Trust
What happens to files on Toolsy after processing

You upload a PDF or Word file, wait for Markdown or OCR text, and download the result. Toolsy treats that upload as temporary job material, not a personal drive. For server-side tools you start a job, we process the file (and for some OCR or AI features we send content through our AI gateway), we return the output to your browser, and we design the upload to be discarded shortly afterward, typically within about one hour. Signed-in history and billing follow different clocks. History keeps short metadata such as the tool and original filename, not the full file body. The Privacy Policy is the binding text; this article restates it in plain English for document upload privacy.
Why people ask what happens after an upload
Online converters earn distrust the hard way. You paste a scan of a contract, a school form, or a research PDF into a site you found in a search result, and you have no inventory of where the bytes went. Marketing pages say “secure” and leave the retention window vague. That gap creates the same search cluster you see around safe PDF converters, file upload security, and “do they keep my files.”
The fear is concrete. Someone might reopen your document later. Someone might train a model on your text. Someone might leave the file in an object store for months. Those are separate risks, and they need separate answers. Mixing them into one slogan helps nobody who has to clear a client PDF before a call.
Toolsy’s product pages and policy draw a line between job files and account records. Job files exist to finish the conversion or OCR pass you requested. Account records exist so you can sign in, hit plan limits, and (if you pay) keep billing straight. Confusing those two clocks is the most common reading error on privacy pages.
You also meet a split inside the product itself. Some utilities run in the browser and never send the paste to our servers. Document conversion, OCR, image pipelines, AI text, and SEO research need a server. Product pages state when a server or AI provider is involved. If you care about document upload privacy, start by reading that line on the tool you plan to use.
The short pipeline on Toolsy
For a server-side tool job, the lifecycle is short and purposeful. You pick a tool, you upload or submit content, we run the job, you get the output back in the client, and the upload is meant to leave temporary storage on a short timer. The policy language is “typically within about one hour,” not “instant delete at millisecond zero,” and that distinction matters when you write internal security notes.
Think of the upload as fuel for one request. Once the response is in your browser, the original bytes have finished their job. You should not expect to reopen the same PDF from a Toolsy library a week later.
The steps below match Privacy Policy sections on uploaded files and retention. If marketing copy and the policy ever disagree, trust the policy.
You upload for a specific tool job
You start a conversion or OCR pass the same way you use any other page on toolsy.tools. The file exists on our side because that job needs bytes the browser cannot finish alone. Freemium counters, rate limits, and abuse checks may still see technical identifiers such as IP and User-Agent even when you stay logged out.
You remain responsible for having a lawful basis to submit the content. If the PDF belongs to a client, a patient workflow, or someone else’s archive, the policy does not make that risk disappear. Skip secrets, passwords, and highly sensitive special-category data unless you accept the residual risk of cloud AI processing for the tools that use it.
Embed widgets follow the same upload idea for end users on a third-party site: Toolsy processes the upload to run the tool. The site owner is typically a separate controller for how they collect and use results.
We process, then return the result to your browser
Processing means we produce the output you asked for: Markdown, extracted text, a cleaned image path, and so on. The response lands in your browser session so you can copy or download it. We do not treat the finished download as a reason to keep the original upload as a library copy.
Operational logs may keep non-content metadata (tool slug, truncated filename, token or cost metrics, latency). Those rows support reliability, abuse prevention, and cost control. They are not a substitute for a document management system, and they are not a backdoor copy of your PDF.
Uploads are designed for short discard, not archival storage
Uploaded files for processing are designed to be discarded shortly after the job completes. The retention section of the Privacy Policy puts that window at typically about one hour and states that uploads are not kept as a long-term content archive. Toolsy also states that we do not use your uploads to train our own models.
“Typically” leaves room for operational delay, failed jobs, and cleanup queues. If your threat model requires cryptographic erase proofs or contractual zero-retention from every subprocessors, you need a different procurement track than a freemium web converter. For everyday document conversion, the published design is short-lived job storage plus a download in your hands.
When content stays in your browser
Not every Toolsy utility uploads. Client-side tools (many text and QR utilities, for example) process content in the browser and do not send the paste to our servers. That path still generates technical traffic for page loads and limits, but the paste itself never becomes a server-side file job.
Before you drag a sensitive PDF onto a page, check whether the tool says it needs a server or an AI provider. If the page is a local utility, you avoid the upload question. If the page is PDF to Markdown or To Markdown, you are in the server pipeline described above.
Anonymous use still involves technical data. IP address, User-Agent, request metadata, and freemium counters exist so we can provide the feature, enforce daily limits, and protect the service. Those rows are not the same as keeping your document body.
OCR and AI jobs: what can leave Toolsy
Vision, OCR, and certain AI features send image or text content to our AI gateway (OpenRouter) and underlying model providers so the model can generate the result. That hop is part of finishing the job you started. Product pages call out when AI is involved; treat those pages as part of your pre-upload checklist.
OCR on Toolsy extracts text from handwriting or print. The Privacy Policy states that we do not treat OCR as biometric identification under UK GDPR special-category rules: the feature is not used to uniquely identify a person by biological characteristics. That clarification sits next to a blunt warning: do not upload content you are not allowed to process.
International transfers follow the company setup. BARS AI LTD is established in the United Kingdom. Some processors, including AI model providers, Stripe, Google (if you use Google sign-in), and SEO data providers, may process data in the UK, EEA, United States, or other countries. Where UK GDPR requires a transfer mechanism, the policy points to safeguards such as the UK IDTA / Addendum, EU Standard Contractual Clauses where applicable, or an adequacy decision. Toolsy does not claim that every byte of every job stays inside the EU.
API keys and embed widgets add one more nuance. OCR API and embed usage count against the account owner’s quotas. API request logs may record key id, status, and timing, not the full document body. If you embed a widget on a third-party site, visitors’ uploads still run through Toolsy to finish the tool; the site owner is typically a separate controller for how they collect and use results.
File retention versus account and billing retention
People search “data retention policy” and expect one number. Toolsy publishes several. Job uploads use a short discard window. Accounts, invoices, and history use longer clocks. Treating those as one number creates false comfort or false alarm.
Security questionnaires often ask “how long do you retain customer content?” Answer with the job-file window first, then list account and billing rows as separate categories. Auditors care about that split; so should anyone clearing a client PDF through a web tool.
The subsections below mirror the retention list in the Privacy Policy. Durations can change when the product or law changes; the “updated” date on the policy page is the checkpoint.
Uploaded files for processing
Job uploads follow the short window: typically discarded within about one hour after the job completes, and not treated as a long-term content archive. That is the answer to “what happens to my file after I download the Markdown.”
If you need the output later, save the download on your side. Closing the tab without saving loses the practical copy even if temporary storage has not finished cleanup yet.
Accounts, sessions, history, and billing
Account data lasts while the account exists, then deletion or anonymisation follows within a reasonable period after closure, except records we must keep (for example billing). The session cookie lasts about 30 days of inactivity, or until you sign out. Activity history for signed-in users lasts about 30 days and is metadata only. Security and rate-limit logs use short rolling windows. Billing records can last several years for accounting and tax. Cookie consent choices last up to 12 months or until you change them.
Paid plans and daily free limits live on Pricing. Those entitlements explain how often you can run jobs. They do not extend the file archive. Buying Pro or Plus does not turn Toolsy into a document locker that stores every PDF you converted.
What activity history stores
Signed-in users may see a short activity history: tool used, original filename, and time. The Privacy Policy states that history does not store the full file contents. Retention is about 30 days.
That design helps you remember which converter you ran last Tuesday without recreating a copy of the client PDF on our side. Filename leakage is still a privacy detail: if the original name contains a matter number or a person’s name, history will show that string for the retention window. Rename sensitive files before upload if that matters in your workflow.
History is not a backup. If you need the Markdown six weeks later, keep your own archive. Deleting or anonymising account data after closure follows the contact process in the policy; email hello@toolsy.tools from the registered address when you want that path.
Habits that improve document upload privacy
Start with classification. Public white papers and your own drafts belong in a different bucket from payroll, medical scans, or unreleased M&A drafts. Toolsy’s freemium converters fit the first bucket well. The second bucket needs your own counsel, vendor review, and sometimes an offline or private-cloud pipeline.
Strip what you do not need. Remove pages that are irrelevant to the conversion. Prefer a clean export over a photographed binder when OCR quality and privacy both matter. For photos you plan to share elsewhere, EXIF GPS is a separate problem; that is a later trust article, not a substitute for reading this pipeline.
Read the tool page before the drag-and-drop. If the page mentions AI or a server, assume content can reach processors listed in the Privacy Policy. If you only need Markdown for RAG prep, use To Markdown or PDF to Markdown, download the result, and move the Markdown into your own store.
Keep an eye on the two clocks. Job files: about one hour by design. Account and history: weeks. Billing: years. When a colleague asks “does Toolsy keep my documents,” answer with the clock that matches their question.
Convert a file, then verify the policy yourself
If your next step is a real conversion, run one non-sensitive sample through To Markdown or PDF to Markdown, save the download, and skim Privacy sections 4, 5, and 9 while the job is fresh in your head. Matching the UI to the written retention rules beats trusting a blog alone.
Bring a file you would be willing to lose. Use the download as the copy of record. If you are writing an internal note for a team, quote the policy’s “about one hour” window and the history metadata rule instead of paraphrasing from memory.
For the broader safety checklist (TLS, phishing lookalikes, what “safe converter” means in search), see Is it safe to upload documents online. For Markdown and RAG workflows that consume the output after you download it, see Prepare documents for RAG with Markdown and What is MarkItDown.
Frequently asked questions
Does Toolsy keep my uploaded PDF after I convert it?
Uploaded files for processing are designed to be discarded shortly after the job completes, typically within about one hour. They are not kept as a long-term content archive. Save the download if you need the output later; Toolsy is not your document drive.
What is the difference between file retention and a data retention policy on Toolsy?
File retention for uploads is the short job window described above. Broader data retention covers account records, sessions, activity metadata, security logs, billing, and cookie consent, each on its own schedule. One search for “data retention policy” often means corporate templates; here you need the Privacy Policy section on how long we keep data.
Does activity history include the full document?
No. For signed-in users, history may record the tool used, the original filename, and the time. The Privacy Policy states that history does not store the full file contents. Retention for that metadata is about 30 days.
Do you use my uploads to train Toolsy models?
The Privacy Policy states that we do not use your uploads to train our own models. OCR and certain AI features still send content to the AI gateway and model providers so those providers can generate the result for your request. That processing hop is separate from Toolsy training on your files.
Are online file converters safe in general?
Safety depends on TLS, the operator’s retention rules, whether AI subprocessors see the bytes, and what you upload. Toolsy publishes short discard for job files, UK GDPR framing, and named processor categories. Generic “safe PDF converter” searches still require you to read each vendor’s policy; there is no single industry default.
What happens during OCR privacy-sensitive jobs?
OCR and vision jobs may send image or text content through OpenRouter and underlying model providers. We process the file to produce the requested output and return it to the client. Avoid highly sensitive special-category data unless you accept the residual risk of cloud AI processing.
Does a paid plan change how long files stay?
Paid entitlements on Pricing change how often you can run tools and which features you unlock. They do not turn job uploads into a long-term archive. Billing records for subscriptions can last years for tax and accounting even after a file job is gone.
Can I use tools without creating an account?
Many tools work without registration. We still process technical data such as IP, User-Agent, request metadata, and freemium counters to provide the feature and protect the service. Client-side tools may never upload the paste; server-side tools upload when you run the job.
Where is Toolsy based, and where can processors run?
BARS AI LTD is established in the United Kingdom. Processors may process data in the UK, EEA, United States, or other countries, with transfer safeguards where UK GDPR requires them. The English Privacy Policy does not claim EU-only residency for all processing.
Where do I read the binding rules or delete an account?
Read the Privacy Policy on toolsy.tools. To delete an account, email hello@toolsy.tools from the registered address; we remove or anonymise personal data that is no longer needed, subject to legal exceptions such as billing records. Related documents include Terms and the Cookie Policy.
Related reading: Is it safe to upload documents online, Prepare documents for RAG with Markdown, and What is MarkItDown.
Convert a document to Markdown
Upload a file, download the result, then we discard the upload on the short retention window.


