Last updated: 4 September 2026

1. What this policy covers

This policy describes what happens when you visit topriv.com, the corporate website of topriv. It is an informational site: it publishes information about our company, our products and our research. You cannot upload a file here, there are no user accounts, and no payment is ever taken on this domain.

Our products are separate services with their own privacy policies, because they handle a different kind of data. If you want to know how a file you convert or share is treated, read the policy for the product you are using:

2. What we collect on this website

We collect as little as we can while still being able to tell whether the site works and whether anyone is reading it. There are exactly three things.

Analytics. We run Umami, an open-source analytics tool, on our own server under our own subdomain. It is not Google Analytics, it is not a third party, and no data about you leaves our infrastructure. It sets no cookies and it does not store your IP address. For each visit it records the page you viewed, the site that referred you, your browser, operating system, device type, screen size, language, and an approximate location derived from your IP address at the moment of the request and then discarded. Visits are grouped under an identifier derived from a value that rotates daily, so the same person cannot be followed from one day to the next, and nothing can be traced back to you.

Server logs. Our web server writes a standard access log containing the IP address that made the request, the time, the page requested, the response code and the browser string. We keep it for one reason: it is the only way to see an attack in progress and block it. These logs rotate daily and are deleted automatically by age, so no entry survives longer than 15 days. Nothing older than that exists to be requested, subpoenaed or breached.

One browser storage entry. If you dismiss the announcement bar at the top of the site, we save a single entry in your browser's local storage so it stays dismissed. It contains the value "1". It is not a cookie, it is never sent to us, and it identifies nothing.

3. What we do not do

To be direct about the things you are most likely to be worried about:

4. Network infrastructure

This site is served through Cloudflare, which sits in front of our server as a content delivery network and a filter against denial-of-service attacks. To route your request, Cloudflare necessarily sees your IP address. It acts as a processor on our behalf and is governed by its own privacy policy. We do not use Cloudflare's analytics or advertising products.

Our fonts are served from our own domain rather than from a font provider, so no request for a typeface tells anyone else that you were here.

5. If you contact us

If you email [email protected] or [email protected], we hold your message and your email address for as long as we need to answer you and to keep a record of the conversation. We use it only to reply. We do not add you to a mailing list, and we do not pass your address to anyone else. Ask us to delete the correspondence and we will.

6. Legal basis for processing

Where the GDPR or the UK GDPR applies, we rely on our legitimate interest in operating a secure website and understanding whether our content is useful. That interest is narrow by design: the analytics data is not personal data, and the security log is the minimum that lets us defend the server and is deleted on a fixed schedule. Where you email us, we process your message to respond to your request.

7. Your rights

Depending on where you live, including under the GDPR, the UK GDPR and the CCPA, you may have the right to access, correct, delete, restrict or object to the processing of your personal information, and to receive a copy of it.

We want to be straightforward about what this means in practice. Because we do not hold accounts and our analytics contains no personal data, there is usually nothing to give you. The one exception is the security log, which contains your IP address for up to 15 days. If you write to us within that window from the connection you visited on, we can confirm what it holds and erase it. After that it has already erased itself. If you have emailed us, we can send you or delete that correspondence at any time.

To make a request, write to [email protected]. We will respond within the period the applicable law allows. We will never charge you for it and we will never treat you differently for asking.

8. International users

Our servers are located in Europe. If you visit from outside that region, your request is handled there, and Cloudflare may route it through a location closer to you first. By using the site you understand that this is how the request reaches us.

9. Children

This website is not directed at children and we do not knowingly collect personal information from anyone under 16. If you believe a child has sent us personal information, contact us and we will delete it.

10. Changes to this policy

If we change what we collect, we will change this page and move the date at the top. We will not quietly add a tracker and leave the policy saying otherwise. The date above tells you when this text was last touched.

11. Contact

Questions, concerns or requests about this policy go to [email protected]. A person reads that inbox.