, and other essential service messages.
  • Authentication providers: Google and GitHub if you use social login. We receive the email, name, profile picture, and provider account identifier returned by the provider.
  • AI processing partners: Some optional features send your file to a specialized AI provider for processing, only when you use that feature: the AI Enhance upscaling tier sends your image to fal.ai for GPU inference; optional audio voice isolation, stem separation, and transcription also use fal.ai; and Document AI features send your document to Google (Gemini). Files are transmitted over TLS. FileMorf does not use your files to train AI models. Provider handling is governed by the linked provider policy. Browser-only editing and export do not use these AI providers.
  • Destinations you configure: If you enable a webhook, FileMorf sends job events to the HTTPS endpoint you provide. The payload can include the job ID and type, status, file name and size, result or error data, and—when produced by the workflow—time-limited download URLs or extracted OCR text. FileMorf does not send webhook events unless you configure that destination.
  • Legal requirements: We may disclose information if required by law, court order, or to protect our rights and safety.

5. Security

FileMorf uses layered technical and release controls:

  • TLS encryption for network transport
  • Encrypted object storage for retained file objects
  • Argon2id password hashing
  • Rate limiting and DDoS protection
  • Automated ownership, authorization, cleanup, dependency, provenance, and release checks
  • Minimal data collection principle

6. Your Rights

You have the right to:

  • Access: Request a copy of your personal data
  • Correction: Update or correct inaccurate data
  • Deletion: Delete your account and associated data. Exception: completed e-sign documents and their audit trails are retained as legal records (see section 3)
  • Portability: Export your data in a standard format
  • Objection: Object to certain data processing

To exercise these rights, contact us at privacy@filemorf.com.

7. International Transfers

Information may be transferred to and processed where the providers listed in section 4 operate. Those providers may use infrastructure outside your country or region.

8. Children's Privacy

The Service is not intended for children under 13. We do not knowingly collect personal information from children under 13. If you believe we have collected such information, please contact us immediately.

9. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by posting a notice on the Service or sending an email. Continued use after changes constitutes acceptance of the updated policy.

10. Contact Us

For privacy-related questions or concerns: