Privacy Policy
Last updated: July 13, 2026
1. Introduction
At Converter Flow (accessible from https://converterflow.io), one of our main priorities is the privacy of our visitors. This Privacy Policy document contains types of information that is collected and recorded by Converter Flow and how we use it.
2. Who We Are
Converter Flow is operated by Muhammad Usman, an independent software developer based in the Netherlands. For the purposes of the EU General Data Protection Regulation (GDPR), the operator is the data controller for personal data processed through this site.
For any privacy question or request, contact converterflow@gmail.com.
3. File Handling & Retention
- Temporary Storage: Files uploaded to our service are stored temporarily solely for the purpose of processing your request (conversion, merging, splitting, etc.).
- Automatic Deletion: Your original upload is permanently deleted from our servers within about 1 hour. Converted outputs are permanently deleted within 24 hours — or sooner if your account's retention setting is shorter. We do not keep backups of your user-generated content.
- No Other Use: Your files are never opened by a person, used to train machine-learning models, or shared with anyone. Conversion is fully automated.
- Access Control: Every conversion job generates a unique, cryptographically secure link. Your files are not accessible to the public or indexed by search engines.
4. Where Your Files Are Processed
All uploads are processed and stored on Oracle Cloud Infrastructure servers located in Amsterdam, Netherlands (EU). Your files do not leave the EU during processing.
- Encryption in transit: all traffic uses HTTPS (TLS).
- Encryption at rest: stored files are encrypted with AES-256.
- Network: web traffic passes through Cloudflare for bot and abuse protection.
5. Sensitive File Formats (DICOM, CAD, GIS)
Some formats we support can carry sensitive data: DICOM files may embed patient details (name, date of birth, patient ID) in their headers, and CAD or GIS files may contain confidential designs or locations. These files get the same treatment as everything else: automated processing only, deletion within 24 hours, no backups, no human access.
Converter Flow is not a HIPAA business associate and is not intended for regulated healthcare workflows. If you convert medical files, remove patient-identifying information before uploading.
6. Third-Party Service Providers
We employ third-party companies and individuals due to the following reasons:
- To facilitate our Service;
- To provide the Service on our behalf;
- To perform Service-related services;
Cloudflare Turnstile: We use Cloudflare Turnstile for spam protection and bot detection. Use of Turnstile is subject to Cloudflare's Privacy Policy.
Product updates and newsletters: If you subscribe to product updates, your email address is stored in our own database and is not shared with third-party marketing platforms. Every update email includes an unsubscribe link; unsubscribing stops all product-update emails immediately, and we keep a record of your opt-out so you are never re-added by accident.
7. Log Files
Converter Flow follows a standard procedure of using log files. These files log visitors when they visit websites. The information collected includes internet protocol (IP) addresses, browser type, Internet Service Provider (ISP), date and time stamp, and referring/exit pages. This data is used for analyzing trends, administering the site, and preventing abuse. Access logs are retained for up to 30 days and then deleted automatically.
8. Cookies and Sessions
Like any other website, Converter Flow uses 'cookies'.
- Essential Cookies: We use temporary session cookies (e.g., `guest_session_valid`) to allow you to perform batch conversions without solving a captcha for every single file.
- Preference Cookies: We store your Theme preference (Dark/Light mode) in local storage to improve your experience.
9. GDPR Data Protection Rights
We would like to make sure you are fully aware of all of your data protection rights. Every user is entitled to the following:
- The right to access – You have the right to request copies of your personal data.
- The right to rectification – You have the right to request that we correct any information you believe is inaccurate.
- The right to erasure – You have the right to request that we erase your personal data, under certain conditions.
- The right to restrict processing – You have the right to request that we restrict the processing of your personal data.
- The right to object to processing – You have the right to object to our processing of your personal data.
To exercise any of these rights, email converterflow@gmail.com. You also have the right to lodge a complaint with a supervisory authority; for the Netherlands this is the Autoriteit Persoonsgegevens.
10. Children's Information
Another part of our priority is adding protection for children while using the internet. We encourage parents and guardians to observe, participate in, and/or monitor and guide their online activity.Converter Flow does not knowingly collect any Personal Identifiable Information from children under the age of 13.
11. Security
All data in transit is protected with TLS (HTTPS), and stored files are encrypted at rest with AES-256. Files exist on our servers for no more than 24 hours, which limits exposure even in the unlikely event of a breach. However, no method of transmission over the Internet is 100% secure. While we strive to use acceptable means to protect your files, we cannot guarantee their absolute security.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Changes are posted on this page with an updated "Last updated" date. Material changes to how files or personal data are handled will be noted at the top of this page.
13. Consent
By using our website, you hereby consent to our Privacy Policy and agree to its Terms and Conditions.