Privacy
Uploaded source and converted output files are kept in private job storage only while needed. The expiry threshold is 15 minutes. Cleanup runs every minute, so inactive jobs are normally removed within the following minute; active work may remain briefly while its process is cancelled and reaped. A successful one-time download or deletion request removes both source and output immediately.
Data handled
- Media bytes and selected output preset.
- Opaque job and access tokens held in volatile memory.
- Client network address used only for in-memory abuse limits.
The MVP has no accounts, analytics, advertising, permanent media library, or URL import. Operational logs must not include media, access tokens, or filesystem paths. A process crash may shorten availability; startup recovery deletes interrupted work.