Skip to content

Privacy Policy

Last updated 16 August 2026

The short version

Your images are converted inside your own browser. They aren't uploaded to us, and we can't see them. The one exception is the sharing feature, which you have to be signed in and subscribed to use, and which you have to trigger yourself.

We don't sell data, and we don't build advertising profiles or a picture of you across the web.

Your images

Conversion runs entirely on your device using WebAssembly. The file you pick is read by your browser, decoded locally, re-encoded locally, and handed back to you as a download. At no point is the image sent to a server we control.

That isn't a policy promise we could quietly break. It's how the tool is built, and you can watch it yourself — open your browser's network tab, convert a file, and you'll see no upload.

What we record about conversions

When a conversion finishes, your browser sends us a small anonymous record so we can tell whether the tool is working. It holds these fields, and nothing else:

There's no filename in that record, no image content, no account link and no IP address, so a conversion can't be traced back to a person.

What we record when you load a page

Separately from conversions, every page loads a first-party analytics script from stats.heic.site. It records the page you loaded, the site that referred you, your country, and your browser and device family.

To tell a returning visitor from a new one without storing your IP address, the analytics derives an identifier by hashing your IP together with a salt that is rotated every day. The hash cannot be reversed, the previous day's salt is discarded, and the identifier is never linked to your account or to the conversions above. That does mean we can count unique visitors.

If you create an account

Accounts are optional, and everything in the free tier works without one. If you create an account we store your email address, and either a hashed password (never the password itself) or a reference to the provider you signed in with.

Sign in with Google and we receive your email address, your Google account identifier, and your name. The email identifies your account, and the identifier recognises you on your next visit. We don't receive your Google password, and we ask for access to nothing else in your Google account.

We also record failed sign-in attempts against your email address and IP for a short period, so that someone can't sit and guess your password indefinitely.

If you share files

Sharing is the one feature that puts a file on our infrastructure, and only when you explicitly use it. The converted files you choose to share are stored in Cloudflare R2 and reachable by an unguessable link. A share holds at most 10 files, or 50 MB in total.

You pick an expiry of 24, 36 or 72 hours. When it passes, the files are deleted from storage and their records removed, and a scheduled job runs every hour to carry that out. If you send the link by email, we pass the recipient's address to our email provider for that message only.

Third-party providers

We rely on a small number of established providers for hosting and storage, payment processing, email delivery, sign-in if you choose to use it, and site analytics. Each of them handles only the data its own part needs. Our payment provider, for example, receives your card details directly, so those never reach our servers. None of them are permitted to use your data for their own purposes, and we don't sell data to anyone. Ask us for the current list by name and we'll send it.

Cookies

We set exactly one cookie, and only after you sign in: a session cookie that keeps you signed in. It's marked HttpOnly, Secure and SameSite, and it expires after 30 days. There are no advertising cookies, and the analytics described above sets none, because it identifies a visit by a rotating hash computed on our side rather than by anything stored in your browser.

How long we keep things

Your rights

You can ask us for a copy of the data attached to your account, ask us to correct it, or ask us to delete it along with the account. Email us and we'll action it. Depending on where you live, the GDPR or a similar law may give you those rights formally — we intend to honour them wherever you are.

Children

heic.site isn't directed at children under 13, and we don't knowingly collect their personal information.

Changes

If this policy changes in a way that affects you, we'll update the date at the top, and for anything significant we'll tell account holders by email.

Contact

Questions about privacy, or a request about your data, can go to privacy@heic.site.