Privacy Policy
Last updated: 1 October 2026
This Privacy Policy explains how filehugger.com ("we", "us"), operated by Brothers IT Yazılım Arge ve Bilişim Hizmetleri Tic. San. Ltd. Şti., handles information when you use filehugger.com.
1. How your files are handled
Depending on the tool, files are processed either directly in your web browser or on our servers. Files sent for conversion are used solely to perform the conversion you requested: they are not read for any other purpose, not shared with third parties, and are deleted automatically after processing. Converted files may be held in your browser's local storage (IndexedDB) so their matching download page can offer them to you for up to two hours. Expired results are deleted when you next use the site; you can also clear this site's browser data at any time. When you choose a file on the home page, the original may also be placed in IndexedDB as a short-lived, on-device handoff to the converter you select; that staging record is deleted when the tool opens and is also purged when the home page is loaded again.
For Office, HTML and PDF/A conversion, our application proxy holds the upload in memory while the Gotenberg engine runs and Gotenberg removes its per-job working files when the job completes. For video and audio conversion, the upload streams into a randomly named, permission-restricted operating-system temporary directory; input is capped at 100 MB, output at 160 MB, the selected stream at 10 minutes, and the complete request at an 8 minute deadline. FFmpeg/ffprobe run only for that job. Normal cleanup removes the directory after the response finishes, fails, is cancelled or times out. If the process is forcibly terminated, startup and five-minute sweeps remove the abandoned directory once it is older than the request-wide deadline; media files are never intentionally retained. File names are sent in a request header rather than the URL so they do not appear in ordinary URL access logs.
The File Intelligence tools first produce a deterministic report in your browser. On tools that offer an optional AI second opinion, nothing is sent unless you press the separate AI button. That action sends extracted document text and, where relevant, your question to our server and then to the configured AI provider; it does not send the original file. The API request asks the provider not to store the generated response, but provider-side retention and abuse-monitoring rules may still depend on our account configuration and current provider terms. Do not use the optional AI step when your policy prohibits third-party processing.
Studio workspaces
The online file virus scanner sends the selected file (up to 25 MB) to our own ClamAV service when you press Scan file. The application uses temporary memory, and the engine removes its working files from isolated temporary storage after processing. Uploaded files are inspected without being executed. Neither files nor reports are intentionally retained, published or sent to third-party analysis services; the original file name stays in your browser. The result is returned to your browser and can be downloaded locally. Abuse-prevention counters use the request IP address and expire after an hour, with expired entries removed by a sweep every minute. Technical access logs follow the log-data policy below.
CV drafts, PDF drafts, design projects, image edits and HTML designs are stored in this browser’s IndexedDB until you delete them or clear site data. PDF editing and printable 3D reliefs run on your device. These tools do not upload their source files. Export a project backup to move an editable draft to another browser.
The Word, spreadsheet and presentation editors send documents to this workspace server and its configured ONLYOFFICE engine. The workspace keeps your documents until you delete them; the document engine also maintains temporary editing caches. The document library keeps the PDFs you explicitly publish until you delete them. Unlisted PDFs are accessible to anyone who knows their link; public PDFs also appear in search. Revoking a link prevents future downloads but cannot remove copies already downloaded by others.
Workspace accounts store a username, a salted password hash and a hash of the recovery code. Passwords are never stored in plain text. Necessary HttpOnly, SameSite cookies authenticate sessions for up to 30 days; production cookies require HTTPS. You can sign out all devices, replace your password with a one-time recovery code, or delete your account and its server files from the account menu. Clearing a cookie signs you out; your account still owns its documents. Anonymous local development sessions remain tied to that browser.
Object reconstruction sends the selected image to this workspace’s TripoSR process. Inference runs offline. Queued jobs survive server restarts. Job images and meshes are removed 24 hours after completion, cancellation or failure, with cleanup running every minute. Processing has a 15-minute deadline. Studio editor pages do not load third-party advertising or analytics scripts.
Reports about published documents are available to designated workspace moderators. Moderators can review reported documents and block or restore access. Security audit events contain account identifiers, action names and document identifiers, and are retained for 90 days. Request throttling counters are kept in server memory. Local operator backups may retain earlier copies until those backups are removed; the operator controls backup retention.
2. Information we collect
Beyond the file handling described above, the data we process is standard website usage data:
- Usage analytics. We collect anonymous page-view data (pages visited, referrer, device type, campaign parameters) through a self-hosted analytics system and Google Analytics 4. This helps us understand which tools are useful.
- Advertising data. We show ads served by Google AdSense and measure ad traffic with Microsoft Advertising (UET). These services may use cookies and similar technologies as described below.
- Log data. Our web server records standard request logs (IP address, user agent, requested URL) for security and operations.
3. Cookies and consent
We use cookies and local storage for: remembering your theme and cookie choices, analytics, and advertising. If you visit from the European Economic Area, the United Kingdom or Switzerland, personalised advertising and analytics storage are disabled by default (Google Consent Mode v2) until you make a choice in the consent banner. You can change your choice at any time by clearing the site's cookies. Where consent is declined, Google may show non-personalised ads which rely on essential cookies only. See our Cookie Policy for details.
4. Advertising
We display ads from Google AdSense to keep the tools free. Google and its partners may use advertising cookies (including, with your consent, personalised advertising based on your interests). You can manage Google ad personalisation at adssettings.google.com. A list of Google's certified ad technology providers is available in Google's documentation.
5. Legal bases (GDPR)
Where the GDPR applies, we process usage data on the basis of legitimate interest (Art. 6(1)(f) — operating and securing the service) and consent (Art. 6(1)(a) — personalised advertising and analytics cookies). You may withdraw consent at any time.
6. Your rights
Depending on your location, you may have rights to access, correct, delete or restrict processing of your personal data, and to lodge a complaint with a supervisory authority. Since we do not maintain user accounts and do not retain the files you convert, the personal data we hold about you is minimal. For any request, contact us at info@brothers.net.tr.
7. Children
The service is not directed at children under 16 and we do not knowingly collect personal information from them.
8. Changes
We may update this policy from time to time. The "last updated" date above reflects the latest revision.
9. Contact
Brothers IT Yazılım Arge ve Bilişim Hizmetleri Tic. San. Ltd. Şti.
İstiklal Mah. 344 Sok. No:4/2, Serdivan/Sakarya 54050, Türkiye
Email: info@brothers.net.tr