Konvertira legal information
Security & Data Handling
Last updated: October 11, 2026
Konvertira reduces unnecessary uploads with local image tools and applies validation, resource limits and bounded result storage to server workflows. Server processing can read your file, and no tool guarantees anonymity or malware-free output. This summary is a guide; the full explanation below describes implemented controls, deployment dependencies and their limits.
1. Local-first design and deliberate uploads
Supported JPG/JPEG, PNG and static WebP tools labelled local work on your device using browser decoding and canvas re-encoding. Those workflows do not call the processing API with the selected image and do not fall back to uploading it when local work fails. Loading the website still makes network requests for pages and assets. Device security, extensions and downloaded copies remain outside Konvertira's control.
PDF, document, Office, advanced image and background-removal features use explicit server processing. All MCP tools also use the server. An explicitly selected server image converter can process common formats, so the local guarantee attaches to the selected tool, not to an extension alone. If a file must not leave your device, stay with a supported local operation or use suitable offline software.
2. Transport security and service separation
The public service uses HTTPS, with Cloudflare handling DNS, reverse proxy/HTTPS traffic and related edge/network services, and runs on a Contabo VPS. Contabo's customer panel reports EU location; the exact data-center country was not independently established. The internal frontend Nginx listener uses HTTP behind the external proxy boundary. Detailed TLS termination and origin restrictions require ongoing operational review. HTTPS protects a transport connection, not every subsequent use of the data.
Frontend, backend and MCP run as separate services in the checked-in Compose configuration, with public-facing ports bound to host loopback for an external proxy. Caddy runs in a separate Compose stack from the application containers. The backend and MCP reuse processors but run in separate processes. Their Compose network is a bridge named internal, not a network configured with Docker's internal-only isolation flag. No claim is made that all outbound networking is blocked or that these services are inaccessible to a compromised host.
3. Server execution boundaries
A server request supplies a file and bounded parameters to a specific operation. The backend validates the declared format and uses appropriate parsers or decoders, then creates a result. Processing runs in application memory where practical. LibreOffice conversions use a separate random temporary workspace and user profile for the invocation, with fixed conversion filters rather than user-provided shell commands.
A temporary workspace is not a separate virtual machine or per-job security container. Jobs can share a service process and installed conversion engines. Native codecs and document parsers remain an attack surface. The service does not claim end-to-end encryption or zero-knowledge processing: the server must read an uploaded file. Resource checks are useful safeguards, not proof that every malformed input is harmless.
4. Temporary results and download links
Many web operations return generated bytes directly. MCP and certain compatibility routes store results under cryptographically random tokens with a default application TTL of 900 seconds, approximately 15 minutes. Generated results use two dedicated Docker volumes, one each for backend and MCP. Storage capacity is bounded; result names and extensions are controlled, token syntax is validated and stored files receive restrictive permissions. Download responses use no-store and nosniff headers.
There is no public account-based authorisation layer for those result downloads. The URL acts as a bearer capability: anyone possessing it may download while it remains available. Keep it private and avoid posting it in issues, screenshots or logs. Random tokens reduce guessing; they do not stop access after a token is disclosed. Result links are not a permanent file-sharing or backup feature.
The deployed backend and MCP use persisted expiry records and descriptor-backed downloads. Expiry is validated when resolving a token and before delivery starts, independently of physical cleanup. Subsequent requests for expired results are denied even if unlink fails; automated tests cover that failure path. Downloads already started while valid may finish after expiry. The operator confirmed a harmless MCP result returned HTTP 200 before expiry and HTTP 404 after expiry.
5. OpenAI downloads and SSRF protections
MCP accepts typed OpenAI file references, not arbitrary local paths or a general-purpose URL-fetching instruction. The downloader requires HTTPS, disallows embedded URL credentials and non-standard ports, validates exact or subdomain matches against configured host suffixes, and revalidates each redirect before following it. Defaults allow openai.com and oaiusercontent.com. Redirect count, streamed bytes and network timeouts are bounded.
These checks substantially restrict server-side request forgery (SSRF), but are not a complete network sandbox. DNS resolution is not pinned for an entire connection lifetime. Allowlist changes, provider behaviour and network configuration still matter; production egress controls are recommended defence in depth rather than claimed to exist here. Signed URLs and query strings should not be exposed in errors or diagnostic output.
6. Validation, detection and format limits
Extensions and MIME types supplied by a client are untrusted. The shared format registry defines supported operations and conversion pairs, and processors use image decoders, PDF parsers and document/package checks as applicable. Unsupported pairs are rejected rather than guessed. Validation is format-specific; it is not a universal forensic type detector or assurance that every parser sees exactly the same structure.
Current image processors reject animated inputs, and current PDF processors reject encrypted PDFs. Image decoding is bounded by compressed-byte and pixel ceilings, with a lower background-removal pixel ceiling. Validation does not establish copyright ownership, lawful disclosure or absence of personal data. A file that passes checks can still contain sensitive visible content, active elements or malicious material.
7. Size, page and resource budgets
Configuration centralises input/output sizes, decoded pixels, PDF pages, rasterisation DPI and generated-pixel budgets, document output, archive complexity and temporary-storage capacity. Repository defaults include 20 MiB image input, 40 MiB per PDF, 25 MiB document input and 250 PDF pages; multiple-PDF workflows also enforce file-count and aggregate limits. These are configuration defaults, not guaranteed production entitlements or a promise that every file below them will succeed.
PDF page selections must be valid; reordering requires each page exactly once, and deleting all pages is rejected. Rasterising a PDF may consume far more memory than its compressed size suggests, so generated-pixel checks are separate. Output limits also apply to generated archives. Actual runtime limits can be lowered for a small VPS, and overload, invalid content or a missing engine can still prevent processing.
PDF structure is handled by pypdf 6.20.0 and PDF-to-image rendering by pypdfium2 5.14.0/PDFium. PyMuPDF is absent from the new production backend/MCP images. PDFium rendering was verified on the Contabo Linux host, and all 16 public MCP tools were verified after deployment. Native PDFium calls are serialised per process because the renderer is not thread-safe; competing renders can receive a busy response. Expected rendering differences do not imply identical output to the previous engine.
8. Package parsing and archive safety
The Office metadata package validator bounds entry counts and declared expanded bytes, rejects encrypted entries and unsafe paths such as traversal components, and checks expected OOXML/ODF markers. It parses package data without extracting those entries onto the filesystem. XML metadata uses a hardened parser. Multi-output PDF and spreadsheet archives use generated names rather than accepting arbitrary output paths from the request.
These controls describe the guarded metadata workflow and generated archives, not every possible native decoder or LibreOffice behaviour. They do not certify a package free of ZIP bombs, malware or hidden data in every library path. Keep readers patched, inspect output and do not enable active content because a document has been converted. There is no general archive-unpacking service or arbitrary filesystem access tool.
9. Rate limiting, concurrency and timeouts
HTTP tools apply short-lived per-client request/heavy-job limits and process capacity gates. MCP adds global request/heavy-job quotas, global capacity and an overall job timeout. Busy heavy jobs are rejected immediately rather than queued without bound. LibreOffice has a subprocess timeout; background removal has a web timeout and permits one active inference per process. Not every HTTP operation has a separate cancellable wall-clock deadline.
Some processing runs in threads that cannot safely be killed. MCP and background-removal jobs retain their capacity slot while work really finishes after a response timeout. A timeout is not immediate erasure of memory or termination of native execution. Limiters are in-memory and per process; the documented baseline is one backend worker and one MCP worker. Multiple workers or replicas need coordinated limits or equivalent proxy protection. Quotas do not eliminate denial-of-service risk.
10. Containers and runtime restrictions
The shared backend/MCP Dockerfile switches to the non-root konvertira user. Compose drops their Linux capabilities and sets no-new-privileges, uses process initialisation and health checks, and mounts only named result volumes rather than the Docker socket or host source tree. The frontend also uses no-new-privileges, but its Nginx image is not represented here as an entirely non-root image.
The model directory is root-owned with mode 0555 and bundled model/licence/attribution files use 0444. A build step running as the runtime user checks read/traverse access and lack of write access. The configuration does not declare a read-only root filesystem, per-job containers or explicit service-wide CPU/memory cgroup budgets. Application limits remain important, and host hardening, patches and correct volume permissions are operational responsibilities.
11. Background-removal model provenance
Background removal uses the compact U²-NetP model from the U²-Net project, with fixed ONNX weights distributed through the documented rembg release. The preparation script downloads only the fixed build/setup URL and verifies the pinned SHA-256 before atomic publication. Runtime initialisation checks integrity again. Users cannot choose a model URL or path, and a missing or corrupt model produces an error rather than a runtime download.
Inference uses CPUExecutionProvider in ONNX Runtime, a reusable per-process session and one configured inference thread by default; no GPU or external AI-inference API is required. The model is not trained or updated from uploads. Hash verification identifies the expected artifact, not a formal audit of its training data or behaviour. Segmentation can be inaccurate. The existing bundled Apache licence and attribution must be retained when redistributing the image.
Third-party PDF licensing notices, including bundled native notices, are collected during Docker builds. The distribution is not described as exclusively permissively licensed: linked and OS components have separate obligations, including GCC Runtime Library Exception-related notices. PDF, U²-NetP and ONNX Runtime provenance and notices do not change the project's own licence or replace a complete redistribution review.
12. Browser protections and errors
The frontend Nginx configuration sends a Content Security Policy without unsafe-inline or unsafe-eval, along with MIME-sniffing, frame, referrer, permissions and cross-origin protections. Exact static legal routes retain the same security headers and no-cache policy. The backend uses an origin allowlist for browser API requests. These measures reduce some browser risks; CORS is not authentication, and headers cannot remove risks inside downloaded documents.
Expected errors report unsupported input, size limits, busy capacity or processing failures without intentionally exposing signed URLs or raw network traces. Bugs and dependency errors can still occur. Health endpoints indicate service responsiveness and do not prove that every codec, Office conversion or model is ready. The application does not provide an external availability guarantee or claim continuous staffed monitoring.
13. Logs, expiry and physical deletion
MCP resource logs describe tool names, outcomes, durations and operational rejection reasons, not intentionally recorded file contents. Backend/MCP commands disable Uvicorn access logs, not other technical logs. Frontend, backend, MCP and Caddy use Docker json-file logging with max-size 10m and max-file 3 per service: size-based rotation, not a fixed period. The system journal uses SystemMaxUse=100M and MaxRetentionSec=14day (a 14-day journal maximum-age setting) through systemd-journald, whose service was successfully restarted and is active. This journal policy does not govern Docker logs, Cloudflare, email or backups.
Cloudflare HTTP request analytics/logs are available, including source IP, timestamp, hostname/path, method and response status. Logpush is not subscribed to or configured; automatic Web Analytics/RUM injection is disabled. These settings do not imply that Cloudflare has no personal data or request logs. Provider retention and redaction remain separate questions; technical paths may contain sensitive tokens.
Expiry enforcement denies subsequent downloads independently of physical deletion. Application cleanup attempts to unlink expired regular result files at startup and periodically; removal is also attempted when an expired token is resolved. Errors, outages and worker operation affect timing; normal input/intermediate workspace cleanup is separate, and process failure can leave orphaned files. Contabo Auto Backup is disabled and the customer panel shows no customer snapshots, but provider-operated infrastructure mechanisms are not ruled out. Deletion is not secure-media overwriting or guaranteed erasure from all copies. Consult the Privacy Policy for retention categories.
14. OpenAI and infrastructure dependencies
The ChatGPT integration receives the selected file reference and tool parameters, not the user's entire conversation. It returns reports or result links to the platform, which may retain those under its own arrangements. Konvertira's expiry does not delete OpenAI's copies. Likewise, a hosting provider or HTTPS-terminating proxy may technically handle submitted data even when no external conversion API is used.
Contabo provides VPS hosting under a concluded DPA. Cloudflare provides DNS and reverse proxy/HTTPS services; its DPA is incorporated into applicable self-service terms, without making it a processor for every activity. OpenAI operates its own platform under its applicable terms and is not automatically Konvertira's processor. DNS, proxy, hosting, email and software dependencies introduce separate security and availability risks. There is no claim of EEA-only processing or access; exact provider retention, access locations and transfer mechanisms remain subject to review.
Incoming legal/support email is routed through Cloudflare Email Routing to Google Gmail; both addresses were manually tested by the operator. This does not establish identical provider roles, a separately signed Google DPA, EU-only Gmail storage or a fixed email deletion interval. Email retention, access and transfer arrangements remain separate from result expiry.
15. Responsible vulnerability reporting
Report suspected vulnerabilities or personal-data exposure privately to [email protected]. General technical issues can go to [email protected]. Include the affected feature, approximate time and minimal reproduction using your own harmless test files. Do not include other users' content or publish live signed/download URLs. Stop if testing would expose data, disrupt service or exceed your authorisation.
No bug bounty, formal safe-harbour programme, external penetration test, audit, ISO 27001, SOC 2 or PCI DSS certification is claimed. Reporting does not authorise unrestricted testing. The operator must assess and address incidents and make legally required notifications when applicable, but no fixed acknowledgement time or staffed 24/7 security operations centre is promised. Use competent emergency or regulatory channels where the situation requires them.
16. Practical precautions and remaining limitations
Keep independent originals and backups, inspect outputs before relying on them, and avoid uploading information you do not need to disclose. Use local processing or trusted offline software for files that should not leave your device. Keep viewers and browsers updated, do not enable macros on trust, and treat temporary result links as private. Metadata removal does not redact visible content, guarantee anonymity or remove every hidden identifier.
Konvertira is not professional forensic, medical, financial, legal-filing or archival-authenticity software. No absolute confidentiality, perfect malware prevention or uninterrupted availability is guaranteed. Implemented safeguards do not waive the operator's statutory duties. Read the Terms of Service, Privacy Policy, Support and About pages for related information.