Skip to main content
Your content. Clear terms.

Privacy Policy

How FileToWeb handles account information, customer documents, AI processing, and published copies.

Effective September 22, 2026 · Version 2026-09-22.1

Our role and this notice

Vinchy Company Inc. operates FileToWeb. This policy explains our personal-information practices; it is not blanket consent to every processing activity. We operate the business as controller of account, billing, support, and necessary security information, and of personal data we lawfully use for independently determined improvement purposes described below. When processing personal data in Customer Content on a customer’s instructions, we act as processor or service provider where those legal roles apply. The customer controls why that content is submitted and published. The Customer Data Processing and Security section of our Terms governs that relationship. An AI provider determining its own improvement purposes has its own applicable controller responsibilities; those uses must meet the conditions described below before they begin.

Where a legal basis is required, we use the basis appropriate to the purpose: performing our contract with an individual customer, legitimate interests in operating and securing the business where those interests are not overridden, legal obligations, and consent for activities requiring it. A subscriber’s acceptance does not constitute consent from every person mentioned in a document.

Information and its sources

Account and administration: registration and contact details, authentication records, workspace membership and permissions, plan and billing metadata, support messages, and relevant security and diagnostic logs. Our authentication service handles passwords; we do not store plaintext passwords. Stripe handles payment details; we receive payment and subscription records needed to operate billing.

Customer Content: source files, extracted text and images, converted output and assets, editing prompts and responses, versions, submitted form data where enabled, and visibility or publishing settings. Integrations may also supply source URLs, external document identifiers, site and workspace identifiers, synchronization metadata, and authentication-related records.

Information can come from you, another authorized workspace member, a connected CMS or API client, a person submitting information through enabled features, and our service providers. Device, browser, IP address, service events, and permitted analytics information may be generated through use of the Service. The Cookie Policy explains browser storage and optional analytics.

Customer Content, Publishing, and Integrations

We retain applicable working materials in the customer’s workspace to provide conversion, editing, versioning, synchronization, and related functionality. A connected website or CMS may separately store exported output. These copies have separate lifecycles.

New web documents default to Public unless a saved workspace default or an explicit creation choice selects Private. Review the visibility choice before submitting content. With Public selected, published output, assets, and available downloads can become accessible through public links when the workflow completes, without another publication confirmation. Anyone who obtains a public link can access the content; it may be copied, redistributed, or indexed. An unlisted address is not a private access control. Select Private before submitting content that must remain restricted. Public visibility does not grant workspace or editor access. Tabular documents use separate access controls. Existing documents and saved Private defaults retain their settings, including after subscription cancellation. APIs and automated workflows follow their explicit choice or applicable default.

Deleting or withdrawing a FileToWeb copy does not necessarily remove exported files, CMS copies, caches, or copies retained by recipients. Withdrawing a customer website page does not itself withdraw a separately public FileToWeb page. Customers should manage both publishing destinations. Customer websites have their own privacy practices. Embedded FileToWeb functionality or remotely served assets can make requests to FileToWeb or its infrastructure; local hosting alone does not guarantee that no requests occur.

AI processing and data use

Relevant source content, extracted text or images, prompts, instructions, and output may be sent to the AI or execution providers used by the selected feature to generate or edit content. Under the standard Terms, FileToWeb may use Customer Content first submitted under this version to evaluate, test, develop, train, and improve its accessibility, document-conversion, and editing workflows and their supporting AI systems and models. We may also authorize AI service providers to use relevant content to train and improve their own workflows and supporting models. These uses may include authorized human review, evaluation datasets, and model training or fine-tuning. They can apply to both Public and Private content; selecting Private restricts public access and does not by itself exclude permitted improvement processing.

Contractual permission is distinct from the legal basis required for personal-data processing. Where permitted, improvement may rely on legitimate interests in improving accessibility and service quality only after assessing necessity, reasonable expectations, and the effect on individuals and their rights; where consent is required, we obtain it separately first. We give applicable purpose, recipient, retention, rights, and transfer information before a new independent provider use begins. A provider is not authorized to train on Customer Content merely because it supplies infrastructure or inference. Personal data restricted to processing on a customer’s behalf is excluded from independent improvement unless a lawful arrangement permits it. Otherwise, improvement uses data that is not personal or confidential, including data lawfully anonymized for that purpose. Acceptance by a subscriber does not waive other people’s rights. Prior content remains subject to the earlier permissions unless the necessary additional authorization is obtained. Continued use of an existing API key does not itself grant expanded improvement permissions; content submitted before the required acceptance or other valid authorization remains subject to the previously applicable permissions.

Inference, temporary processing, provider abuse monitoring, and authorized operational or support access are distinct from model training. Provider retention and processing locations depend on the service, deployment type, feature, and configuration. We do not promise zero retention, no human access, or exclusively United States processing. Contact us before submitting data subject to requirements needing a particular region, retention period, or contractual arrangement.

Operational measurements used to improve reliability include timing, errors, resource use, and credit consumption. Document content and editing prompts are not treated as unrestricted analytics data. PostHog session replay and associated product events are enabled by default in signed-in workspaces to help us understand navigation and diagnose usability issues. Rejecting optional analytics in Cookie settings turns them off; saved rejections and supported browser privacy signals are honored. Inputs and page text are masked, and embedded documents, media, console logs, and network request contents are excluded from these application recordings. Google Analytics and marketing-page analytics still require an affirmative choice.

Service providers and disclosures

Depending on the enabled feature, we disclose information to the following categories of technology and business service providers. Each receives information needed for its role: AI inference and model-processing providers receive relevant source content, images, prompts, instructions, and output; cloud computing and isolated execution providers process working files and instructions for conversion and editing; hosting, content-delivery, storage, and security providers process relevant files, output, and request information; authentication and database providers process account records, workspace metadata, and applicable service data.

Analytics providers process optional browser product analytics and separately generated operational events. Error-monitoring providers process diagnostic and service-reliability information. Transactional email providers process recipient information and message content to deliver service messages. Stripe processes payments and related customer and billing information. Optional browser analytics remain subject to your cookie preferences.

For the current providers relevant to your use of the Service, including their identities, locations, and processing functions, contact support@filetoweb.com. We make that information available to Customers for applicable subprocessor review and authorization and identify recipients in response to privacy requests where required by law. We provide required provider-specific information before any new independent use of personal data for training or improvement begins.

Infrastructure and provider services can process information in the United States and other countries depending on the service, deployment, and configuration. We use appropriate contractual and other safeguards where required; this notice is not consent to an otherwise unlawful transfer. Contact us for applicable processing-location and transfer information. We give affected Customers advance written notice of intended subprocessor additions or replacements involving Customer Content and an opportunity to object as described in the Terms.

We may also disclose information on customer instructions, for the permitted improvement purposes above, to comply with law, protect rights and security, or in a business transfer subject to applicable safeguards. The standard improvement permission does not authorize selling personal data or sharing it for cross-context behavioral advertising. We do not enable a provider arrangement requiring additional sale or sharing notices, choices, or authorization until those requirements have been met.

Retention, deletion, and security

Active workspace documents and editing history: retained while needed for the requested service, until customer deletion, workspace closure, or an agreed retention rule. Cancellation of a subscription is not a deletion request. Temporary processing materials: retained for the processing, recovery, and troubleshooting needs of the relevant job and removed through the applicable cleanup process. Temporary and provider-side storage may have different lifecycles.

Deleted documents and workspaces: active-record deletion initiates associated storage cleanup. Processing already in progress and cleanup failures can delay completion and require retries or operational follow-up. Contact support for status. We do not represent a universal fixed deletion deadline in this policy. Where return or deletion is required by the customer-data terms, we carry it out subject to legally permitted exceptions.

Permitted improvement datasets: limited to the content needed for the stated evaluation or training purpose and retained only while needed for that purpose, subject to applicable legal and contractual limits. We establish the applicable dataset and provider retention rules before using personal data for a new independent improvement purpose. Contact support for details or a rights request. Deleting a document does not necessarily reverse learning already incorporated in a trained model; we remain responsible for legally required deletion and remediation, including in relation to models where applicable.

Backups: deleted information may remain in restricted backups until the relevant backup cycle expires. It is not used for ordinary service purposes, and applicable deletions must be reapplied when restoring a backup. Security and diagnostic records: retained according to investigation, security, troubleshooting, and accountability needs. Billing and legal records: retained as required for taxes, accounting, disputes, and other legal obligations. Contact us for deployment-specific retention details or to establish a required retention schedule before using the Service.

We use safeguards including encryption in transit, authentication, and access controls. Authorized personnel may access information for necessary operations, requested support, and security investigations, subject to access restrictions and confidentiality. No system is absolutely secure.

Your choices and rights

Depending on applicable law, you may have rights to access, correct, delete, export, restrict, or object to processing of personal information, withdraw consent, and complain to your data-protection regulator. Contact support@filetoweb.com. We may verify identity and authority. Withdrawal does not affect the lawfulness of earlier processing.

For information in customer-controlled documents, contact the publisher or workspace customer where possible. We can help route requests and cooperate with the customer, while meeting obligations that apply directly to us. We do not treat the customer relationship as an exception to our own legal duties. Cookie preferences control optional browser analytics; marketing opt-outs do not stop essential account, security, and billing messages.

Children, changes, and contact

Accounts are intended for people aged 18 or older. Customer documents may contain information about children when the customer is authorized to submit it; that differs from a child registering for an account. Contact us about an underage account or a concern involving a child’s information so we can assess and respond appropriately.

We provide email or in-product notice of material changes before they take effect where required, and obtain additional authorization where necessary for a new processing purpose. We retain historical privacy notices for accountability. Contact support@filetoweb.com if you need information about a notice that applied to your data.

Contact Vinchy Company Inc. at support@filetoweb.com.