What stays in your browser
Supported tools pass selected files or pasted text to browser APIs and Web Workers. Intermediate artifacts and outputs may be kept in origin-scoped IndexedDB or OPFS storage while the job runs and until you download or clear them.
PrivConvert does not require an account and does not provide an account-based cloud conversion history. Tool pages publish their accepted input, output, browser requirements, and practical limits.
What may use the network
- HTML, CSS, JavaScript, fonts, libraries, and tool model assets.
- Cloudflare hosting, delivery, security, and page-performance measurement requests.
- Plausible page views and configured product events with limited metadata such as tool slug, category, file counts, size buckets, MIME type, run status, duration, and output count.
The app's configured analytics events do not intentionally include selected file contents, filenames, raw pasted text, or generated output contents.
A dated browser observation, with its limits
On September 6, 2026, we selected a generated public PDF in the live Compress PDF tool. We ran Optimize images with metadata removal off and the keep-original option off, then inspected the completed output. The source contains a distinctive public marker to help identify its text.
Scroll the table sideways to see all columns.
| Observed in the page-target trace | Result |
|---|---|
| GET requests | 7: page route, application and initial worker scripts, manifest, and icon |
| POST requests | 9: 7 Plausible events and 2 Cloudflare measurement requests |
| POST bodies available for inspection | 8 of 9; one Cloudflare Ping body was unavailable |
| Public marker or source filename in available bodies | Not found in those 8 bodies |
| Downloaded output | 398,058-byte PDF, with the measured page text and form field retained |
The available analytics bodies contained operational information such as tool identifier, file count, aggregate size, MIME type, run status, duration, and output count. Page-view URLs also included a random job identifier. The available Cloudflare body contained navigation, browser, and timing metadata.
This is a limited first-party observation, not a complete upload audit. Worker-internal requests were not independently captured, one POST body was unavailable, and searching available text bodies cannot rule out every binary or encoded representation. This result does not prove behavior for every tool, extension, device, or future version.
Read the sanitized network record and coverage limits. Raw headers, cookies, request tokens, and job identifiers are not published. The PDF compression guide documents output sizes and text checks separately.
How to verify a representative tool
- Open your browser's Developer Tools and select Network.
- Enable Preserve log. Note whether you are testing a first load or a warmed cache; libraries can load only when a tool starts.
- Clear the request list, then select a non-sensitive test file such as the public PDF above.
- Run the tool and inspect request URLs, methods, initiators, and available payloads. Include the worker's requests when your browser exposes them.
- Look for your test marker, the input file, and output contents. Record unavailable bodies or worker requests as coverage gaps, not as proof of no transmission.
Some tools load a library or model when first used, so an entirely offline first run is not guaranteed. Browser support and cached assets also affect offline behavior.
Limits and cleanup
Browser memory, storage quotas, file formats, and device performance limit what a local tool can process. You can remove origin-scoped job data through your browser's site-data settings and delete downloaded outputs from your device.
Policy and questions
The full service disclosures are in the Privacy Policy. For questions, contact [email protected].
