Privacy Policy
Last updated: March 2026
1. Data Controller
FileCrank is operated by FileCrank Ltd. For all privacy-related enquiries, please contact us via our contact form.
FileCrank does not have a designated Data Protection Officer (DPO) at this stage, as our processing activities do not meet the mandatory DPO thresholds under GDPR Article 37. This assessment is reviewed as the service scales.
2. What We Collect
FileCrank processes the following categories of data:
- Session identifier β a randomly generated anonymous UUID stored in a first-party cookie. It contains no personally identifying information.
- Uploaded file names β file names from your device are never stored. We assign an internal UUID to each job. Only the file size and job status are retained in our database.
- Tool usage events β when you consent to analytics, we record which tool you used, your device type (desktop / mobile / tablet), and country-level location derived from your IP address. No file contents, text, or personal data are included in analytics events.
- IP address (anonymised) β your IP address is hashed using SHA-256 with a rotating daily salt before any storage. The raw IP is never persisted and cannot be reversed from the stored hash.
FileCrank does not use browser fingerprinting, canvas fingerprinting, or any device identification technique beyond the session cookie.
Browser-based tools exception: Browser-based tools (Base64, URL encoding, JSON viewer, CSV viewer, HTML entities, number base converter, and others) run entirely in your browser and transmit no data to our servers. Nothing you paste or type into these tools is ever sent anywhere.
3. How We Use It
- Service delivery β to perform the file operation you requested and make the result available for download.
- Abuse prevention β to rate-limit API requests and protect the service for all users.
- Aggregate analytics β to understand which tools are used, identify errors, and improve the service. Analytics fire only after you grant consent.
FileCrank does not sell, rent, or share your personal data with any third party for their own marketing purposes. Data shared with sub-processors (Section 6) is limited to what is strictly necessary for service delivery.
FileCrank does not use automated decision-making or profiling as defined in GDPR Article 22.
4. Legal Basis (GDPR)
- Contract performance (Article 6(1)(b)) β processing your uploaded files to deliver the service you requested. For uploaded files that may contain special category data (health, legal, financial), the legal basis is your explicit consent (Article 9(2)(a)), obtained via the upload consent notice before your first file upload.
- Legitimate interest (Article 6(1)(f)) β rate limiting and abuse prevention using hashed IP addresses. Our legitimate interest is protecting the security and availability of the service for all users.
- Consent (Article 6(1)(a)) β analytics tracking (PostHog) and behavioural advertising (Google AdSense). You may withdraw consent at any time via the Cookie Settings link in the site footer. Withdrawal of consent does not affect the lawfulness of processing before withdrawal.
- Legal obligation (Article 6(1)(c)) β retaining consent records to demonstrate compliance with GDPR Article 7(1).
5. Data Retention
- Uploaded files β deleted within 1 hour of processing completion. A background job runs every 15 minutes to enforce deletion. Download links expire simultaneously.
- Hashed IP addresses β purged automatically after 24 hours.
- Session data β the session cookie expires when you close your browser. Consent preference and language cookies have a 12-month TTL.
- Job metadata β retained for 90 days for system health monitoring, then automatically deleted.
- Analytics events β retained for 12 months in PostHog under a rolling retention policy, then automatically purged.
- Consent audit log β retained for 3 years to satisfy our obligation to demonstrate that consent was obtained.
6. Third-Party Processors
We use the following sub-processors to deliver the service. Data shared with each is limited to the minimum necessary for that purpose.
| Processor | Purpose | Location |
|---|---|---|
| Cloudflare | CDN, DDoS protection, edge network | Global (US-based) |
| Oracle Cloud | Compute hosting and file processing | EU / US (configurable) |
| PostHog | Product analytics β fires only after analytics consent | EU cloud region |
| Google AdSense | Behavioural advertising β fires only after advertising consent | United States |
| Media.net | Contextual advertising (no personal data used in contextual mode) | United States |
US-based processors are subject to EU Standard Contractual Clauses (SCCs) or are certified under the EU-US Data Privacy Framework. For further detail, contact us via our contact form.
7. Your Rights (GDPR)
If you are located in the EU, UK, or EEA, you have the following rights under GDPR Articles 15-22:
- Right of access (Article 15) β request a copy of the personal data we hold about you.
- Right to erasure (Article 17) β request deletion of your personal data. For immediate file deletion, use the Delete my files now button on any tool page.
- Right to data portability (Article 20) β receive your data in a structured, machine-readable format.
- Right to object (Article 21) β object to processing based on legitimate interest. You can also withdraw analytics and advertising consent at any time via Cookie Settings in the footer.
- Right to restrict processing (Article 18) β request that we restrict processing of your data in certain circumstances.
To exercise these rights, contact us via our contact form or use our data deletion request page. We respond within 30 days.
You also have the right to lodge a complaint with your national supervisory authority. For EU users, a full list of authorities is available at edpb.europa.eu. For UK users, the relevant authority is the ICO.
8. Your Rights (CCPA / California Privacy Rights)
If you are a California resident, the California Consumer Privacy Act (CCPA) as amended by the CPRA gives you additional rights.
Categories of personal information collected
- Identifiers (hashed IP addresses, session IDs, anonymous user IDs)
- Internet or electronic network activity (page views, tool usage, ad interactions)
- Geolocation data (country-level only, derived server-side)
Categories of personal information sold or shared
When you consent to advertising cookies, we share internet activity information with Google AdSense for cross-context behavioural advertising. Under CPRA, this constitutes "sharing."
Your rights under CCPA
- Right to know β request disclosure of what personal information we have collected, sold, or shared in the preceding 12 months.
- Right to delete β request deletion of your personal information. We will respond within 45 days.
- Do Not Sell or Share My Personal Information β opt out of the sharing of your personal information for behavioural advertising. Use the opt-out page or the Cookie Settings link in the footer. We also honour the Global Privacy Control (GPC) signal automatically.
- Right to non-discrimination β we will not discriminate against you for exercising your CCPA rights.
9. Cookie Usage
FileCrank uses cookies for session management, consent preference storage, and (with your consent) analytics and advertising. For full details, including a complete cookie inventory table, see our Cookie Policy.
10. Children's Privacy
FileCrank is not directed at children under 16. We do not knowingly collect personal data from anyone under 16. If you believe a child under 16 has submitted data to us, please contact us via our contact form and we will delete it promptly.
11. Contact
For all privacy enquiries, please use our contact form.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be announced via a site banner. Continued use of the service after the effective date of an update constitutes acceptance of the revised policy.
Last updated: April 2026
13. Networking Tools
FileCrank's Networking Tools include browser-based utilities for IP address lookup, DNS queries, subnet calculations, and related functions. Most tools (subnet calculator, CIDR expander, bandwidth calculator, port lookup, etc.) run entirely in your browser β no data is sent to our servers or any third party.
IP Address Detection (βWhat Is My IPβ). When you use this tool, your IP address is read from request headers provided by our infrastructure (Cloudflare) and displayed to you. Your IP address is not logged, stored, or transmitted to any third party. It exists in server memory only for the duration of your request.
IP Geolocation Lookup. When you use this tool, the IP address you submit is transmitted from our server to ipinfo.io, a third-party geolocation service, to retrieve approximate location data (country, region, city, coordinates, timezone, ISP, and organisation). Results are displayed to you and held in volatile server memory for up to 5 minutes to reduce redundant queries. No IP addresses or geolocation data are written to disk or stored in any database. ipinfo.io processes this data in accordance with its own privacy policy (ipinfo.io/privacy).
Legal basis for processing (GDPR Article 6): when you look up your own IP, processing is on the basis of Article 6(1)(b) β performance of a contract. When you look up a third-party IP, processing is on the basis of Article 6(1)(f) β legitimate interest in providing a standard internet utility.
California residents: the transmission of IP addresses to ipinfo.io is solely for delivering the geolocation service and does not constitute a sale or sharing of personal information under the CCPA/CPRA. No personal information from these tools is stored persistently, so there is no data to disclose or delete upon request.