Privacy Policy
This Privacy Policy explains how AllFileCompressor processes personal data. It matches the live product: browser-only file tools, consent-gated analytics, optional location, and free-usage limits.
Last updated: 28 August 2026
Who we are
AllFileCompressor is an independently operated online service available at allfilecompressor.com. For privacy and data-protection requests, contact allfilecompressor@gmail.com.
How your files are processed
Compression and conversion for PDF, images (JPG, PNG, WebP, HEIC), MP4 video, audio (MP3/WAV), ZIP, PDF↔image, and MP4→MP3 run in your browser on your device. Your file contents are not uploaded to our servers for processing, and we do not keep copies of your files in our application database. The browser may download technical libraries (for example FFmpeg WebAssembly from jsDelivr, or PDF.js worker assets from a CDN) to run those tools locally. If you have accepted analytics cookies, the site may send tool metadata only — tool id, approximate input/output sizes in bytes, duration, and error messages — not file contents.
Cookies & similar storage
We use first-party cookies for: analytics/cookie preference (afc_cookie_consent); optional location-prompt state (afc_location_state); a device identifier for free usage limits only (afc_did, HttpOnly); local usage counters; UI locale and theme; and an optional local Pro flag. Accept means you consent to optional analytics cookies (Google Analytics and our first-party analytics). Accept is not GPS consent. Reject keeps essential tools and usage-limit cookies working without loading Google Analytics or first-party analytics. You can change or withdraw analytics consent anytime via Cookie settings in the footer. Session storage may briefly hold afc_consent_id (internal id only).
Optional approximate location (GPS)
GPS is optional. We never request geolocation on page load. Cookie Accept alone is not GPS consent. GPS runs only if you click Use My Location and grant browser permission. Latitude/longitude are processed temporarily only to reverse-geocode approximate City, State/Region, and Country, then precise coordinates, accuracy, exact address, and map location are discarded and are not intentionally persisted by the application.
If you choose “Not now”, we do not collect approximate location through this optional location feature. If you actively choose “Use My Location” but GPS is unavailable, times out, or technically fails, we may temporarily process your client IP to derive an approximate City, State/Region, and Country. The raw IP is discarded after the lookup and is not intentionally persisted as part of the location feature. Denying browser GPS permission after clicking Use My Location also means we do not collect approximate location via this feature.
Location/consent records keep only: approximate City, State/Region, Country/country code; source (GPS or IP fallback); permission/location status; cookie consent status; UI locale; timestamp; and internal consent record id.
Security, abuse prevention & usage limits
Separately from optional analytics, free-tier limits (/api/usage) may process your public IP in memory and store only a keyed HMAC (pseudonymous) representation of that IP together with a device id cookie (afc_did), tool feature id, and timestamp. This enforces up to 3 uses per tool in a rolling 24-hour window and helps prevent abuse (for example wiping cookies to reset limits). The HMAC secret stays on the server and is never sent to the browser. We do not store the raw IP in usage records. Usage-limit rows are automatically deleted after 48 hours. This processing is essential to operate fair free limits and is distinct from optional analytics.
Analytics (consent required)
Google Analytics (G-Q2WGX7ZEJM) and our first-party analytics load or record only after you Accept optional analytics cookies. Before Accept, and after Reject or withdrawal via Cookie settings, Google Analytics scripts are not loaded and first-party analytics events are not sent. First-party analytics store page path, title, locale, event type, tool feature id, success/failure, duration, input/output byte sizes (not file contents), error messages, and referrer — not raw IP and not device id. Google Analytics may set Google cookies and process technical data under Google's terms once consented.
Accounts, reviews & support
If you create an account, Supabase Auth stores your email, hashed password, and optional full name. Optional star ratings may store stars, tool/feature id, page path, locale, and — when logged in — user id/email/name. Ratings do not store raw IP. Support emails go to our inbox and are not stored as an app database table.
Categories of personal data
Depending on use: identifiers (email, account id, usage device id); contact details; technical data (locale, paths; IP processed briefly for usage HMAC or temporary location lookup); approximate city/region/country if you use optional location; consented analytics events; ratings; cookie preferences. We do not process your file contents on our servers.
Purposes & legal bases
We process data to: provide browser tools; remember preferences; enforce free usage limits and prevent abuse (necessary for the free service / legitimate interests); operate accounts (contract / steps at your request); send OTPs (contract / legitimate interests); run Google Analytics and first-party analytics only with your prior consent for non-essential cookies/storage; and process optional approximate location after Accept plus, for GPS, your voluntary click and browser permission (consent). Consent is freely given, specific, informed, and withdrawable.
Retention periods (automatic)
Automatic deletion runs hourly in production (and opportunistically on writes): feature_usage 48 hours; first-party analytics (page/tool/error) 14 days; visitor_consents (cookie + approximate location) 60 days; tool_reviews 180 days. Consent cookies up to 1 year (or until cleared). Device id cookie (afc_did) up to about 400 days. Account data while the account exists, or until deletion request. Support emails per normal mailbox practice. OTPs expire in minutes. Narrow exception: we will not auto-delete a record that is genuinely required for an unresolved security incident, fraud investigation, dispute, or legal obligation.
Service providers & third parties
Supabase (auth/database); Netlify (hosting/CDN); Google Analytics (after consent); Gmail/SMTP (OTP/support); OpenStreetMap Nominatim (temporary GPS reverse-geocode); ipwho.is, ipapi.co, and geojs.io as a sequential fallback chain for temporary IP place lookup (first successful provider wins); jsDelivr (FFmpeg core) and CDN hosts for PDF.js workers.
International transfers
Providers may process data in the United States or other countries. Where GDPR/UK GDPR applies, we rely on each provider's applicable transfer safeguards (such as Standard Contractual Clauses). Contact us for details about a specific transfer.
Your rights (including GDPR / UK GDPR)
Where applicable you may access, correct, delete, restrict, or object to certain processing; request portability; and withdraw consent anytime without affecting prior lawful processing. Use Cookie settings to change analytics consent; skip or deny location; clear cookies; revoke browser location permission — core tools still work. Email allfilecompressor@gmail.com with Privacy request. You may complain to your supervisory authority (for example an EU/EEA DPA or the UK ICO).
Consent, refusal & core tools
Rejecting analytics cookies, skipping Use My Location, or denying GPS does not block core compression/conversion. The usage-limit device id and HMAC-based limit checks remain so free-tier limits stay fair. Withdraw analytics anytime via Cookie settings.
Infrastructure & security logs
Netlify, Supabase, and similar hosting/CDN/security systems may independently log IP addresses, timestamps, and request metadata. Our location feature does not intentionally persist raw IP or GPS coordinates, and usage stores an HMAC instead of raw IP, but we do not claim infrastructure logs never retain IPs.
Contact & complaints
Privacy requests: allfilecompressor@gmail.com (subject: Privacy request). EU/EEA/UK users may also contact their supervisory authority.
Changes to this policy
We update this policy when the product or legal needs change. The Last updated date at the top will change. Please review it periodically.