Privacy Policy
August 28, 2026
FileBench ("FileBench", "we", "us") provides free online tools to convert, compress, edit, inspect, and manage files at filebench.app. This page describes what information FileBench actually processes to do that — written to match how the product actually works, not a generic template.
Most of FileBench works without an account. Creating one only extends how long your files are kept and unlocks account features like a file library, saved workflows, and share links.
Account information
If you create a FileBench account, we process the information needed to run it:
- Your email address and password (stored as a salted, one-way hash — we cannot read your password).
- Your account identity (an internal account ID) and any optional profile details you choose to set, like a display name.
- Authentication and session information — a session cookie and its associated login records (see "Cookies" and "Logs" below) — used to keep you signed in and to let you review or revoke your own active sessions.
- If Google sign-in is enabled for your account: your Google account ID, email address, name, and profile picture (if available), shared with FileBench by Google when you choose to continue with Google. FileBench uses this only to create or sign in to your FileBench account, never to access your Gmail, Drive, Calendar, Contacts, or any other Google data, and never for advertising.
Files you upload
You upload files to FileBench so we can run the specific processing operation you request — converting, compressing, editing, inspecting, or otherwise transforming that file. Files are private by default: nobody else can see or download them unless you deliberately create a share link (see "Share links" below).
Uploaded files, and the output files a processing job produces, are kept only temporarily:
- Guest uploads (no account): kept for approximately 1 hour after upload, then deleted.
- Registered accounts: kept for approximately 7 days, then deleted.
Deletion runs on a recurring automated schedule, not the exact instant a file's retention window ends — there can be a short delay between a file becoming eligible for deletion and the cleanup process actually removing it. Output files you generate follow the same retention window as the file they came from.
Private storage and temporary links
Uploaded and generated files are stored in private cloud object storage — the storage bucket itself is not publicly browsable or listable. When your browser needs to upload a file or download a result directly, FileBench's server generates a temporary, cryptographically signed link (a "presigned URL") scoped to that one file and valid for a limited time. We don't publish the storage credentials that create those links, and this policy doesn't describe our infrastructure setup beyond that high level.
How your files are processed
Uploaded files are processed automatically by FileBench's own backend infrastructure, using standard media and document tooling appropriate to the operation you request — for example FFmpeg for audio/video, image-processing libraries for pictures, PDF tooling for documents, and OCR (text recognition) for scanned pages. Processing is automated: FileBench staff do not manually open, view, or review the content of your files as part of normal operation.
Security scanning
FileBench performs a basic, automated file-type check on uploads (confirming the file actually is the format it claims to be) so it can offer the right tools — this is a technical check, not a review of your file's contents.
FileBench's codebase includes optional malware-scanning support (ClamAV) that can be enabled per deployment. As of this policy's last-updated date, malware scanning is not active in FileBench's production environment. If that changes, uploads would be scanned automatically before processing, and this section will be updated to say so.
Logs and security telemetry
Like most web services, FileBench's infrastructure records standard operational information to keep the service running and secure:
- IP address and browser user-agent string, associated with login sessions and rate-limiting.
- Request and error logs, and timestamps, generated by normal server operation.
- Security-relevant account events — sign-in, sign-out, session revocation, password/Google-account linking — kept as an internal audit trail.
- Content-Security-Policy violation reports, a standard browser security mechanism that helps us notice broken or malicious scripts on the site.
We don't collect device fingerprinting, precise location, or any browser/device details beyond what's listed above.
Analytics
FileBench runs its own first-party, self-hosted product analytics — for example, which tools get used and whether a conversion completed — stored in FileBench's own database. There is no third-party analytics, advertising, or tracking service (no Google Analytics, no ad pixels, no cross-site tracking) installed on FileBench.
Data retention, summarized
Account information and uploaded files are retained on different schedules:
- Uploaded/generated files: deleted automatically per the guest (~1 hour) or registered (~7 days) windows described above.
- Account information (email, account ID, session/security history): kept for as long as your account exists.
Deleting an individual file does not delete your account, and deleting your account does not necessarily happen instantly — see "Your rights and choices" below for how to request either.
Third-party services we use
Running FileBench relies on a small number of infrastructure providers, in these categories:
- Cloud compute infrastructure, to run FileBench's servers.
- Cloud object storage, to hold uploaded and generated files privately (see "Private storage" above).
- Google, as an optional authentication provider — only if Google sign-in is enabled (see "Account information" above).
FileBench does not currently use an email-delivery provider (no account/marketing emails are sent) or any payment/billing provider — FileBench has no paid plans or subscriptions.
Your rights and choices
Whatever privacy law applies to you, FileBench aims to make the following straightforward without requiring a formal legal process:
- Access — ask what account information we hold about you.
- Correct — update your account details (display name, email) yourself, or ask us to.
- Delete files — remove any individual file, or your whole file library, from your file library page at any time.
- Delete your account — request deletion of your account and its associated information.
- Ask a question — contact us at the address below with any privacy question.
FileBench does not claim certification under, or guaranteed coverage by, any specific privacy law (for example GDPR or CCPA) — this section describes what we actually offer, not a legal compliance guarantee.
Changes to this policy
If FileBench's practices change in a way that affects this policy, we'll update this page and its "last updated" date above.
Contact
Privacy questions or requests: support@filebench.app.