Privacy policy

Last updated 18 September 2026

Seven things worth knowing up front
  • Deleted within one hour, every time — files and results alike.
  • Encrypted in transit and at rest, the whole time it's with us.
  • Never used to train any model, ours or anyone else's.
  • No account needed to convert a file.
  • Processed in the EU, under GDPR.
  • Never opened or seen by a human being.
  • Every job runs in its own isolated container.

What we collect

The file you upload, for as long as it takes to convert it. Basic request metadata — timestamp, file size, format pair, and a coarse country code — so we can keep the service running and spot abuse.

If you create an account: an email address, and a hashed password if you did not sign in with a provider. If you subscribe: billing details, held by our payment processor, not by us.

What we do not collect

No analytics trackers, no advertising pixels, no third-party scripts reading your session. We do not read the contents of your files for any purpose beyond the conversion you asked for, and we do not build a profile of what you convert over time.

Cookies

One functional cookie, used only to remember whether you are signed in. It is not used for tracking or advertising, and nothing is shared with third parties because of it. Declining it just means signing in again next visit.

Your rights

Under GDPR, you can ask what data we hold about you, ask us to correct it, or ask us to delete your account and everything tied to it. Since files are already gone within the hour, there is rarely a file left to delete by the time you ask.

Email privacy@whatafile.com and we will respond within 30 days, usually much sooner.

Contact

Questions about this policy go to privacy@whatafile.com, or use the contact page.