privacy and processing
Choose where your document is processed.
The free browser workspace and paid API are intentionally separate. This page explains what stays local, what makes a network request, and what is stored when you choose server-side processing.
at a glance
Know which boundary you are choosing.
File stays in the tab.
Supported conversion can avoid a document upload. Results remain in browser memory.
Extract and Ask may request.
A bounded file or converted text can be sent for the selected run when the hosted path is available.
Hosted processing when you need it.
API sources, artifacts, accounts, and usage records are part of a separate server workflow you can choose when local processing is not enough.
Free browser tools
Convert reads supported files in the current browser tab. It does not upload, store, or use your document contents for training. Converted results remain in browser memory until you copy, download, remove, or close the tab. The free Extract and Ask playground may send a bounded file to the anonymous playground endpoint when the hosted path is available; that request is processed for the run and is not saved as an API source or artifact. Use local Convert when a file must not leave your device.
OCR and URL mode
Image OCR and scanned-PDF OCR run in the browser, but OCR libraries, language data, or worker assets may be fetched the first time they are needed. URL mode requests the public URL directly from your browser when the target site allows CORS; the app does not provide a server-side proxy.
Analytics and third-party assets
The site uses Google Analytics 4 to understand aggregate usage such as page visits and feature engagement. Document contents, converted Markdown, and filenames are not sent as analytics events. The site may also request Google Fonts and other browser assets. Use your browser's privacy controls or an extension if you want to restrict those requests.
Server API accounts
The optional paid API is separate from the free browser workspace. API requests send the selected document to the server for processing; Extract and Ask send converted text to the configured AI provider. Account records, hashed passwords, hashed sessions, hashed API keys, usage counters, rate-limit counters, and API source and artifact bytes are stored in MongoDB, with file bytes held in MongoDB GridFS. API key plaintext is not stored. API accounts include a limited trial quota. Paid plans add recurring credits, and active paid accounts can purchase optional one-time top-ups.
Your responsibility
Local processing reduces the need to upload a source file, but it is not a guarantee of complete device privacy or zero network activity. Review OCR and extracted output before using it for legal, financial, medical, confidential, or other high-stakes work.