Converter safety and privacy

How to choose a safer online file converter

No checklist can guarantee that a website or downloaded file is safe. Before uploading, verify the exact domain, read how files are handled, avoid tools that demand software for an ordinary conversion, and scan the result before opening it.

Reviewed 3 August 2026 · Methodology and limitations included below

Why converter safety deserves a check

In March 2025, the FBI warned that criminals were promoting malicious file-converter and downloader websites. The warning described sites that could install malware or collect information from submitted files. That does not mean every online converter is malicious; it means the site and the downloaded result should be evaluated before use.

Read the FBI Denver warning

Seven checks before you convert

  1. Check the exact domain

    Type or inspect the address carefully. Lookalike spellings, unexpected subdomains, and a prominent search ad are not proof that a service is trustworthy.

  2. Expect HTTPS, but verify more

    A secure browser connection helps protect data in transit. It does not prove what a site does with a file after it arrives.

  3. Question required downloads

    A normal browser conversion should not require an extension, installer, or executable. Leave if the page unexpectedly asks you to install one.

  4. Read the file policy first

    Look for a specific deletion window, what operational records remain, who operates the service, and a way to report problems.

  5. Keep sensitive files offline

    For confidential, financial, identity, health, legal, or client material, prefer an approved local tool or your organization’s controlled workflow.

  6. Inspect and scan the result

    Confirm the extension is the format you expected. Keep browser and security warnings enabled, scan the download, and do not bypass a warning just to open it.

  7. Check the output

    Compare page count, duration, dimensions, resolution, and important settings with the source. A successful download is not proof that the conversion is complete or correct.

Google also recommends taking download warnings seriously and using security scanning when a download is suspicious. Review Google Chrome download-safety guidance.

What happens in a standard Convertr conversion

These statements apply to the standard server-based audio, video, image, document, and format-conversion flow. A specialist tool may use a different, clearly labelled input or browser-only workflow.

Diagram showing a file moving from the user’s browser over HTTPS to an automated conversion worker, then to a signed download before automatic deletion.
Standard server conversion file journey. The diagram contains no user files or user data. Download the SVG diagram.
Upload and processing
Your browser uploads the file over HTTPS. Convertr validates the request and sends it to a compatible automated conversion worker. No account is required for the public conversion flow.
Temporary download
The result is made available through a time-limited signed download URL. A link should still be treated as private and not shared unnecessarily.
File deletion
Files in the standard conversion workspace are automatically deleted within 24 hours, often sooner. Five minutes after a completed full download, the workspace becomes eligible for cleanup. Active conversion workspaces are protected from cleanup while a job is running.
Operational records
Deleting files is separate from deleting limited operational records used for reliability, abuse prevention, and aggregate analytics. The privacy policy describes those records and their retention; conversion telemetry is retained for 14 days.

Read the full privacy and retention policy

The 1 GB upload policy

The standard converter accepts an individual upload up to exactly 1 GiB (1,073,741,824 bytes), commonly labelled 1 GB in the interface. Files above that limit are rejected before conversion. Convertr does not intentionally reduce output resolution, duration, codec, bitrate, dimensions, or quality merely to control server load; available settings still depend on the selected workflow and formats.

What this page does not claim

This is a transparency statement, not a security certification, independent audit, penetration test, or guarantee that every website, file, conversion, or download is malware-free. We do not use this page to claim an external certification, encryption at rest, or antivirus scanning that has not been verified and documented.

How we verified these statements

On 3 August 2026, we reviewed the standard upload validation, workspace storage, signed-download configuration, cleanup scheduler, active-job protections, deletion code, automated tests, current privacy policy, and the application revision deployed on representative production conversion workers. We compared the public wording with the implemented behavior and removed broader claims that the evidence did not support.

This review covers product behavior and public documentation. It does not replace an independent security assessment. We review this page when relevant behavior changes and schedule a full review at least quarterly. Corrections can be reported through the contact page without attaching a confidential file.

Report a correction or privacy concern

Frequently asked questions

Is any online converter guaranteed to be safe?

No. Use several checks together, keep sensitive material in an approved offline workflow, and treat unexpected installers or security warnings as reasons to stop.

When does Convertr delete standard conversion files?

Standard conversion workspaces are automatically deleted within 24 hours and may be removed sooner after a completed download. Limited operational records have separate retention periods described in the privacy policy.

Does every Convertr tool upload my file?

No. Some utilities run locally in the browser, while standard media and document conversions use an automated server worker. Check the selected tool’s instructions before providing a file or other input.