Cookies for analytics and advertising
We use cookies for analytics and advertising, both sent to Google. Refusing changes nothing you can see.Read the privacy page
Last updated 2026-08-02
Most conversions never send your file anywhere. Images, audio, video, data files, subtitles, fonts and 3D models are converted inside your browser, by code your browser downloaded. For those, the file is never sent to us, never stored by us and never seen by us. You do not have to take our word for it: open your browser's developer tools, watch the network tab, and convert something. You will see the page itself, the analytics and advertising requests described below — and no request carrying your file.
Document and archive conversions are the exception and they do upload the file. Which is which is written on the button before you press it, and described in full further down.
Reading the text in a picture also happens in your browser. The recogniser and its language model are several megabytes, and they are downloaded from this site — not from a content delivery network, which is the usual arrangement and would have told a third party your IP address and which page you were on. Once downloaded, the language model is kept in your browser's storage so a second document does not fetch it again. That copy sits on your device, is never sent anywhere, and disappears when you clear your browsing data.
The controller for the processing described here, in the sense of Article 4(7) GDPR, is:
Valentin Grube
Marrensmoor 2
24999 Wees
Deutschland
You can reach us at info@quinvert.com or through the contact page. The full provider details are on the imprint.
There is no data protection officer, and none is required. Article 37 GDPR and section 38 BDSG make one mandatory where a controller employs at least twenty people on automated processing, where the core activity is large-scale regular monitoring, or where special categories are processed on a large scale. This is a one-person business whose core activity is converting files on the visitor's own device. Saying so is more useful than silence, because the absence of an officer is otherwise indistinguishable from having forgotten to name one.
The supervisory authority responsible for us is the Unabhängiges Landeszentrum für Datenschutz Schleswig-Holstein, Holstenstraße 98, 24103 Kiel. You may complain to them, and you may equally complain to the authority where you live or work — Article 77 GDPR gives you the choice and does not ask you to come to ours.
There is no account system, so there is nothing you have told us. What we collect is measurement and, where you allow it, advertising data — the advertising is described in its own section below. For measurement, we use Google Analytics, if you agree to it, to count page views and see which conversions people look for. It records the page you are on, where you are, down to the approximate city, and a fair amount about the device: type, model and make, operating system and browser. Google derives the location from your IP address, which Google states it does not log or store for people in the EU, Switzerland and the UK — the location is derived on EU-based servers and the address discarded immediately afterwards; nothing here places you at a street or a building, and we could not obtain that even if we wanted it. We keep this at the level Google offers rather than the coarser one, because with four languages the question of which regions actually use the site is one we have to answer. The legal basis is your consent, given through the banner and withdrawable at any time — under Article 6(1)(a) GDPR for the processing, and under section 25(1) TDDDG for storing anything on your device at all; see the cookie section below for exactly what is and is not stored before you answer.
It also records what you did with the tool, and this section says exactly what that means, because "analytics" is a word that can cover almost anything. When you convert, compress or clean a file, and only if you have agreed to measurement, we record: the format that went in and the format that came out, which operation it was, whether it ran in your browser or on our server, a size band such as “10–50 MB”, roughly how long it took, and whether it worked. When something fails we record a category — protected, damaged, unsupported — and not the error message.
What is never recorded is just as specific. Not the file. Not its name. Not its exact size, only the band. Not the error text, because our own messages quote your file name back at you, and a name like “Kündigung_Müller.pdf” says more than the whole rest of this list put together. The file itself never leaves your device for a browser conversion at all — that is unchanged, and it is the reason the site exists.
Why we collect it: to find out which conversions are actually used rather than merely searched for, and which ones are quietly failing. A converter whose owners cannot see that a format has been broken for three months is a worse converter. If you would rather not contribute to that, decline measurement in the banner — every conversion on this site works identically either way.
Google acts as our processor for this and also uses the data for its own purposes, which is why it is named here rather than described vaguely as "our analytics". You can opt out for every site at once with Google'sbrowser add-on, or by using your browser's tracking protection, which blocks it. Blocking it does not affect any conversion on this site.
The site is hosted on Cloudflare Pages. Like any web host, Cloudflare processes technical data in order to deliver the page to you — your IP address, the time of the request, which page you asked for and what browser you use. This is necessary for the site to work at all and to protect it from attack, and it is the basis on which we rely: our legitimate interest in operating and securing the service. We build no profiles from it.
Nothing is stored on your device until you say yes — and nothing is requested from Google either. Every category of consent — analytics, advertising storage, advertising personalisation and ad user data — is set to denied before any tag could run. But the stronger point is the one underneath: on a first visit the Google tag is not downloaded at all. It is fetched at the moment you accept, and never if you decline.
This is worth spelling out because the common arrangement is the other one. Google's consent mode has an "advanced" setting in which the tag loads for everybody and sends stripped-down, cookieless pings while consent is denied. That sets no cookie, so it satisfies section 25 TDDDG — but the ping still carries your IP address, your browser's description of itself and the address of the page you are reading to a recipient in the United States, and there is no legal basis on this site for doing that to somebody who has not agreed. Legitimate interest does not carry it: the party that benefits from an unconsented ping is the analytics provider, not you and not us. So we use the basic setting and lose the modelled statistics that the advanced one would have given us. That is a reporting feature, and it is not worth a transfer we could not justify.
You can check both halves. Open your developer tools before answering the banner: the network tab shows no request to googletagmanager.com, and the cookie list shows no_ga.
Accepting sets two cookies, _ga and _ga_GNJ92YFFZJ, which let Google tell a returning visit from a new one. They last up to two years. Rejecting sets none, and we delete any that an earlier acceptance left behind.
You can change your mind at any time with the link, which is in the footer of every page. Withdrawing takes exactly one click, the same as giving it did.
Which banner you saw depends on where you are. In the European Economic Area, the United Kingdom and Switzerland the question is asked by Google's certified consent platform, because advertising there may only be served through one. Everywhere else it is asked by our own, which is the one described above. Only ever one of them appears, and the link in the footer reaches whichever it was — two banners would mean two answers that could disagree, with no way to say which counted.
Where Google's platform asks, your answer to "store or access information on this device" is also taken as your answer for analytics. That is the standard mechanism and it is why one dialog settles both; if you would rather it did not, refusing it stops analytics as surely as refusing ours does.
While consent is denied, Google's tag still sends a request that says a page was viewed, without cookies and without advertising identifiers — this is what Google calls consent mode, and it is how the visit is counted without being tied to you. That request carries your IP address, as any request to any server does. If you would rather it were not sent at all, browser tracking protection blocks it, and blocking it does not affect a single conversion on this site.
Consenting to advertising sets further cookies, belonging to Google and its advertising partners, which is what an advertising identifier is stored in. Refusing sets none of those either. Nothing else on this site stores anything: there is no account and no preference to remember, and the record of your consent choice is kept in your browser's local storage rather than in a cookie, so it never travels to any server.
An earlier version of this page said there were no cookies at all and that a banner would therefore be theatre. That was true when it was written and it is not true now, which is why it is corrected here rather than quietly removed.
Advertising is how this site is paid for. Converting a file costs you nothing, there is no account and no premium tier, and the money has to come from somewhere; it comes from ads shown beside the converter. Ads are supplied by Google AdSense and the advertising partners Google works with.
Where an ad appears, what happens next depends entirely on your answer to the consent dialog:
We never give an advertiser your files, and we could not: the ads run on the page, and most conversions never leave your browser at all. We are not paid per conversion and no advertiser is told what you converted.
The measurement above can feed advertising as well. Analytics is configured so that what it records may be used to build advertising audiences — people who looked at a particular conversion, say — and shared with a Google Ads account if we link one. None is linked today, so nothing is exported and the setting currently does nothing. It is left on because switching it on later would not reach back and cover the visits it missed, and because we would rather describe a capability here in advance than quietly acquire one later. It rides on the same answer as everything else on this page: refuse advertising personalisation and your visit is not used this way.
We do not use the feature that lets vendors scan your device's characteristics to identify you — fingerprinting, in plainer words. It is offered to us and it is switched off, because a site whose argument is that your files stay on your device should not be probing that device to recognise you.
Some formats cannot be converted inside a browser — documents, spreadsheets, presentations, archives and fonts among them — and those run on our own server. The file is uploaded over an encrypted connection, converted, and the working directory is deleted as soon as the result has been read, whether the conversion succeeded or failed. We keep no lasting copies of uploaded files and we do not evaluate their contents. Outbound internet access is disabled for the execution environment by the platform, so as far as we can determine it has no way to pass your file onward.
Every conversion says which of the two it is, on the button, before you press it.
The legal basis is Article 6(1)(b) GDPR — processing necessary to deliver the thing you asked for. You upload a file in order to receive it back in another format; without the upload there is no service to perform. We do not ask for consent for this, because consent you cannot refuse without losing the feature is not freely given, and dressing a necessity up as a choice would be the weaker position rather than the stronger one.
Who touches the file. The server runs on Cloudflare's infrastructure, which acts as our processor under Article 28 GDPR and under a data processing agreement with the European Commission's standard contractual clauses attached. Nobody else receives it. It is not stored in any database, not written to any bucket, and not used to train anything.
How long it exists. For the duration of the conversion. The working directory is a RAM-backed temporary filesystem, and it is removed in a `finally` — the branch that runs whether the conversion succeeded, failed or threw. Nothing survives the request. There is no backup of it, because there is nothing to back up by the time a backup could run.
One caution we would rather give than skip. This route exists for documents, spreadsheets, presentations, archives and fonts, and people convert real documents — contracts, payslips, medical letters. We do not look at them and we delete them immediately, but a file that leaves your device has left your device, and that is a different risk from one that never did. If you are handling material you are not free to disclose — patient records, privileged correspondence, anything under a duty of confidentiality — the honest advice is to use desktop software for it. The conversions that run in your browser carry no such caveat, and the button tells you which is which before you press it.
The site is delivered over Cloudflare, Inc.’s infrastructure. TLS is terminated there, routing is decided there, and the defence against denial-of-service attacks and the security filtering run there — so Cloudflare handles more than the address alone. Serving a page means their servers receive what any web request carries: the IP address it came from, the time, the page requested, the referring page if there was one, and the browser's own description of itself. This is not something we switched on; it is what delivering a page over the internet consists of.
The legal basis is Article 6(1)(f) GDPR, our legitimate interest in operating the site at all and in defending it against attack — an interest Recital 49 names explicitly for network and information security. We do not build profiles from these records, do not combine them with anything else, and do not use them for analytics; the measurement described above is a separate thing that happens only with your consent. Cloudflare acts as our processor, and their security logs are retained on their own short schedule rather than ours.
Server conversions are capped per visitor per day, because the machine that runs them costs money by the minute and an unmetered endpoint is an invitation. Enforcing a per-visitor cap requires telling visitors apart, and there are no accounts here, so the only handle available is the connecting IP address.
Our application does not store it. Cloudflare sees it, as the operator of the infrastructure — the hosting section below covers that. The address is put through SHA-256 together with a secret salt and truncated, and what is kept is that fragment together with a count and a day number. Our store holds no addresses, and the fragment is useless for anything except recognising the same visitor again on the same day. The record expires automatically about a day after the day it covers.
We are deliberate about not overclaiming here: a hashed address is pseudonymous, not anonymous, and it remains personal data under the GDPR. The legal basis is Article 6(1)(f) — our legitimate interest in preventing abuse and in keeping the service available to everybody else. You have the right to object to this under Article 21, and the section on your rights says how.
This is the one page on the site that fetches something while you use it, so it is worth being exact about what moves. The page downloads a table of exchange rates from our own server. It sends nothing: not the amount you type, not the currencies you pick, not any part of what you are calculating. The arithmetic happens in your browser after the table arrives, the same way the unit calculators work.
The rates originate with the European Central Bank, but your browser never contacts them — we fetch their daily file on our side and serve a copy, so the ECB has no way of knowing you visited. The request your browser makes carries what any request carries: an address, a browser version, a time. It carries nothing about the calculation.
We do not sell your data. Two companies process it on our behalf: Cloudflare, which hosts the site, runs the conversion server and now also carries our mail, and Google, which provides both the analytics and the advertising described above. Google is in the United States, so that data leaves the EU. Google LLC is certified under the EU–US Data Privacy Framework, which the European Commission has found to provide an adequate level of protection, and that adequacy decision is what the transfer rests on; the Commission's standard contractual clauses remain in place behind it. Google's advertising partners receive advertising data only, and only where you have consented — the full list is shown inside the consent dialog, where you can accept or refuse them individually. Your files go to none of them, for any purpose other than the conversion you asked for.
Several of the laws below require this to be listed by category rather than described in prose, so here it is once, and the regional sections refer back to it.
| Category | What it is | Why | Kept |
|---|---|---|---|
| Identifiers | A random analytics ID in a cookie, and your IP address | Counting visits, if you consented | 14 months at Google; cookies up to 2 years |
| Internet activity | Pages viewed, referring site, browser, and device type, model and make | Seeing which conversions people look for | 14 months at Google |
| Location | Country, region and city, derived from the IP address. Never a street or a building | Part of the same analytics record | 14 months at Google |
| Advertising data | Which ads were shown to you, whether you interacted with them, and — only with your consent — an advertising identifier | Paying for the site, and telling advertisers whether their ads worked | Google's advertising cookies last up to 2 years; none are set if you refuse |
| Your files | The file you convert | Performing the conversion you asked for | Never sent for browser conversions; deleted immediately for server ones |
We collect no name, no email address unless you write to us, no account, no payment details and nothing that any of these laws calls sensitive or special-category data.
We build no profile of you ourselves, and no decision affecting you is made automatically. What the advertising described below can do is a separate question, answered there rather than glossed over here.
There is an address rather than a contact form, and that is deliberate — a form on a site whose argument is that nothing you give it leaves your device would need a backend to put the messages in. The consequence is that writing to us is ordinary email, and ordinary email means we receive your address, your name if you sign with one, and whatever you chose to put in the message.
The basis depends on why you wrote. For a bug report, a question or a request for a format, it is Article 6(1)(f) — our legitimate interest in answering people who take the trouble to write. For something about a conversion you were running, Article 6(1)(b). And for a request under Articles 15 to 21, Article 6(1)(c): answering it is not a choice we make, it is a duty, and we cannot discharge it without processing what you sent.
How long it stays. Until the matter is dealt with, and then a reasonable while in case you come back to it. Two caveats we would rather state than leave you to discover: mail passes through our email provider, who processes it on our behalf; and correspondence that counts as a commercial letter falls under German retention law, which requires six years under section 257 HGB. That is a duty rather than a preference, and for those messages it overrides a deletion request — Article 17(3)(b) says so explicitly.
The route it takes. The address on this site is not a mailbox. Mail sent to it reaches Cloudflare's routing service, which forwards it to the mailbox we actually read. Cloudflare acts as our processor for that, under the same agreement that covers the hosting, and does not keep a copy — it is a relay rather than a place messages sit. From there our email provider holds it in the ordinary way, and the retention above applies to that copy.
Two things worth knowing before you write. The forwarding passes through the United States, on the same adequacy decision described under sharing. And email is email: between your provider and ours it is encrypted in transit but not end to end. For anything genuinely sensitive, that is a reason to say less in the first message and more once we have replied.
What we do not do with it: no newsletter, no marketing, no adding you to anything. There is nothing to be added to.
Article 13 GDPR wants the basis for each purpose, and scattering them through a page is a way of technically complying while making them hard to check. All of them, together:
Under the GDPR and the UK GDPR you have the right to access the personal data held about you, to have it corrected or erased, to restrict or object to its processing, and to receive it in a portable form. Where we rely on your consent — which is the case for analytics — you can withdraw it at any time, and withdrawing is neither harder nor slower than giving it was. The button in the footer reopens the choice on any page, and withdrawing does not make anything we already did unlawful — it stops it continuing.
The right to object, specifically. Where we rely on legitimate interest rather than consent — the hosting log and the daily limit above, and nothing else — Article 21 GDPR lets you object on grounds relating to your particular situation, and we then have to stop unless we can show compelling grounds that override yours. One address is enough to exercise it; you do not owe us a form or a reason in a particular shape.
Complaining. Article 77 GDPR gives you the right to lodge a complaint with a supervisory authority — the one where you live, the one where you work, or the one where you think the infringement happened. Ours is named in the first section. Nothing on this page asks you to come to us first, and nothing here waives that right.
Answering costs you nothing and takes a month. Article 12 GDPR gives us one month to respond, extensible by two more for a genuinely complex request, and it makes the answer free unless a request is manifestly unfounded or excessive. We may have to ask you something that identifies which visitor you were, and for a site with no accounts that is often impossible — which is a consequence of collecting almost nothing rather than an excuse for evading the request.
We do not sell your personal information, and we never have. If we later run advertising, showing personalised ads counts as "sharing" for cross-context behavioural advertising under the CPRA even though no money changes hands for your data — so the control is already here rather than added afterwards: .
We honour the Global Privacy Control signal. If your browser sends it, that is treated as an opt-out on arrival and you are not asked again — you will not see the consent banner at all, and analytics stays off unless you deliberately turn it on with the link above.
You have the right to know what we collect (the table above is that, published rather than requested), to delete it, to correct it, and to opt out of sharing. We will not treat you differently for exercising any of them — there is no premium tier that turns tracking off, because the tracking is off for everyone who says so. To make a request, write toinfo@quinvert.com.
Under the LGPD the legal basis for analytics is your consent (Art. 7, I) and for delivering and securing the site it is our legitimate interest (Art. 7, IX). You have the rights set out in Art. 18: confirmation that processing exists, access, correction, anonymisation or deletion of unnecessary data, portability, information about who we share with, and withdrawal of consent. Requests go to info@quinvert.com, which is also the contact for data protection matters generally. Analytics data is processed in the United States by Google under the transfer terms described above.
Under POPIA we process personal information lawfully and only for the purposes named above, and we hold no more than those purposes need. You may ask what we hold about you, ask for it to be corrected or deleted, and object to processing; the same address handles those requests. You may also complain to the Information Regulator. Analytics data is transferred outside South Africa to Google in the United States, which is permitted under section 72 because you consented to it and can withdraw that consent at any time.
In practice we hold no name, no email address and no files, because we ask for none and keep none. The analytics data is the one thing that exists, and it is not tied to anything that identifies you by name. If you want it gone, the fastest route is Google's opt-out linked above, which stops it being collected in the first place. You can also write toinfo@quinvert.com and we will look into it.
Quinvert is not directed at children under 13. We do not invite children to enter personal data, and we do not knowingly process personal data from children beyond what running the site requires. What still arises technically — the IP address in the host’s logs and, only after consent, the measurement — applies to every visit alike and is described above.
When what we do changes, this page changes with it, and the date at the top moves. We do not make changes quietly.