Privacy Policy
Last updated 16 August 2026
The short version
Your images are converted inside your own browser. They are not uploaded to us, and we cannot see them. The only exception is the optional sharing feature, which you have to be signed in and subscribed to use, and which you have to deliberately trigger.
We do not sell data, we do not run advertising profiles, and we do not build a picture of you across the web.
Your images
Conversion runs entirely on your device using WebAssembly. The file you pick is read by your browser, decoded locally, re-encoded locally, and handed back to you as a download. At no point is the image sent to a server we control.
This is not a policy promise we could quietly break — it is how the tool is built. You can watch it yourself in your browser's network tab: convert a file with the tab open and you will see no upload.
What we record about conversions
When a conversion finishes, your browser sends us a small anonymous record so we can tell whether the tool is working. It contains exactly these fields, and nothing else:
- The input and output formats (for example, HEIC to JPG)
- The file size in bytes, and the size of the result
- How long the conversion took, and which engine handled it
- Any error message, if it failed
- Your country, and your browser family (Chrome, Firefox, Safari, and so on)
There is no filename, no image content, no account link, and no IP address in that record. We deliberately do not store IP addresses against conversions, which means we cannot count unique people — a trade-off we are happy with.
If you create an account
Accounts are optional. Everything in the free tier works without one. If you create an account we store your email address, and either a hashed password (never the password itself) or a reference to the provider you signed in with.
If you sign in with Google, we receive your email address, your Google account identifier, and your name. We use the email to identify your account and the identifier to recognise you on your next visit. We do not receive your Google password, and we request no access to any other Google data.
We also record failed sign-in attempts against your email address and IP for a short period, so that someone cannot sit and guess your password indefinitely.
If you share files
Sharing is the one feature that puts a file on our infrastructure, and only when you explicitly use it. Converted files you choose to share are stored in Cloudflare R2 and reachable by an unguessable link.
You pick an expiry of 24, 36, or 72 hours. When it passes, the files are deleted from storage and their records removed. A scheduled job runs every hour to carry this out. If you send the link by email, we pass the recipient's address to our email provider for that message only.
Third-party providers
We rely on a small number of established providers for hosting and storage, payment processing, email delivery, sign-in if you choose to use it, and site analytics. They handle only the data needed for their part — our payment provider, for example, receives your card details directly, so those never reach our servers. None of them are permitted to use your data for their own purposes, and we do not sell data to anyone. If you would like the current list by name, ask us and we will send it.
Cookies
We set exactly one cookie, and only after you sign in: a session cookie that keeps you signed in. It is marked HttpOnly, Secure, and SameSite, and it expires after 30 days. There are no advertising or tracking cookies, which is why you have never seen a cookie banner here.
How long we keep things
- Shared files — until the expiry you chose, then deleted
- Sign-in sessions — 30 days, then removed automatically
- Failed sign-in records — a short window, then swept
- Account details — until you ask us to delete them
- Anonymous conversion records — kept, as they identify no one
Your rights
You can ask us for a copy of the data attached to your account, ask us to correct it, or ask us to delete it along with the account. Email us and we will action it. Depending on where you live, the GDPR or similar laws may give you these rights formally; we intend to honour them regardless of where you are.
Children
heic.site is not directed at children under 13, and we do not knowingly collect their personal information.
Changes
If this policy changes in a way that affects you, we will update the date at the top and, for anything significant, tell account holders by email.
Contact
Questions about privacy, or a request about your data, can go to privacy@heic.site.