Privacy and file handling
Understand local file processing, temporary server uploads, one-hour expiry, download links, ownership cookies and job metadata retention.
Browser tools
Tools labelled Runs in browser process file content locally without uploading it to FileNimble. The website still requests its pages and application assets. Clearing a tool or leaving its page releases application references; browsers control memory reclamation, so this is not secure erasure. Your source files and saved downloads remain on your device.
Temporary server processing
Server tools upload files only when you start conversion. Temporary storage holds the upload, validated input and generated output. Isolated conversion workers process those files. File content is not stored in the job database, queue messages or application logs. There is no permanent file library.
Optional AI processing
AI tools are disabled unless the operator configures an external provider. When enabled, the page explains the data sent and asks for consent before each request. For current AI tools, PDF bytes are extracted locally in your browser; only the text you enter or extracted text is sent to FileNimble’s API and then to the configured provider. AI text is not stored in conversion jobs, object storage, databases or application logs. The provider may handle requests under its own terms and retention policy. AI output can be wrong and should be reviewed.
Expiry and deletion
Abandoned jobs expire one hour after creation. Completed outputs expire one hour after completion. Failed, cancelled or deleted jobs become eligible for immediate cleanup. Clear files requests early deletion. Cleanup is retried, but outages can delay physical deletion. Expiry is not a promise of instant erasure. Saved downloads are outside this cleanup process.
Download links and job records
Downloads require the session that owns the job. Issued download links last at most 60 seconds and do not intentionally extend expiry. An already issued link can remain valid briefly if deletion is delayed; do not share it. Minimal job records, including status, size, format, checksums and attempt information, are purged seven days after confirmed artifact removal. These records do not contain document bytes or original filenames.
Cookies, advertising and operational information
Server jobs use a necessary anonymous ownership cookie lasting up to 24 hours to authorize access without an account. When monetization is configured and enabled by the operator, third-party advertising partners such as Google AdSense may place or read cookies and device identifiers to serve, personalize, and measure advertisements in accordance with their privacy policies and applicable user consent. Users can manage personalized ad preferences through Google Ads Settings or industry opt-out tools. File contents, uploaded documents, filenames, and conversion data are strictly isolated: they are never shared with, processed by, or accessible to advertising services. Application diagnostics use bounded error categories and operational counters, never document content, passwords, or signed URLs. Hosting infrastructure receives connection information such as IP addresses; provider logging and retention must be reviewed before public deployment.
Your choices
Choose browser tools when you need file content to stay on your device. Avoid uploading information you are not authorized to process. Download results before they expire, clear server jobs when finished, and remove local downloads yourself when no longer needed. Contact details, when configured by the operator, are on the Contact page.