Skip to main content
Drop files to convert
Loconva logo
  • Home
  • Converters
  • About
  • Developers

Legal information

Privacy Policy

Deployment note: Complete the controller and provider configuration before publication and review this policy against the final production setup.

This policy explains which data Loconva processes, why it is needed, and which optional actions send data to third parties.

Controller

Not yet configured for production
Not yet configured for production
Email: support@loconva.com

Data protection officer: No appointment is currently recorded as required; this assessment must be confirmed before launch.

Policy version: Not yet configured for production; review date: Not yet configured for production

Processing activities

Each legal basis below is a proposed classification and requires final approval by a qualified reviewer before production release.

Hosting, access logs, and security

Data categories
IP address, HMAC-pseudonymous rate-limit identifier, request time, method, path, response status, request ID, and security events. File content reaches the server only for an explicitly selected hosted API conversion.
Purpose
Deliver the site and API, detect abuse, diagnose faults, secure the service, and enforce request limits.
Proposed Article 6 basis
Article 6(1)(f) GDPR (secure and reliable operation); Article 6(1)(b) where required to provide a requested service. Final legal approval required.
Recipients
netcup hosting infrastructure, self-hosted Coolify deployment tooling, and authorized operators.
Retention
Access logs are configured for up to 7 days; security records may be retained longer only where an incident requires it.
Required and consequence of refusal
Network identifiers are technically required to establish a connection. Refusal means the website or hosted API cannot be delivered.

Local browser conversion

Data categories
Selected source files, generated output, and conversion settings remain in browser memory on the user's device.
Purpose
Perform the conversion selected by the user without uploading the source file to Loconva.
Proposed Article 6 basis
Article 6(1)(b) GDPR for the requested service; to the extent Loconva receives no personal data, server-side GDPR processing does not occur. Final legal approval required.
Recipients
No server or third-party recipient for ordinary local conversion.
Retention
Files remain on the device and are released by the page after use or when the page is closed.
Required and consequence of refusal
Providing a file is optional but necessary to perform that conversion. Refusal has no effect on browsing the site.

Aggregate server-side reach measurement

Data categories
Allowlisted public route name and receipt time. Loconva does not send visitor IP addresses, browser User-Agents, referrers, language, screen size, query strings, fragments, cookies, account or session identifiers, filenames, formats, or file contents to analytics.
Purpose
Measure aggregate public-page traffic and route popularity so Loconva can improve navigation, documentation, and capacity planning.
Proposed Article 6 basis
Proposed Article 6(1)(f) GDPR (limited aggregate reach measurement), subject to a documented balancing test and final legal approval. No analytics access to terminal-device information occurs under Section 25 TDDDG. Final legal approval required.
Recipients
netcup hosting infrastructure and authorized Loconva administrators. Umami is self-hosted in private mode; Umami Software does not receive visitor analytics data.
Retention
Live analytics events are deleted after 90 days. The dedicated analytics event database is not backed up.
Required and consequence of refusal
Not required to use Loconva. Do Not Track and Global Privacy Control signals are honored as objections; refusing or blocking measurement has no effect on the service.

Accounts and authentication

Data categories
Email address, password hash, verification status, account tier, session version, API-key hashes and labels, balance, account timestamps, and safe authentication-token lifecycle metadata.
Purpose
Create and secure accounts, authenticate sessions, manage API access, and provide export and deletion controls.
Proposed Article 6 basis
Article 6(1)(b) GDPR (account contract) and Article 6(1)(f) GDPR (account and credential security). Final legal approval required.
Recipients
Hosting provider and authorized operators; Resend only for the account-email activity described separately.
Retention
For the life of the account; operational deletion is immediate after a valid deletion request, subject to legally required provider records and backups expiring within up to 30 days.
Required and consequence of refusal
An account is optional for local conversion but required for subscriptions, hosted API keys, token balances, exports, and optional history.

Registration, verification, and password email

Data categories
Email address, selected language, message purpose, single-use action URL, delivery metadata, and provider idempotency identifier.
Purpose
Verify ownership of an address, activate accounts, and provide secure password recovery.
Proposed Article 6 basis
Article 6(1)(b) GDPR (account service) and Article 6(1)(f) GDPR (secure account recovery). Final legal approval required.
Recipients
Resend and its reviewed subprocessors; the feature remains disabled until the provider review is recorded.
Retention
Application token hashes expire after the configured verification/reset period and are removed by maintenance; provider delivery metadata follows the reviewed contract.
Required and consequence of refusal
A valid email is required to register or recover an account. Refusal leaves local conversion available but prevents those account functions.

Support contact

Data categories
Name, contact email, optional account email, category, subject, message, language, reference, and submission time. IP address and user agent are not included in the support email.
Purpose
Answer the request, associate it with an account when requested, and protect the form from abuse.
Proposed Article 6 basis
Article 6(1)(b) GDPR for contractual/pre-contractual requests or Article 6(1)(f) GDPR for general support and abuse prevention. Final legal approval required.
Recipients
Hosting provider, mailbox.org/SMTP support mailbox, and authorized support staff.
Retention
No application-database copy; mailbox copies are scheduled for deletion after up to 180 days unless an active case or legal obligation requires longer.
Required and consequence of refusal
Required form fields are necessary to answer the request. Refusal means the support form cannot be used; privacy requests can still be sent to the published privacy address.

Optional conversion history

Data categories
Original filename, source format, target format, and conversion timestamp.
Purpose
Display a personal list of recent conversions.
Proposed Article 6 basis
Article 6(1)(a) GDPR (opt-in consent), subject to final legal review. Final legal approval required.
Recipients
Hosting provider and the authenticated account holder.
Retention
Up to 30 days. Disabling history atomically deletes all existing entries; individual and clear-all deletion are also available.
Required and consequence of refusal
Entirely optional. Refusal or withdrawal has no effect on conversion or paid account access; no history metadata is sent.

Hosted API and CLI conversion

Data categories
Uploaded file and content, source and target formats, API-key identifier, request ID, token usage, and temporary processing paths. Original filenames are not stored in token-transaction descriptions.
Purpose
Authenticate, convert, return the output, meter token use, and investigate request failures.
Proposed Article 6 basis
Article 6(1)(b) GDPR (requested hosted conversion) and Article 6(1)(f) GDPR (security and abuse prevention). Final legal approval required.
Recipients
Hosting provider and authorized operators.
Retention
Temporary input/output files are deleted after the request; format-only token transactions remain with the account and as legally required.
Required and consequence of refusal
Required only for hosted API use. Refusal prevents hosted conversion but the local browser converter remains available.

Billing, subscriptions, and token purchases

Data categories
Account email, Stripe customer/subscription/payment identifiers, purchased product, payment and subscription status, billing timestamps, token ledger, refunds, and dispute state. Loconva does not receive full card details.
Purpose
Open checkout, administer subscriptions, credit purchases, process refunds/disputes, prevent duplicate processing, and meet accounting duties.
Proposed Article 6 basis
Article 6(1)(b) GDPR (payment contract), Article 6(1)(c) GDPR (tax/accounting duties), and Article 6(1)(f) GDPR (fraud and duplicate prevention). Final legal approval required.
Recipients
Stripe, hosting provider, authorized operators, and legally required tax or audit recipients.
Retention
Operational subscription data remains with the account; records subject to tax/accounting duties are configured for up to 10 years. Stripe applies its own required retention.
Required and consequence of refusal
Required only for a paid subscription or token purchase. Refusal leaves the free local converter available.

Optional Google Drive or Dropbox export

Data categories
Converted output, output filename, provider account/authorization data, short-lived OAuth state, and browser-side pending output.
Purpose
Send a converted result to the cloud destination explicitly chosen by the user.
Proposed Article 6 basis
Article 6(1)(a) GDPR (explicit optional action) and/or Article 6(1)(b) GDPR (requested export), subject to final legal review. Final legal approval required.
Recipients
Google or Dropbox, selected by the user. Their code and authorization flow remain hidden until the corresponding privacy review and credentials are present.
Retention
Loconva keeps handoff state only for the browser session or until completion; the provider retains the uploaded file and account activity under its terms.
Required and consequence of refusal
Optional. Refusal disables only cloud export; normal download and local conversion remain available.

Browser storage and necessary cookies

Data categories
Theme and locale choice, secure session cookie, optional offline application assets, OAuth state, and a pending converted output during cloud handoff.
Purpose
Remember requested settings, maintain login, provide user-requested offline operation, and complete optional cloud handoffs securely.
Proposed Article 6 basis
Section 25(2) TDDDG for strictly necessary storage and proposed Article 6(1)(b)/(f) GDPR; offline storage begins only after the user's request. Final legal approval required.
Recipients
The user's browser; no advertising or analytics recipient.
Retention
Varies by item as listed below; offline caches contain only anonymous application assets and a non-personal fallback.
Required and consequence of refusal
Session storage is required only for login; locale, theme, offline mode, and cloud handoff are optional. Refusal limits only the related function.

Storage in Your Browser

TechnologyPurposeWhen usedRetention
theme in localStorageRemember light or dark appearanceAfter you change the themeUntil you clear site data
loconva_locale cookieRemember your language selectionAfter you explicitly choose a languageUp to one year or until you clear site data
fc_session cookieKeep you securely signed inAfter registration or loginUp to 30 days or until logout
Dropbox state in sessionStorageProtect and complete the OAuth redirectAfter you choose Dropbox exportRemoved after the callback or when the browser session ends
Pending output in IndexedDBCarry a converted file across a cloud-provider handoffAfter you choose a cloud export that requires itRemoved after successful handoff; otherwise retained until site data is cleared
Cache StorageProvide optional offline application filesOnly after you click “Enable offline mode”Until you disable offline mode or clear site data

These functional storage mechanisms are not used for advertising or cross-site tracking. Aggregate analytics runs only on the server and does not add browser storage or read device information for analytics, so no analytics consent banner is shown. If browser-side or non-essential storage is introduced, it remains disabled until the required consent is obtained.

Providers, processing locations, and transfers

Roles are proposed classifications. Locations, transfer safeguards, contracts, subprocessors, and retention must be verified and recorded before a feature is marked reviewed.

ProviderProposed rolePurpose Data categoriesProcessing locationTransfer mechanism RetentionPrivacy informationReview status
netcup GmbH Processor for infrastructure, subject to Article 28 agreement verification. Compute, network, database volume, backups, and access/security logs. Network identifiers, logs, account data, and hosted API files when that feature is used. Not yet configured for production Not yet configured for production Not yet configured for production Official policy Not reviewed; feature gated
Coolify / coolLabs Self-hosted deployment tooling; verify whether any managed feature creates a separate recipient. Deploy, configure, monitor, and administer the application. Deployment metadata, configuration names, operational status, and logs available to administrators. Not yet configured for production Not yet configured for production Not yet configured for production Official policy Not reviewed; feature gated
Umami (self-hosted software) Internal analytics software operated by Loconva; Umami Software is not a recipient when private mode and telemetry blocking remain enabled. Store and display aggregate counts for allowlisted public routes. Normalized public route and receipt time; a fixed service-level sender is used instead of visitor identifiers. Not yet configured for production Not yet configured for production Not yet configured for production Official policy Reviewed/configured
mailbox.org / Heinlein Hosting GmbH Proposed processor for the support mailbox, subject to Article 28 agreement verification. Receive and retain support and privacy correspondence. Contact details, message content, references, and mail-delivery metadata. Not yet configured for production Not yet configured for production Not yet configured for production Official policy Not reviewed; feature gated
Resend / Plus Five Five, Inc. Proposed processor for transactional account email; transfer role requires approval. Deliver verification and password-recovery email. Email address, message content/action URL, language, category, and delivery metadata. Not yet configured for production Not yet configured for production Not yet configured for production Official policy Not reviewed; feature gated
Stripe Processor and/or independent controller depending on the payment activity; final classification required. Checkout, subscription portal, payment processing, refunds, disputes, and fraud prevention. Customer and transaction identifiers, email, product, payment method and status, billing and fraud data. Not yet configured for production Not yet configured for production Not yet configured for production Official policy Not reviewed; feature gated
Google Drive User-selected cloud provider; proposed independent controller for the user's provider account. Authorize and store the converted output selected by the user. Provider account data, authorization metadata, filename, converted file, and upload activity. Not yet configured for production Not yet configured for production Not yet configured for production Official policy Not reviewed; feature gated
Dropbox User-selected cloud provider; proposed independent controller for the user's provider account. Authorize and store the converted output selected by the user. Provider account data, authorization metadata, filename, converted file, and upload activity. Not yet configured for production Not yet configured for production Not yet configured for production Official policy Not reviewed; feature gated

Retention and Deletion

  • Optional history is deleted after 30 days at the latest or immediately when disabled/cleared.
  • Stripe webhook idempotency records are deleted after 90 days.
  • Operational backups are configured to expire after 30 days; deletion propagates as backups rotate.
  • You can export or delete account data held by Loconva from the account page. Active subscriptions must be cancelled first. Payment providers may retain legally required records independently.

Your Rights

Subject to the applicable requirements, you may request access, correction, deletion, restriction, portability, or object to processing. You may also complain to a competent data protection supervisory authority. Contact the controller using the address above.

Verified rights requests are logged, assigned, and answered without undue delay and normally within one month. Recipients are notified of correction, erasure, or restriction where Article 19 GDPR requires it.

Competent supervisory authority: Not yet configured for production

Contact

Questions about privacy? Email support@loconva.com.

Policy version: Not yet configured for production; review date: Not yet configured for production

Loconva

Fast, private file conversion directly in your browser. Your files stay on your device.

Private by design

Product

  • Convert files
  • All formats
  • Pricing
  • API documentation

Company

  • About

Support

  • Help Center
  • FAQs
  • System Status
  • Contact

Legal

  • Imprint
  • Privacy
  • Terms
  • Cancellation

More languages can be added at any time.

Offline storage is optional and starts only when requested.

© 2026 Loconva. All rights reserved.

Made for simple, secure conversions.