Trust Center
Trust starts with a precise processing boundary.
This page explains what stays in your browser, what is sent to a server, how retained files expire, which providers support the service, and how to report a security issue.
Last reviewed July 31, 2026
Processing
The tool tells you which side of the boundary it uses.
Browser-local tools
Standard image, document, PDF, data, and local media edits run in the active browser tab. For those workflows, the selected file is not uploaded for processing.
- Usable without creating an account where the tool says so.
- File contents stay on the device during the conversion.
- Results can be downloaded and may be kept in the on-device Bench.
Server-backed tools
OCR, AI features, retained workspace jobs, and other labeled server workflows upload the required input over TLS. The UI discloses that boundary before file selection or submission.
- Jobs and retained results are scoped to the signed-in workspace.
- Download access uses short-lived signed links.
- Files follow the retention rules described below.
Data lifecycle
Browser-local files are not sent to or retained on FileMorf servers. The browser may keep local results or saved signatures on that device. Those records are namespaced by the server-confirmed browser principal and remain unavailable while authentication is unresolved. Server-backed files follow the product workflow and plan rules described here and in the privacy policy.
- On-device Bench
- Local result copies have a 7-day logical expiry in this browser’s IndexedDB. Metadata and bytes are separated by confirmed anonymous/account scope; account changes cannot read another scope. Expired bytes are purged when the Bench next initializes, and signing out, clearing the Bench, or clearing site data removes them sooner.
- Saved PDF signatures
- Saved signatures and PDF insertion settings use the same confirmed-principal separation. They stay unavailable while identity is unresolved and are cleared for the departing scope on sign-out or account change.
- Per-tab recipes
- In-progress recipe steps are isolated by the confirmed browser principal within the tab. Confirmed anonymous state stays browser-profile local and is never migrated into an account.
- Free workspace files
- Workspace access and download URLs expire after 7 days. Expired objects are queued for automatic cleanup, with deletion retried after storage failures.
- Paid workspace files
- Workspace access and download URLs expire no later than 30 days, depending on the plan. Expired objects then enter the same retried cleanup path.
- AI intermediates
- Optional provider jobs use the input needed for that action; FileMorf's saved result follows workspace retention.
- Completed e-sign records
- Signed documents and audit trails are retained as legal records; this exception is detailed in the privacy policy.
Service providers
FileMorf uses providers for infrastructure and explicitly selected product features. Browser-local tools do not send file contents to these processing providers.
Provider handling details| Provider | Purpose | Relevant data |
|---|---|---|
| Cloudflare | CDN, traffic protection, and encrypted object storage | Requests and files explicitly sent to server-backed workflows |
| Hetzner | Application and worker hosting with FileMorf-managed PostgreSQL and Redis | Server-job inputs and results, plus account, job, entitlement, cache, and operational records |
| Resend | Transactional service email | Recipient address and the message needed for resets, signing, and delivery |
| Stripe | Payments and subscription management | Billing and payment data submitted during checkout |
| Google and GitHub | Optional social sign-in | Profile fields returned when that sign-in method is chosen |
| fal.ai | Optional GPU-backed image and audio processing | The input needed for the AI action a user explicitly starts |
| Google Gemini | Optional document intelligence | The document submitted to that server-backed feature |
Product and release controls
Automated checks are part of the release process. They reduce risk; they are not a claim that defects or security issues are impossible.
Configuration tests require each shared server-processing route to map to a registered disclosure and fail closed when that disclosure is missing.
Ownership and authorization tests cover retained jobs, downloads, checkout state, and public API boundaries.
Cleanup checks cover expired workspace objects, unfinished jobs, and e-sign material.
Release candidates carry immutable source, backend-image, and frontend-artifact identities with rollback targets.
Published flagship measurements include source-linked evidence artifacts and provenance checks.
Dependency vulnerability scans and focused browser checks are release gates.
FileMorf does not claim an external security certification or independent audit on this page. If that changes, the scope and date will be published here.
Report a security issue
Email the affected URL or feature, reproduction steps, and the potential impact. Do not access another user's data, degrade the service, or publish sensitive details before the report can be evaluated. Use a redacted, minimal reproduction; do not email credentials, access tokens, personal data, or customer files.
support@filemorf.comNo public bug-bounty program or response-time SLA is offered.
Security contact recordPublic incident notices
No public incident notices are currently listed. That statement is not an uptime guarantee and does not imply that the service has never experienced interruption.
Material notices that require user action will be added here and communicated through the relevant account channel.