Legal
Privacy Policy
Last updated: August 15, 2026.
This Privacy Policy explains what Convyx collects, why we collect it, and how long we keep it. Controllers of personal data for the Service are reachable via contact.
What we collect
- Account data: name, email, and authentication/session tokens. OAuth identifiers are collected only if a social provider is enabled and used.
- Billing data: handled by our payment provider (Polar); we store plan, status, and Polar IDs.
- Conversion data: file names, sizes, formats, status, and storage keys for jobs you create.
- File contents: held only for the retention window you select, then hard-deleted from storage.
- Security metadata: IP address and user agent for abuse prevention and session security.
- API keys: stored as SHA-256 hashes with a short prefix — plaintext is shown once at creation.
How we use data
We use this data to operate conversions, enforce plan limits, deliver webhooks you configure, prevent abuse, and improve reliability. We do not sell personal data. Uploaded files are not used to train models and are not shared with other customers.
Retention & deletion
Conversion outputs expire per your retention setting. You can delete jobs and your account from the dashboard. Account deletion removes API keys, webhooks, subscription links, and stored file objects. Historical conversion rows may remain without the user-account link for aggregate operational statistics; they can include non-content metadata such as format, size, status, and timestamps.
Your rights
Depending on your location you may have rights to access, correct, export, or delete personal data. See also our GDPR overview and security page.