What Popular Online File Tools Say They Do With Your Uploads
A dated, sourced snapshot of what widely used PDF and image tools state in their own published policies — quoted verbatim, with links.
By Cassi Lup · Last reviewed 31 July 2026
Every online file tool publishes something about what happens to the files you hand it, and almost none of them say the same thing. What follows is a record of what a set of widely used PDF and image tools state in their own privacy policies and terms about uploading, storing and deleting your files. Every passage was retrieved on 31 July 2026 and is quoted word for word, with a link to the page it came from.
How to read this page
This is a reading exercise, not an experiment. Nothing here was measured. We did not send files to anyone’s servers, watch what their infrastructure did with them, or audit a single company. We opened the document each company publishes, copied the sentences that describe file handling, and wrote down where and when we got them.
That distinction matters more than it sounds. A privacy policy is a statement of intent with legal weight behind it, which is not nothing. It is still a different kind of object from evidence. It tells you what a company has committed to in writing; it cannot tell you what a particular server did with a particular file on a particular afternoon.
The rows are in alphabetical order. There is no ranking, no score and no verdict, because ranking would require judging things this method cannot see — how the commitments are implemented, how they are enforced, and what happens when something goes wrong. Two services can publish nearly identical sentences and operate very differently, and this page has no way of knowing that.
One column you might expect is missing. We did not include whether a free tier requires an account, because answering that reliably means using each product and watching where it stops you — a behavioural test, not a documentary one, and the two do not belong in the same table. Where a company happens to address accounts in the document itself, that sentence appears in the quotes below.
What each document says, in summary
All source URLs in this table were retrieved on 31 July 2026. The retention column is quoted; the phrasing is theirs, including the parts that are vague.
| Tool | Does the document describe files going to their servers? | Stated retention, quoted | Source (retrieved 31 July 2026) |
|---|---|---|---|
| CloudConvert | Yes | “This will happen automatically at the latest after 24 hours.” | cloudconvert.com/privacy |
| Convertio | Yes | “output files are deleted after 24 hours automatically” | convertio.co/privacy |
| FileWash (this site) | No upload path exists in the site’s source | No stated period, because no server receives the file | This repository; see the section below |
| iLovePDF | Yes | “within TWO (2) HOURS of being processed on ILOVEPDF’s servers” | ilovepdf.com/help/privacy |
| PDF24 Tools | Yes | “usually deleted one hour after uploading or creating the results” | pdf24.org/en/privacy-policy |
| Sejda | Yes | “permanently deleted after upload or processing respectively” | sejda.com/privacy |
| Smallpdf | Yes | “within a reasonable period of time after the last time they were opened” without an account; “within one hour” with one | smallpdf.com/privacy |
| TinyPNG (Tinify) | Yes | “temporarily stored, optimized and deleted within 48 hours” | tinify.com/terms |
The passages in full
CloudConvert
From the CloudConvert privacy policy, retrieved 31 July 2026 from cloudconvert.com/privacy:
The service can be used both without and with optional registration. … In the course of providing the service, your selected files are transferred to and temporarily stored on CloudConvert’s servers.
Your files are deleted immediately and irreversible from our servers when using the delete button. This will happen automatically at the latest after 24 hours.
Convertio
From the section headed “User’s Files Handling and Keeping”, retrieved 31 July 2026 from convertio.co/privacy:
We do not read, look into or copy your files. You can delete your uploaded files yourself at any time. … We delete input files and all temporary files instantly after any file conversion. We delete output files instantly when the user clicks ‘X’ in the web panel, otherwise, output files are deleted after 24 hours automatically.
iLovePDF
From sections 3 and 6 of the privacy policy, retrieved 31 July 2026 from ilovepdf.com/help/privacy:
In relation to the content of the files, we confirm you that we will not access, analyze, review, index or carry out any other action on their content except as necessary to provide the ILOVEPDF services as indicated in the Terms and Conditions.
Also, please note that, except for iLoveSign services, to which the storage period of files contemplated in their respective Specific Terms of Service apply, ILOVEPDF will delete the files of your Content (as defined in the Specific Terms of Service) within TWO (2) HOURS of being processed on ILOVEPDF’s servers.
PDF24 Tools
From the section headed “Additional data protection provisions to PDF24 Online PDF Tools”, retrieved 31 July 2026 from pdf24.org/en/privacy-policy:
All files uploaded in this area for processing, which may contain personal data, are stored on a special server infrastructure for processing and subsequent download. … All files uploaded by the user and the results created are usually deleted one hour after uploading or creating the results. Longer storage may be required if uploading files, processing or producing results takes longer than one hour. During this hour we do not look at the files and do not evaluate them.
Sejda
From the privacy policy, retrieved 31 July 2026 from sejda.com/privacy:
All user-uploaded files as well as the processed output files will be permanently deleted after upload or processing respectively. We store the files for the sole purpose of giving you enough time to process and download them. No backups are made of these files. We don’t access your files without your explicit permission.
The same document addresses files you deliberately share with others separately:
When a public link is generated for a shared file, we make a copy of the file and store it for the lifetime of the shared link. Anyone who has the shared link can access the shared files. The access link and the shared files will be permanently deleted automatically, 7 days after being shared.
Smallpdf
From sections 1.10 and 6 of the Privacy Notice, which carries the line “Last updated: 29 July 2025”, retrieved 31 July 2026 from smallpdf.com/privacy:
If you choose to use our PDF services and upload or otherwise provide User Files for this purpose, we process the User Files and metadata (such as file size, file name, and file type) and may store User Files as set out in Section 6 below. … By default, the documents you process using our services are accessible to anyone with a unique sharable URL. This can be disabled by the User — please let us know if you need assistance with this.
If you do not have a User Account … or are not logged in when using our services … we will generally aim to delete User Files within a reasonable period of time after the last time they were opened. Please note that this retention period is extended every time you reopen the respective User File. … If you access our services via a User Account, we delete User Files within one hour unless you save them to your file storage.
TinyPNG (Tinify)
At the time of retrieval, tinypng.com/privacy redirected to tinify.com/privacy, which returned a 404, so we could not retrieve a separate privacy page; the file-handling text we found is in the Terms of Service, retrieved 31 July 2026 from tinify.com/terms:
You grant Tinify and its service providers the right to temporarily store and modify your content insofar as necessary to provide the Service to you. Submitted content will be stored for a maximum of 48 hours.
Images uploaded to the Service are temporarily stored, optimized and deleted within 48 hours. Requests to the Service can be logged in order to understand how the Service is used and to avoid misuse. A log entry contains information such as browser type, IP address, any API key, date, time, and fingerprint of the transferred file. Log entries are deleted within 31 days.
What retention language actually means
Read the quotes above next to each other and you will notice they are not variations on one sentence. They take several different shapes.
One shape is a fixed period. “Deleted within 48 hours” or “within TWO (2) HOURS” is a number someone can be held to. It also tells you something uncomfortable if you were hoping otherwise: for that window, the file exists on equipment you do not control, in a form that could in principle be read, copied or subpoenaed.
A second shape states a period and names an exception to it in the same breath. PDF24 writes “usually deleted one hour” and then sets out the exception — longer if uploading, processing or producing results takes longer than one hour. “Usually” is not “always”, and the sentence says as much itself.
A third shape names no clock at all. Sejda’s “permanently deleted after upload or processing respectively” ties deletion to an event rather than a duration. Smallpdf’s “within a reasonable period of time after the last time they were opened” names no duration either, and the next sentence says the period is extended each time you reopen the file. These are statements that cannot be converted into a number, and you should not silently convert them into one in your head.
There is a fourth pattern worth naming, because it is the one most likely to be misread: assurances about what the company does with your file rather than how long it keeps it. “We do not read, look into or copy your files” and “we will not access, analyze, review, index” are commitments about conduct. They are meaningful, and they are not retention statements. A file can be untouched and still be present.
Underneath all four sits the fact none of the wording changes: every one of these services receives your file. Deletion, however fast, happens after receipt. If your concern is that a document should never reach a third party’s hardware in the first place, no retention clause addresses it, because retention clauses start from the assumption that the transfer already happened.
FileWash, judged by the same criteria
It would be dishonest to compile this page and leave ourselves out of it, so here is the same exercise applied to this site, sourced from its code rather than from a policy page.
FileWash’s tools run in the browser tab. Compression, conversion, merging, splitting, rotation and metadata stripping are performed by libraries loaded into the page — pdf-lib, pdfjs-dist, browser-image-compression, jspdf, heic2any and others. The site’s source contains no upload endpoint and no code path that transmits a selected file anywhere. Because no server receives the file, there is no retention period to state: the honest cell in that column is not “zero hours” but “not applicable”. There is also no account system, so the account question does not arise.
Two limitations belong in the same paragraph. First, some tools fetch code or data from third-party CDNs while they work: the PDF tools that read page contents load the PDF.js worker from unpkg.com, and background removal downloads its model from staticimgly.com. Those requests carry what any web request carries, including your IP address. They do not carry your file, but they are not nothing, and a strict reading of “entirely offline” would exclude them. Second, the site loads Cloudflare Web Analytics on every page, and Google Analytics and advertising only after you accept the consent banner. That is ordinary website telemetry about visits, unrelated to file contents, but it exists.
And the obvious caveat: you are reading this on our own site, which puts our claim in exactly the same category as everyone else’s. It is a statement. Treat it the way you should treat the rows above.
What this page cannot tell you
Policies change, often without announcement. Everything here reflects 31 July 2026 and may already be out of date when you read it; the links go to the live documents so you can check rather than trust this snapshot.
We read one public page per company and nothing else. A public consumer policy is not necessarily the document that governs a paid, business or API account, and separately negotiated agreements are not published at all. Whether any of that applies to the tool you are about to use is not something this page checked.
We quoted the passages that describe file handling directly. Full policies are long, and other sections — sub-processors, international transfers, log data, legal disclosure — also bear on where your data ends up. If a document matters to you, read the whole thing.
Finally, and most importantly: none of this is evidence of behaviour. A published commitment is a promise about behaviour, and this page records promises.
If you want evidence instead of statements
There is one question a policy can never settle and your browser can answer in about a minute: did this page actually send my file anywhere? The Network tab records every request a page makes, including the size of what was uploaded, and no amount of marketing copy survives contact with it. A second check — loading the tool, going offline, and seeing whether it still works — settles the same question from the other direction.
We wrote up both methods, including what they can and cannot prove, in how to check whether an online file tool is actually uploading your files. Run it on the tools in this table if you like. Run it on ours too — that is the point of publishing the method.