File-processing boundary
The application has no file-processing route handler, upload bucket, conversion queue, or database field that receives a selected document. After a user gesture, the browser grants the current tab temporary access to a local File reference. A format-specific engine reads those bytes in tab memory and creates an output Blob. Temporary object URLs support previews and downloads and are revoked after use.
PandaFileKit does not intentionally place file bytes, filenames, extracted text, EXIF values, GPS coordinates, or document metadata values in localStorage, IndexedDB, analytics events, or advertising parameters.
Optional analytics and advertising
Google Analytics and Google AdSense remain absent unless their real environment IDs are configured. When configured, the preference panel keeps each service disabled until the visitor grants its individual preference. The panel stores only two boolean choices in localStorage. Google Analytics receives tool IDs and coarse operational buckets; it must not receive filenames or content. Ad personalization is denied by this interface.
A commercial publisher remains responsible for a region-appropriate legal review and any Google-certified consent platform required for its audience. The built-in controls are a technical loading gate, not a claim of jurisdiction-specific certification.
Your controls
- Select “Essential only” to prevent optional Google scripts from loading.
- Use the persistent “Privacy choices” control to change the two optional preferences.
- Refresh or close the tab to clear in-memory file and output state.
- Clear this site's storage in browser settings to remove the saved preference record.
Contact
A public privacy contact must be supplied through NEXT_PUBLIC_CONTACT_EMAIL before commercial launch.