Privacy
Convert files without uploading them
Start here
What “upload” means, and why nobody explains it
If you have ever wondered what the progress bar on a converter is actually doing, this is it.
The usual way: your file leaves
You press Convert. A copy of your document is sent across the internet to a computer owned by whoever runs the site. It is converted there and the result is sent back. That journey — and the copy left at the other end — is what the word “upload” describes. From that moment, what happens to your file is governed by a policy you did not write, on hardware you cannot see, often in a country you did not choose.
Here: nothing is sent at all
When you open a converter on this site, the page brings the conversion software with it. Your file is read by the browser you are already using, converted there, and saved straight back to your device. It never travels. This is not a faster server or a stricter deletion policy — it is the absence of the step entirely, which is why there is nothing to delete.
What that rules out
A file that is never sent cannot be retained after you were told it was deleted, exposed if the company is breached, read by staff or contractors, handed over when the business is sold, produced under a subpoena, or used to train a model. Not because of a promise on any of those points — because the copy those things would need does not exist.
Side by side
A normal online converter, and this one
The left column is not an accusation about any particular site — it is simply how server-side conversion works, and most converters are server-side.
| Typical online converter | FileTools360 | |
|---|---|---|
| Where the work happens | On a computer owned by the website | In the browser tab you have open |
| Does your file travel? | Yes — across the internet, both ways | No. It is never transmitted |
| Who could read it | Staff, contractors, anyone who breaches the server | Nobody. There is no copy to read |
| How long it is kept | A retention period stated in a policy | No retention — there was never a copy |
| If the company is sold or subpoenaed | Whatever it holds can change hands | It holds nothing to hand over |
| Works without internet | No | Yes, once the page has loaded |
Do not trust this page
Two ways to check it for yourself
Every other privacy claim you have read this week asks you to believe it. This one can be tested in less time than it takes to read the policy.
The ten-second version
- 1. Open any converter on this site and wait for it to finish loading.
- 2. Turn off your Wi-Fi, or switch the device to flight mode.
- 3. Add a file and convert it.
It works. A converter that needed your file on its server could not possibly do that, which makes this the whole proof in one step.
The version that shows you the traffic
Press F12 to open your browser's developer tools and choose the Network tab, then convert a file while you watch. You will see the page and the conversion software load, and then nothing carrying your document — no request with your file in it, because none is made. It is the same view a security researcher would use, and it needs no expertise to read: either your file is in that list or it is not.
The documents people actually convert
It is easy to read all of this as abstract until you think about the specific file you were about to convert. People do not often convert things that do not matter — a file becomes worth converting precisely when somebody needs to send it, sign it, submit it or keep it. In practice that means the queue on any converter, anywhere, looks something like this:
- Bank statements and payslips — account numbers, balances, salary, your home address, and a record of everyone you have paid.
- Passport, visa and licence scans — the single most useful set of documents for anyone attempting identity theft.
- Signed contracts and NDAs — your signature, plus terms you may be contractually obliged not to disclose to a third party.
- Medical letters, results and scans — health information, which is regulated in most countries precisely because of how sensitive it is.
- Tax returns — income, dependants, and national identity numbers.
- Payroll and customer spreadsheets — not one person's data but hundreds, which is what turns an ordinary file into a reportable breach.
- Recorded calls, interviews and meetings — conversations involving people who never agreed to a third party holding a copy.
- CVs and résumés — date of birth, home address, phone number and a complete history of where you have been.
For an ordinary photo of a sandwich, none of this is worth a second thought. The trouble is that the same converter handles both, and you have to decide which one you are using before you find out. Keeping every file on your own device removes the decision.
What this does not protect you from
A page arguing for honesty has to include the limits, so here they are. Converting on your own device protects your file from being sent anywhere — that is the whole of the claim, and it is a large claim, but it is not every claim.
It does not protect you from something already running on your own computer: malware that can read your files can read them whether or not this site exists. It does not protect a shared or unlocked machine from the next person to sit at it. And it does not encrypt anything — your file is handled in your browser's memory in the ordinary way, and the converted result is saved wherever your browser saves downloads. If your threat model includes your own device, this site helps with none of it, and no converter can.
One exception: files you bring in from somewhere else
This site can also take a file from Google Drive and Dropbox. That is a convenience, and it is worth being precise about what it changes and what it does not.
What does not change: the file is still converted on your device, and it still never reaches a FileTools360 server — there is no such server. It arrives in your browser and is handled exactly like a file you dragged in from your desktop.
What does change: the file travels over the network to get here, from a service you chose, and this page has to be permitted to contact that service. So for those imports the page is no longer talking only to its own origin, and the flight-mode test above will not work — there is nowhere for the file to come from with the network off. Files you add from your own device are unaffected by any of this, and they remain the default.
Where the claim is enforced, not just stated
One detail worth knowing, because it is what separates this from a policy. Every page on this site is served with a Content-Security-Policy — a rule the browser itself enforces — that declares which destinations the page is permitted to contact. Your files are not in that set of permitted destinations, and nothing on the page can change the header after it is sent. So the claim is not only a description of how the software behaves; it is a restriction the browser applies whether the software behaves or not.
The privacy page sets out what is collected in full — the short version is two numbers when a conversion finishes, and an email address if you choose to make an account.
FAQ
Questions about uploading and safety
What does “uploaded” actually mean?
So my file really never leaves my device?
Is it safe to convert a bank statement or a passport scan?
What do you actually collect, then?
Why do other converters upload files at all?
Is there anything this does not protect me from?
Try it
Pick a category and check for yourself
Every tool behind every one of these links runs the same way.
522 tools, none of which upload anything
Free, no account, no watermark, and the same on every one of them.