Legal

Security & Privacy Center

How your files are processed

Fourteen tools; twelve run entirely in your browser and never touch a server. Two — Office to PDF and PDF to Office — upload your file for conversion, because that's the only way to run a real document engine. See How it works for the exact processing model, technology and limitations of each of the three product families.

Transport

Every upload to this site travels over HTTPS (TLS). For the two tools that upload a file, that connection is the only path your file takes to reach the conversion server.

Where files are stored, and for how long

The source file you upload is deleted immediately once conversion finishes. The converted result is deleted after 15 minutes, or as soon as you download it — whichever happens first. Nothing is kept beyond that window, and nothing is backed up.

Server location

The public site, the admin panel and the browser-based tools run on Cloudflare's global network (Workers, D1 and KV). The two upload tools' conversion server is separate infrastructure — not Cloudflare Workers — currently hosted in Turkey.

What we log

We don't keep a permanent record of the files you process or their names. During conversion, the job briefly exists in a processing queue on the conversion server; if a conversion fails, our error log records the internal job ID and the error message, not the file's content or name. Standard web server connection logs (IP address, timestamp, requested URL) are retained by Cloudflare for a limited period, same as any website.

Rate limiting

Not currently applied to the file-processing tools — a maximum file size is enforced instead. We're aware this is a gap for a production security posture and it's on our roadmap.

Malicious file scanning

Not currently performed. Uploaded files are handed directly to the document conversion engine; there's no separate antivirus or malware scan step today.

Subprocessors

Cloudflare (hosting, CDN and storage for the public site and admin panel) and the hosting provider for the file-conversion server described above. We don't use any other third-party processor for the tools on this site.

Reporting a security issue

Found a vulnerability or a way this policy doesn't match what actually happens? Email security@byterivet.com — we'll acknowledge it and follow up. A machine-readable version of this contact is also published at /.well-known/security.txt per RFC 9116.

Last updated: 2026-09-03