Trust Center

Trust starts with a precise processing boundary.

This page explains what stays in your browser, what is sent to a server, how retained files expire, which providers support the service, and how to report a security issue.

Last reviewed July 31, 2026

Processing

The tool tells you which side of the boundary it uses.

Browser-local tools

Standard image, document, PDF, data, and local media edits run in the active browser tab. For those workflows, the selected file is not uploaded for processing.

  • Usable without creating an account where the tool says so.
  • File contents stay on the device during the conversion.
  • Results can be downloaded and may be kept in the on-device Bench.
See the local-processing breakdown

Server-backed tools

OCR, AI features, retained workspace jobs, and other labeled server workflows upload the required input over TLS. The UI discloses that boundary before file selection or submission.

  • Jobs and retained results are scoped to the signed-in workspace.
  • Download access uses short-lived signed links.
  • Files follow the retention rules described below.
Read the complete privacy policy

Data lifecycle

Browser-local files are not sent to or retained on FileMorf servers. The browser may keep local results or saved signatures on that device. Those records are namespaced by the server-confirmed browser principal and remain unavailable while authentication is unresolved. Server-backed files follow the product workflow and plan rules described here and in the privacy policy.

On-device Bench
Local result copies have a 7-day logical expiry in this browser’s IndexedDB. Metadata and bytes are separated by confirmed anonymous/account scope; account changes cannot read another scope. Expired bytes are purged when the Bench next initializes, and signing out, clearing the Bench, or clearing site data removes them sooner.
Saved PDF signatures
Saved signatures and PDF insertion settings use the same confirmed-principal separation. They stay unavailable while identity is unresolved and are cleared for the departing scope on sign-out or account change.
Per-tab recipes
In-progress recipe steps are isolated by the confirmed browser principal within the tab. Confirmed anonymous state stays browser-profile local and is never migrated into an account.
Free workspace files
Workspace access and download URLs expire after 7 days. Expired objects are queued for automatic cleanup, with deletion retried after storage failures.
Paid workspace files
Workspace access and download URLs expire no later than 30 days, depending on the plan. Expired objects then enter the same retried cleanup path.
AI intermediates
Optional provider jobs use the input needed for that action; FileMorf's saved result follows workspace retention.
Completed e-sign records
Signed documents and audit trails are retained as legal records; this exception is detailed in the privacy policy.

Service providers

FileMorf uses providers for infrastructure and explicitly selected product features. Browser-local tools do not send file contents to these processing providers.

Provider handling details
FileMorf service providers, their purpose, and the data relevant to each service
ProviderPurposeRelevant data
CloudflareCDN, traffic protection, and encrypted object storageRequests and files explicitly sent to server-backed workflows
HetznerApplication and worker hosting with FileMorf-managed PostgreSQL and RedisServer-job inputs and results, plus account, job, entitlement, cache, and operational records
ResendTransactional service emailRecipient address and the message needed for resets, signing, and delivery
StripePayments and subscription managementBilling and payment data submitted during checkout
Google and GitHubOptional social sign-inProfile fields returned when that sign-in method is chosen
fal.aiOptional GPU-backed image and audio processingThe input needed for the AI action a user explicitly starts
Google GeminiOptional document intelligenceThe document submitted to that server-backed feature

Product and release controls

Automated checks are part of the release process. They reduce risk; they are not a claim that defects or security issues are impossible.

Configuration tests require each shared server-processing route to map to a registered disclosure and fail closed when that disclosure is missing.

Ownership and authorization tests cover retained jobs, downloads, checkout state, and public API boundaries.

Cleanup checks cover expired workspace objects, unfinished jobs, and e-sign material.

Release candidates carry immutable source, backend-image, and frontend-artifact identities with rollback targets.

Published flagship measurements include source-linked evidence artifacts and provenance checks.

Dependency vulnerability scans and focused browser checks are release gates.

FileMorf does not claim an external security certification or independent audit on this page. If that changes, the scope and date will be published here.

Report a security issue

Email the affected URL or feature, reproduction steps, and the potential impact. Do not access another user's data, degrade the service, or publish sensitive details before the report can be evaluated. Use a redacted, minimal reproduction; do not email credentials, access tokens, personal data, or customer files.

support@filemorf.com

No public bug-bounty program or response-time SLA is offered.

Security contact record

Public incident notices

No public incident notices are currently listed. That statement is not an uptime guarantee and does not imply that the service has never experienced interruption.

Material notices that require user action will be added here and communicated through the relevant account channel.