Draft, pending legal review
This text has not been reviewed by a lawyer yet and may change before convt launches. Highlighted parts are placeholders.
Legal
Privacy policy
Effective [Effective date]
convt converts files on your own computer. The app has no analytics or tracking, and your files stay on your machine unless you choose to convert one in the cloud. This policy covers the convt app, the command line tool, convt.app and the convt API.
1.Who we are
convt is run by [Legal entity name], [Registered address] ("we"). We are the controller of the personal data described here. Write to privacy@convt.app with any question about it.
2.The desktop app and command line tool
Conversions run on your computer. The app and the convt command never upload a file, and contain no analytics, crash reporting or advertising code. The trial and your license key are stored on your computer and checked offline.
The app connects to the internet only in these cases:
- Update check. At most once a day, while update checks are on in Settings, the app downloads a list of available versions from convt.app. The request carries your IP address and app version, like any web request, and nothing about your files. You can turn it off.
- Pro renewal. If you have signed in to convt Pro from the app, it asks convt.app for your current Pro key at most once a day at launch, and when you click Refresh license. The request identifies your account and this computer through the sign-in token. Desktop license owners never sign in.
- Things you ask for. Signing in, installing the optional document pack, downloading an update and sending a file to the cloud each happen only when you click to do them.
3.Cloud conversions and the API
convt Pro can convert a file in the cloud, from the web converter or when you choose the cloud for a job in the app, which asks you each time. The API converts files your code sends. In these cases we receive the file and process it only to convert it for you.
- Input and output files are deleted 24 hours after the job is created. We do not look at, keep or train anything on them.
- Each conversion runs in an isolated sandbox with no network access.
- We keep a record of each job without the file: its formats, size, status, timing and any error, for usage limits, billing and support.
- API keys are stored only as a hash. You see a key once, when you create it.
4.What we collect on convt.app
We collect only what the account, licensing and billing features need:
- Account: your email address and name, and your profile picture if you sign in with GitHub or Google. We do not store passwords; you sign in with an emailed code or with GitHub or Google.
- Sessions and security: a session cookie, and the IP address and browser of each session, so you can see where you are signed in. We count sign-in attempts per email address and IP address to stop abuse.
- Computers: for each computer signed in to Pro, a name, its operating system and app version, so you can revoke it from the dashboard.
- Purchases: your orders, subscriptions, invoices and license keys. Card details go to our payment provider and never reach us.
The site sets only the cookies it needs to work: the sign-in session and, during a purchase, a short-lived cookie that lets this browser show your new license key. There are no analytics, advertising or third-party tracking cookies.
5.Who processes data for us
- Polar is the merchant of record: it sells convt to you, takes payment, handles sales tax and VAT and issues receipts. Polar receives your payment details and billing address under its own privacy policy.
- Resend delivers our emails: sign-in codes, license keys, receipts and account notices. We send no marketing email.
- Cloudflare hosts convt.app and stores cloud conversion files.
- Railway hosts our Postgres database and the conversion servers.
- GitHub and Google receive a sign-in request only if you choose to sign in with them.
We do not sell personal data or share it with advertisers.
6.How long we keep it
- Cloud conversion files: 24 hours.
- Account data: until you delete your account. Delete it from Settings on the dashboard; any subscription ends first.
- Orders, invoices and license records: kept after you delete your account, as tax and accounting law requires. They keep the email address used for the purchase.
- Sign-in codes expire after 15 minutes; sessions end when you sign out or they expire.
7.Your rights
Depending on where you live, you can ask for a copy of your data, correct it, delete it, object to or restrict how we use it, and take it elsewhere. Most of it is on your dashboard, and you can delete your account there. For anything else, write to privacy@convt.app. You can also complain to your local data protection authority.
We process account and purchase data to provide what you signed up for or bought, and security data for our legitimate interest in keeping the service safe. [Legal bases and international transfer mechanism to confirm]
8.Changes
If this policy changes in a way that matters, we will say so on this page and email account holders before it takes effect. Older versions stay available on request.