← WebP to PNG Online

Privacy Policy

Read how WebP to PNG Online handles local images, temporary memory, website requests and optional preferences. Review analytics controls and privacy choices.

catalog.project.com@gmail.com

Privacy Policy: Files & Data | WebP to PNG Online
A laptop and botanical image cards on one desk represent a local image workspace.Original concept illustration. It explains the workflow; it is not a measured conversion result.
A practical field guide

Privacy Policy: the actual data flow

Read how the service handles images, local preferences, website requests and your choices.

10 sections7 min readUpdated

Read how WebP to PNG Online handles local images, temporary memory, website requests and optional preferences. Review analytics controls and privacy choices.
Botanical image cards are grouped in a green folder with a zipper, with individual files alongside.Original concept illustration. It explains the workflow; it is not a measured conversion result.
In this guide +

Service and contact

These documents describe WebP to PNG Online, a browser-based service for converting still WebP, PNG and JPG images. For questions about these policies, privacy choices or the converter, use the support address on the Contact page. Describe the issue without sending private images, filenames or image metadata.

The sections below explain actual image processing, browser storage and optional privacy choices. Cookie agreement controls optional purposes; it does not accept the Terms or grant rights to your images. You can revisit Cookie Settings and contact support without sharing an image or account credentials.

Images are processed in your browser

After you choose, paste or drop a supported file, its bytes, filename and pixels are read locally. Native browser decoding, worker canvases and the self-hosted WebP WASM codec run on your device. ZIP creation also happens locally. Source files, output files, alpha, EXIF/GPS/XMP, canvas pixels, thumbnails, clipboard contents, job identifiers, blob/data URLs and ZIP contents are excluded from server, analytics and advertising requests.

The page requests its HTML, styles, illustrations, scripts, codecs and a first-party regional-policy response. These ordinary requests disclose connection information to the infrastructure. Local conversion therefore does not mean that opening the website creates no network traffic. No upload endpoint or server image store is part of this release.

Memory, deletion and downloaded copies

Selected files, previews and completed results stay in page memory while you work. Removing an item or using Clear all releases its tracked previews; workers are terminated and canvas/bitmap resources are released when processing finishes or is cancelled. Reloading or closing the page discards the working queue. Images are not saved in localStorage, IndexedDB, Cache Storage or session replay.

A download URL is retained for about 30 seconds to allow the browser to start saving, then revoked. A downloaded image or ZIP is managed by your browser and operating system, and may be copied by your backup or synchronization software. Clearing site data does not delete downloaded copies or guarantee erasure from operating-system memory. Ordinary application assets may be cached independently of your images.

EXIF, GPS, color profiles and what is not preserved

The output is a newly encoded image. Original EXIF, GPS and XMP records are not copied; an encoder may add its own technical fields. Orientation is applied to the image rather than relying on the original orientation tag in the download. Keep the original if you need camera settings, capture dates or an archival record.

Working pixels use an sRGB canvas where supported. Exact source ICC profiles, HDR information and 16-bit precision are not retained. A screen that looks similar is not proof of identical color data. For calibrated print, scientific measurement or preservation of high-bit-depth originals, use a workflow designed for those requirements.

Optional preferences are separate from files

Remember language stores only the selected EN, ES or PT-BR locale and expiry. A later visit can offer that language; an explicit page URL is respected. Remember tool settings stores the output pair, JPG/WebP quality, JPG background and expiry for each supported tool. The output format still follows one of the six registered routes, never an arbitrary encoder. No selected filenames, previews or queue are included.

Browser storage can be blocked. In that case the decision remains effective on the current page and a localized message explains that it could not be saved. Cross-tab notifications share privacy choices within this host, not image data or visitor IDs. Consent is not shared with other sites in the owner’s network. Deletion affects only this site’s known preference keys, not unrelated storage.

Before a choice, after Agree and after refusal

Unknown regional applicability uses the strict profile. This build has no enabled analytics or advertising provider, so before a choice it makes only necessary delivery requests. The aggregate-only fallback does not install a client counter or claim that host analytics have been configured. Existing necessary infrastructure operations may have their own operational statistics; the operator must confirm their actual details.

Agree enables only the disclosed available optional purposes: in this build, remembering language and tool settings. Save preferences enables only the selected options. Reject optional stops all optional purposes. Closing the panel, changing a tab, continuing to convert or following a link is not consent. Advertising permissions are separate from analytics and cannot override an applicable Global Privacy Control restriction.

Cookie Settings in the footer reopens your current decision. Changes apply without reloading and do not reset files, conversions or results. Withdrawing permission removes known saved optional preferences but keeps current settings and work in memory. Refusal is remembered for the same 180-day project interval as agreement. Information already transmitted by a provider cannot be recalled by a browser switch.

Regional measurement and safe events

The integration boundary supports consent-required, aggregate-only and reviewed GA4 Advanced modes. Geography comes only from trusted hosting infrastructure, not URL language or a client country selector. Without an approved configuration, no third-party pre-consent pings are enabled. A cookieless request can still contain connection or device information and is not automatically anonymous or exempt.

If an approved GA4 deployment is enabled later, denied consent defaults precede configuration and events. Safe events describe tool views, file selection counts, conversion starts/results/errors and download/ZIP actions using only registered tool, locale and format values and broad size/duration buckets. Canonical page paths exclude queries and fragments; referrers are reduced to their origin. Filenames, image bytes, EXIF, canvas, blob/data URLs, job IDs, signed URLs and clipboard text are forbidden. Automatic download, click and form measurements must be disabled in the GA4 stream before activation.

After explicit rejection or disabling measurement, future optional events stop, pending events are discarded and loaded GA4 is disabled. Merely denying analytics storage would not enforce this product rule. No pre-consent action history is saved for later association with a new identifier. Google Signals, advertising personalization, User-ID, fingerprinting and cross-domain decoration are not enabled by analytics agreement.

Infrastructure, recipients and international processing

The requested website is delivered by its hosting infrastructure, which receives IP address, request path and ordinary HTTP information. The local preview does not add request analytics or application logging. Cloudflare Static Assets is the prepared deployment target, but the actual production account, hosting regions, subprocessors, security logs and retention have not been confirmed. No claim is made that all processing remains in one country or the EU.

Analytics, advertising, optional client diagnostics and external embeds are disabled in the delivered build. The Vendors panel lists actual available services, not a hypothetical cookie catalogue. If Google Analytics is configured after review, Google becomes a disclosed recipient of safe analytics and connection information, with international processing subject to its terms and the operator’s applicable safeguards. Ads require their own verified certified CMP integration; four Consent Mode flags alone do not activate AdSense.

Rights, support and requests

Depending on the applicable law and circumstances, you may have rights to access, correct, delete or restrict personal data, receive a portable copy, object to processing, withdraw consent and complain to your competent supervisory authority. Optional permission can be withdrawn through Cookie Settings. Necessary delivery and security processing is separate; its actual legal basis and retention must be confirmed by the operator, not inferred from a consent button.

There is no upload form or account support history in this version. If you contact an available support address, the recipient and email provider may process your message and return address for responding. Do not send private images, EXIF, access tokens or sensitive filenames to support; explain the problem with a harmless example. Actual support providers, lawful bases and retention are operator details still awaiting confirmation.

Security, audience and policy changes

The implementation uses format checks, resource limits, same-origin codecs and a restrictive content security policy. These safeguards reduce risk but do not guarantee complete anonymity, perfect security or that extensions and operating systems never access your data. Keep original files, use a supported updated browser and check output before relying on it. The service is not designed specifically for children; the operator must finalize any applicable age and parental-contact arrangements without assuming a universal age threshold.

The displayed update date identifies this revision. New optional purposes start disabled and require a new decision only for the newly introduced purposes; an existing refusal is not reset on every visit. Changes to providers or data handling require corresponding registry and document updates before activation. Review the current documents when the service changes.