Privacy Policy
HEIC2JPG privacy policy — photos are decoded and re-encoded inside your browser; the only network activity is page delivery, one decoder download and ads.
Last updated: September 2026.
Three facts cover almost everything:
- Your photos are never uploaded. Conversion — HEIC decode plus JPG/PNG/WebP encode — runs in a WebAssembly worker inside your tab. There is no upload endpoint and no processing server.
- One download does happen. On the first HEIC file, your browser fetches the decoder itself (
/libheif-*.jsand/libheif-*.wasm, ~1.5 MB) — from this site’s own domain, not a third-party CDN. After that the tool works fully offline: pull the connection and keep converting. - The usual web plumbing still runs. Hosting logs and ad requests exist — described below.
Hosting and logs
Pages and static files — the decoder included — are delivered by Cloudflare. Its edge records standard request metadata (IP address, user agent, timestamp, URL) to serve traffic, resist abuse and produce aggregate counts. There are no user accounts and no forms, so nothing links those records to you or your files.
Advertising
The site is funded by ads from Google AdSense. When ads load, Google may set or read cookies to measure impressions and, where allowed, personalise them — its own policies apply. Opt out in Google’s Ads Settings or block third-party cookies; conversion works the same with ads blocked.
Analytics
We may look at privacy-respecting aggregate traffic (no cross-site tracking, no profiles). File names, photo contents and conversion results are never part of it — they never reach the network.
Your controls
- The articles read fine with JavaScript off; the converter needs it.
- Cookies and ad personalisation are browser-side settings.
- Policy questions: hello@photopassport.online.
Changes
Revisions land on this page with a new “last updated” date.