privacysecurity

The Privacy Risk of Free Online File Converters

Uploading a file to a free online converter sends it to a third-party server. Here's what Smallpdf, ILovePDF, and similar tools do with your documents.

You need to convert a PDF to a Word document. A quick search returns half a dozen free tools. You upload the file, download the result, and close the tab. Quick and useful. What most people don’t think about is that their document just traveled to a server they know nothing about, owned by a company they’ve never heard of, operated under terms they didn’t read.

Online file conversion tools are used by hundreds of millions of people. PDFs become Word documents, images become compressed JPEGs, audio files get reformatted, spreadsheets are converted to CSVs. The documents being uploaded represent some of the most sensitive material people handle digitally: tax returns, contracts, medical records, identification documents, legal correspondence.


How These Services Actually Work

Online file converters operate by receiving your uploaded file, processing it on their servers using the conversion software they run, and returning the result. The conversion itself is cloud-based by necessity — the processing happens on their infrastructure, not yours.

When you upload a document, several things occur:

  1. Your file is transmitted to the service’s servers over HTTPS (encrypted in transit on reputable services)
  2. The file is stored temporarily on their servers while processing occurs
  3. The converted file is generated and made available for download
  4. Your original file and the converted output sit on their infrastructure for some period of time before deletion

The critical variable is that third step: “some period of time.” How long that is, what happens to the file during that window, who can access it, and whether deletion is actually permanent all depend on the service’s policies — and those policies vary significantly.


What the Major Services Say About Your Files

Smallpdf is one of the most widely used PDF conversion tools globally. Its privacy policy states that uploaded files are processed and then deleted after a set time period, which has historically been around one hour on the free tier. Smallpdf is based in Switzerland, which means it operates under Swiss data protection law (aligned with GDPR) and cannot be compelled to produce user data by US government demands as easily as a US-based provider.

ILovePDF is a popular alternative, headquartered in Spain and therefore subject to EU law and GDPR. Its privacy policy states files are deleted after two hours. It does not claim to use file content for training or product improvement.

Adobe Acrobat Online (the free web tools) operates under Adobe’s broader privacy policy. Files uploaded to Adobe’s conversion tools are processed on Adobe’s infrastructure. Adobe has AI features integrated across its products, and its terms of service have historically included language that researchers flagged as potentially permitting use of uploaded content for AI training — though the company has updated these terms multiple times. If you’re uploading a sensitive document to any Adobe online tool, reading the current version of their terms before doing so is worthwhile.

Zamzar is a UK-based conversion service. Its free tier retains files for 24 hours. Zamzar’s terms of service are relatively plain — the company states files are used only for conversion and deleted after the retention period.

Online-Convert.com is operated by a German company. Files are reportedly deleted within 24 hours. Being EU-based provides some regulatory baseline.


The Services That Don’t Make It Clear

The larger concern isn’t the established, named services — it’s the long tail of conversion tools that rank highly in search results but have opaque privacy practices.

Searching for “convert PDF to Word free” returns dozens of results. Many are operated by entities with minimal public information: no named company, no verifiable address, no meaningful privacy policy beyond boilerplate text. Some appear to be operated from jurisdictions with minimal privacy law.

When you upload a document to one of these services, you have no meaningful way to know:

  • Where the server is physically located
  • Whether the file is retained after your session
  • Who has access to the server and the files on it
  • Whether the file is scanned, indexed, or used in any way beyond the conversion

This is not a hypothetical risk. Researchers have found file conversion services that retain uploaded documents in accessible storage buckets, some exposed to the open internet. In one documented case, a database of files converted through a popular-seeming tool was discovered publicly readable, containing user-uploaded documents including financial records and personal identification.


Which File Types Carry the Most Risk

Not all conversions carry equal exposure. The sensitivity calculates based on what the document contains:

High sensitivity: Tax documents, government IDs, passports, birth certificates, medical records, legal agreements, financial statements, contracts with personally identifiable information, confidential work materials.

Moderate sensitivity: Work documents without confidential client data, professional correspondence, presentations, academic materials.

Lower sensitivity: Images of non-personal subjects, public documents, creative files with no personal information, general-purpose files you’d be comfortable sharing publicly.

If the file you’re converting falls into the high-sensitivity category, the convenience of a free online tool is rarely worth the exposure. The risk is not purely theoretical: converted medical documents or financial records on a compromised or negligent server create the conditions for identity theft, insurance fraud, or targeted phishing.


Retention Periods and What Deletion Means

Most reputable conversion services publish retention periods: files are deleted after one hour, two hours, or 24 hours, depending on the service and subscription tier. This is meaningful — shorter retention reduces the window during which a breach, a legal demand, or a human error could expose your file.

However, “deleted” in cloud storage terms is not always the same as “gone.” Cloud storage systems typically operate with backups, snapshots, and caching layers. A file that’s been “deleted” may persist in a backup copy for additional days or weeks before those backups rotate. If you upload a sensitive document to a conversion service and delete it — or simply wait out the retention period — the file may not be immediately unrecoverable.

The leading services are generally transparent about their retention practices and operate systems that comply with GDPR deletion requirements. Lesser-known services may not.


Safer Alternatives

Use desktop software. Microsoft Word can open and convert most document formats without any upload. LibreOffice (free, open source) handles a wide range of conversions including PDF to editable formats, entirely locally. Apple Preview can convert PDFs and images. For audio and video, VLC and ffmpeg are capable local converters.

Use built-in OS tools. macOS can export to PDF from any application via the Print dialog. iOS and Android can produce PDFs natively. For images, both platforms include basic format conversion tools.

Use a trusted paid service for sensitive files. Smallpdf and ILovePDF both offer paid subscriptions with stronger data handling commitments and GDPR compliance. If you regularly need to convert sensitive professional documents, a paid subscription to a reputable EU-based service is a more defensible choice than a free tool of unknown provenance.

Store files in a private system before converting. Keep your sensitive original files in a private, encrypted storage system. Convert only the specific version you need for sharing or compatibility, not the original with maximum detail.

The pattern to avoid is the reflexive search-and-upload: encountering a file format issue and uploading the first free tool that appears. That habit, at scale, moves sensitive documents through dozens of unknown servers over the course of a year. Most of the time nothing happens. The times when something does happen — a data breach, a misconfigured server, an unscrupulous operator — tend to be the times you most wish you’d used local software.

For truly sensitive documents, do the conversion locally. The software has existed for decades.

Your memories deserve better than an ad platform.

Try daftei free →
← All posts