Privacy Policy
Last updated: October 29, 2025
1. Introduction
ConvertGoblin ("we", "us", "our", or "Service") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our document conversion service.
By using ConvertGoblin, you agree to the collection and use of information in accordance with this policy. We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date.
2. Our Core Privacy Principle: 100% Client-Side Processing
2.1 No File Uploads: ConvertGoblin processes all document conversions entirely within your web browser. Your files are:
- Never uploaded to our servers
- Never transmitted over the internet
- Never stored on our systems
- Never accessed by us or any third party
All conversion processing happens locally on your device using JavaScript libraries loaded in your browser. This ensures maximum privacy and security.
2.2 Zero-Knowledge Architecture: We operate on a zero-knowledge basis. We cannot see, access, or know anything about the files you convert, including:
- File names
- File contents
- File sizes
- Conversion results
3. Information We Collect
3.1 Account Information (Optional): If you create an account, we collect:
- Email address (for account creation and communication)
- Username or display name (if provided)
- Password (hashed using SHA-256, never stored in plain text)
- Account preferences (theme settings, language preferences)
3.2 Usage Analytics (Minimal): We collect basic usage statistics stored locally in your browser:
- Number of conversions performed (stored in localStorage)
- Conversion types used (for feature improvement)
- Error logs (if errors occur, stored locally)
3.3 Payment Information: When you subscribe to Pro or Lifetime plans:
- Payment processing is handled entirely by PayPal
- We do not store credit card numbers, bank account details, or payment information
- We only receive confirmation of successful payments
- PayPal's privacy policy applies to payment transactions
3.4 Technical Information: We may automatically collect:
- Browser type and version
- Operating system
- Screen resolution (for UI optimization)
- IP address (for security and abuse prevention only)
3.5 What We Do NOT Collect:
- Your files - Never uploaded or stored
- File contents - Cannot be accessed by us
- Personal documents - No access to document content
- Location data - Not collected (except approximate IP-based location for security)
- Third-party tracking - No Google Analytics, Facebook Pixel, or similar tracking
4. How We Use Your Information
We use the information we collect to:
- Provide the Service: Enable document conversions and account management
- Improve Service Quality: Analyze usage patterns to improve features (all data aggregated and anonymized)
- Respond to Support Requests: Help you with technical issues or questions
- Send Important Notifications: Account-related updates, security alerts, service changes
- Prevent Abuse: Detect and prevent fraud, spam, or security threats
- Comply with Legal Obligations: Meet legal requirements and respond to lawful requests
4.1 We Do NOT:
- Sell your personal information to third parties
- Use your information for advertising or marketing (except service-related communications)
- Share your information with third parties except as described in this policy
- Monitor or track your conversion activities for commercial purposes
5. Cookies and Tracking Technologies
5.1 Essential Cookies: We use minimal cookies only for essential functionality:
- Authentication: Session cookies to maintain your login state
- Preferences: Store your theme preference (dark/light mode)
- Security: CSRF tokens to prevent cross-site request forgery attacks
5.2 No Tracking Cookies: We do NOT use:
- Google Analytics or similar analytics services
- Advertising cookies or tracking pixels
- Social media tracking buttons
- Third-party advertising networks
5.3 Local Storage: We use browser localStorage (not cookies) to store:
- Theme preferences
- Conversion history (stored locally on your device)
- User preferences
All localStorage data remains on your device and is never transmitted to our servers.
6. Data Sharing and Disclosure
6.1 No File Sharing: We do not and cannot share your files because we never have access to them. Files are processed entirely in your browser.
6.2 Service Providers: We may share minimal account information with trusted service providers who assist in operating our Service:
- Hosting Provider: Vercel (for hosting our website - no file access)
- Payment Processor: PayPal (for payment processing - see PayPal's privacy policy)
- Email Service: For sending account-related emails (no file access)
All service providers are contractually required to maintain the confidentiality and security of your information.
6.3 Legal Requirements: We may disclose information if required by law or in response to:
- Valid legal requests from law enforcement
- Court orders or subpoenas
- Protecting our rights, property, or safety
- Preventing fraud or security threats
6.4 Business Transfers: In the event of a merger, acquisition, or sale of assets, your account information may be transferred. You will be notified of any such change in ownership.
7. Data Security
7.1 Client-Side Security: By processing all conversions in your browser:
- Files never leave your device
- No network transmission of sensitive data
- No server-side storage vulnerabilities
- Reduced risk of data breaches
7.2 Account Security: We implement security measures for account protection:
- Passwords are hashed using SHA-256 (never stored in plain text)
- HTTPS encryption for all communications
- Session management with secure tokens
- Rate limiting to prevent abuse
7.3 No Guarantees: While we employ industry-standard security practices, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security of account information.
8. Your Privacy Rights
8.1 Access: You can access your account information at any time through your dashboard.
8.2 Correction: You can update your account information, email, and preferences through your account settings.
8.3 Deletion: You can delete your account at any time, which will permanently remove:
- Your account information
- Usage statistics
- All stored preferences
Note: Since files are processed client-side, there are no files to delete from our servers.
8.4 Data Portability: You can export your account data through your dashboard.
8.5 Opt-Out: You can opt-out of non-essential communications by:
- Unsubscribing from marketing emails
- Adjusting notification preferences in your account settings
8.6 GDPR Rights (EU Residents): If you are in the European Union, you have additional rights under GDPR:
- Right to access your personal data
- Right to rectification (correction)
- Right to erasure ("right to be forgotten")
- Right to restrict processing
- Right to data portability
- Right to object to processing
- Right to withdraw consent
To exercise these rights, contact us at support@ConvertGoblin.app.
9. Children's Privacy
ConvertGoblin is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If you believe we have collected information from a child under 13, please contact us immediately, and we will delete such information.
If you are between 13 and 18, you must have your parent's or guardian's permission to use our Service.
10. International Data Transfers
Our Service is hosted in the United States. If you are accessing our Service from outside the U.S., please note that:
- Your information may be transferred to, stored, and processed in the United States
- Data protection laws in the U.S. may differ from those in your country
- By using our Service, you consent to the transfer of your information to the U.S.
For EU residents: We comply with GDPR requirements for international data transfers and implement appropriate safeguards.
11. API and Third-Party Integrations
11.1 API Usage: If you use our API:
- API requests are logged for security and rate limiting purposes
- API keys are associated with your account but not linked to specific files
- We track API usage statistics (number of requests, not file contents)
11.2 Third-Party Services: Our Service may contain links to third-party websites or services. We are not responsible for the privacy practices of third parties. We encourage you to review their privacy policies.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by:
- Posting the new Privacy Policy on this page
- Updating the "Last updated" date
- Sending email notifications for material changes (if you have an account)
- Displaying a notice on our website for significant changes
You are advised to review this Privacy Policy periodically for any changes. Changes are effective when posted on this page.
13. Contact Us
If you have questions about this Privacy Policy or wish to exercise your privacy rights, please contact us:
Email: support@ConvertGoblin.app
Contact Form: /contact
Response Time: We aim to respond within 48 hours
14. Compliance and Certifications
ConvertGoblin is designed with privacy and security as core principles:
- GDPR Compliant: We comply with the General Data Protection Regulation (EU)
- CCPA Compliant: We respect California Consumer Privacy Act requirements
- Zero-Knowledge Architecture: Your files are never accessible to us
- HTTPS Encryption: All communications are encrypted
Last updated: October 29, 2025
This Privacy Policy may be updated periodically. We recommend reviewing it regularly.