Security

Security & Data Handling

This page explains how EverythingConvert handles local browser tools, server-assisted AI tools, account data, payments, and security responsibilities.

Last updated: July 22, 2026

1. Security approach

EverythingConvert is designed around data minimization. Where practical, conversion work runs in the user's browser so files do not need to be uploaded to our servers. This reduces unnecessary file handling and limits the amount of information we need to store.

When account features, usage limits, payments, or AI-assisted conversions require server-side systems, we limit the data used for the requested operation and rely on established providers for authentication, hosting, database, AI processing, and payments.

2. Processing transparency

Standard browser-only tools: many PDF, image, media, QR, and developer utilities process the selected file locally in your browser. In these workflows, EverythingConvert does not intentionally receive or store the selected file.

Server-assisted and AI tools: features such as AI transcription, background removal, Smart OCR, PDF summaries, checkout, account usage limits, and conversion history may use server-side processing or third-party providers. Uploaded files for AI tools are used only to create the requested result, enforce usage or payment rules, troubleshoot abuse or failures, and meet legal or security obligations.

Tool pages identify whether processing is browser-only or server-assisted so users can choose an appropriate workflow before selecting a sensitive file.

3. Browser-based conversion

Many tools currently use browser APIs and client-side libraries. In these workflows, the selected file is processed locally by your browser, and the output is generated on your device. Browser-based processing can improve privacy, but it still depends on your device security, browser security, and the libraries loaded by the page.

Some features may be limited by browser memory, file size, format complexity, fonts, embedded media, scanned documents, or unsupported file structures.

4. Authentication and account data

Authentication and user profile storage are handled through Supabase. Account-related data may include email address, user ID, nickname, role, plan level, login provider, and timestamps needed to operate the account system.

Account-related features use Supabase authentication, database permissions, and row-level security policies where appropriate. Administrative access is limited to authorized operators.

5. Payments and PCI scope

Subscriptions, AI credit-pack purchases, and donations use Stripe-hosted payment flows or Stripe-managed checkout components. AI tools do not offer separate per-result payments. Full card numbers are handled by Stripe rather than stored directly by EverythingConvert.

PCI compliance is a shared responsibility. Stripe provides payment infrastructure and PCI-related tools, while EverythingConvert remains responsible for integrating payment flows securely, protecting account access, and avoiding unsafe handling of payment data.

6. Hosting and infrastructure

The production site and serverless functions are hosted on Cloudflare infrastructure. The hosting provider supplies HTTPS, edge delivery, deployment isolation, and platform-level security controls according to its service configuration.

We are responsible for our own application code, secrets, access control, dependency choices, configuration, and any serverless functions or APIs we deploy.

7. File handling and retention

For browser-only conversions, selected files are not sent to or stored by EverythingConvert. For server-assisted or AI tools, uploaded files are used to perform the requested operation and are scheduled for deletion within 24 hours, unless longer retention is required for security, abuse prevention, payment disputes, or legal compliance.

Users should keep their own backups. We do not promise permanent storage, recovery, archival access, or guaranteed availability of converted outputs.

8. Data protection controls

Current controls include HTTPS, provider-managed authentication, scoped database access, row-level security where appropriate, role-based administrative functions, local browser processing where possible, usage-limit checks, abuse monitoring, and Stripe-hosted payment redirects.

We continue to improve audit logging, incident response procedures, backups, access reviews, security headers, dependency maintenance, and retention enforcement. This is an operational improvement program, not a claim of independent certification.

9. Compliance posture

EverythingConvert is not currently claiming independent SOC 2, ISO 27001, HIPAA, PCI DSS merchant certification, or other formal compliance certification for the entire service. Some infrastructure providers we use may maintain their own certifications or compliance programs, but those provider certifications do not automatically certify EverythingConvert as a whole.

If you need to use the service for regulated data, healthcare data, government data, legal evidence, financial records, or confidential enterprise documents, contact us first so we can discuss whether the current service is appropriate for your requirements.

10. Responsible disclosure

If you believe you found a security issue, please contact us at contact@everythingconvert.com. Include a clear description, affected URL, steps to reproduce, potential impact, and any screenshots or logs that help us understand the issue.

Do not access, modify, delete, download, or disclose data that does not belong to you. Do not perform denial-of-service testing, automated scanning at high volume, social engineering, spam, or attacks against users or third-party providers.

11. User security responsibilities

Users should keep devices and browsers updated, use strong account passwords, protect email and Google accounts, avoid shared computers for sensitive work, verify converted output before relying on it, and avoid uploading highly sensitive documents unless they understand the risks.

12. Contact

Security questions, compliance requests, and vulnerability reports can be sent to contact@everythingconvert.com.