Security

Security and Compliance

This page explains how EverythingConvert handles local browser tools, server-assisted AI tools, account data, payments, and security responsibilities.

Last updated: July 3, 2026

1. Security approach

EverythingConvert is designed around data minimization. Where practical, conversion work runs in the user's browser so files do not need to be uploaded to our servers. This reduces unnecessary file handling and limits the amount of information we need to store.

When account features, usage limits, payment features, or future advanced conversions require server-side systems, we aim to limit access, collect only necessary data, and use established providers for authentication, hosting, database, and payments.

2. Processing transparency

Standard browser-only tools: many PDF, image, media, QR, and developer utilities process the selected file locally in your browser. In these workflows, EverythingConvert does not intentionally receive or store the selected file.

Server-assisted and AI tools: features such as AI transcription, background removal, Smart OCR, PDF summaries, checkout, account usage limits, and conversion history may use server-side processing or third-party providers. Uploaded files for AI tools are used only to create the requested result, enforce usage or payment rules, troubleshoot abuse or failures, and meet legal or security obligations.

Each tool should make the processing model clearer over time so users can decide whether a local browser workflow or an AI/server-assisted workflow is appropriate for the file they are working with.

3. Browser-based conversion

Many tools currently use browser APIs and client-side libraries. In these workflows, the selected file is processed locally by your browser, and the output is generated on your device. Browser-based processing can improve privacy, but it still depends on your device security, browser security, and the libraries loaded by the page.

Some features may be limited by browser memory, file size, format complexity, fonts, embedded media, scanned documents, or unsupported file structures.

4. Authentication and account data

Authentication and user profile storage are handled through Supabase. Account-related data may include email address, user ID, nickname, role, plan level, login provider, and timestamps needed to operate the account system.

Access to account-related features should be protected with Supabase authentication, database permissions, and row-level security policies where appropriate. Administrative access should be limited to trusted operators only.

5. Payments and PCI scope

Payments, donations, and future subscriptions are expected to be handled by Stripe-hosted payment flows or Stripe-managed checkout components. This helps reduce our exposure to payment card data because full card numbers are handled by Stripe rather than stored directly by EverythingConvert.

PCI compliance is a shared responsibility. Stripe provides payment infrastructure and PCI-related tools, while EverythingConvert remains responsible for integrating payment flows securely, protecting account access, and avoiding unsafe handling of payment data.

6. Hosting and infrastructure

The site may be hosted through Vercel or similar hosting infrastructure. Hosting providers can provide HTTPS, deployment isolation, DDoS mitigation, logging, edge delivery, and security controls depending on the plan and configuration.

We are responsible for our own application code, secrets, access control, dependency choices, configuration, and any serverless functions or APIs we deploy.

7. File handling and retention

For browser-only conversions, files are not intentionally stored by EverythingConvert. For server-assisted or AI tools, uploaded files should be used only to perform the requested operation, then deleted or made inaccessible after a reasonable operational period unless retention is needed for security, troubleshooting, abuse prevention, payment disputes, or legal compliance.

Users should keep their own backups. We do not promise permanent storage, recovery, archival access, or guaranteed availability of converted outputs.

8. Data protection controls

Current and planned controls may include HTTPS, provider-managed authentication, limited database access, role-based administrative functions, local browser processing where possible, usage-limit checks, abuse monitoring, secure payment redirects, and dependency updates.

As the service matures, we plan to improve audit logging, incident response documentation, backup procedures, access reviews, security headers, vulnerability scanning, and clearer retention rules for any server-processed files.

9. Compliance posture

EverythingConvert is not currently claiming independent SOC 2, ISO 27001, HIPAA, PCI DSS merchant certification, or other formal compliance certification for the entire service. Some infrastructure providers we use may maintain their own certifications or compliance programs, but those provider certifications do not automatically certify EverythingConvert as a whole.

If you need to use the service for regulated data, healthcare data, government data, legal evidence, financial records, or confidential enterprise documents, contact us first so we can discuss whether the current service is appropriate for your requirements.

10. Responsible disclosure

If you believe you found a security issue, please contact us at contact@everythingconvert.com. Include a clear description, affected URL, steps to reproduce, potential impact, and any screenshots or logs that help us understand the issue.

Do not access, modify, delete, download, or disclose data that does not belong to you. Do not perform denial-of-service testing, automated scanning at high volume, social engineering, spam, or attacks against users or third-party providers.

11. User security responsibilities

Users should keep devices and browsers updated, use strong account passwords, protect email and Google accounts, avoid shared computers for sensitive work, verify converted output before relying on it, and avoid uploading highly sensitive documents unless they understand the risks.

12. Contact

Security questions, compliance requests, and vulnerability reports can be sent to contact@everythingconvert.com.