Last updated: October 10, 2026

THE COMPLETE GUIDE
Privacy Policy
How this converter handles uploaded media, temporary MP3 results, owner sessions, privacy choices, retention and verified deletion.
Scope, operator and contact
MP3 Converter Online temporarily uploads audio and video to a server for conversion; processing is not entirely on your device. Support and privacy requests go to catalog.project.com@gmail.com. The operator's legal identity, hosting-provider name and processing country have not been supplied and are not invented here.
What is processed and where it comes from
You supply the audio or video content, its byte size, declared type and conversion settings. The server validates the actual container, audio codec, duration, sample rate and channels, and creates a verified MP3. The source may contain metadata such as ID3 or personal information in its sound or video. Upload only material you are entitled to submit. Output encoding removes source metadata rather than forwarding it to analytics.
The original filename stays in browser memory to suggest a download name; the upload body does not send that name as a server field. The backend keeps a job ledger, queue entries, ownership references, stored object versions, normalized error codes and limited media properties needed to deliver and clean up the job. CSRF tokens, upload tickets and temporary signed links are security data, not analytics dimensions.
Why processing is necessary
The requested service needs temporary upload, format validation, queued processing, output verification, playback and download, abuse limits and verified cleanup. Necessary session and security operations are separate from optional preferences, analytics or advertising. Optional preferences use your explicit choice. The legal basis for delivering the requested service and any infrastructure processing must be confirmed by the operator for the applicable deployment; this local policy does not assert a universal legal exemption.
Your upload does not give the service permission to publish your files, sell their contents or train models on them. Processing is limited to performing your requested conversion, securing access and removing temporary copies.
The owner session is necessary
A first-party host-only HttpOnly cookie named mp3_session lasts seven days from creation. It links this browser to its own jobs; knowing a job ID or copying a result URL does not grant another session access. The cookie uses SameSite=Lax and Secure on HTTPS. The browser’s security request tokens are held in memory. There is no account or password recovery.
Agree, Reject optional, Save preferences and later withdrawal never remove the owner cookie, cancel a job or revoke a result. Clearing that cookie in the browser may lose job access. Delete files is the separate control for requesting media deletion.
Before a choice, after Agree and after refusal
This installation uses a strict interface and aggregate_only pre-consent mode because regional applicability is unconfirmed. Before a choice, necessary requests and operational counters from existing server work continue. No optional third-party analytics SDK, advertising SDK, session replay or embedded-media tracker is installed. Language does not determine a legal region, and no visitor-level client history is buffered for later tracking.
Agree enables the disclosed active optional purposes: remembering language and bitrate/channel settings. Save preferences enables only your selected available purposes. Reject optional or withdrawal stops optional purposes and removes the corresponding known preference cookies; the converter and required operational work continue. A privacy choice is not acceptance of the Terms. It does not erase information already transmitted or a copy already downloaded.
The same-host choice lasts 180 days, equally for agreement and refusal, and can be changed through Cookie Settings in the footer. It records purpose choices, versions and time, not a visitor ID. If storage is blocked, the choice still applies on the current page. A detected GPC signal keeps advertising restrictions in force. No optional advertising is currently active.

Retention follows the job lifecycle
These values are verified against the current backend settings and cleanup code. They describe availability and normal cleanup rules, not guaranteed physical erasure during a storage outage. If a worker is retried, its source remains only while that job still requires it.
| Data | Availability / removal rule |
|---|---|
| Uploaded original | Cleanup starts after a verified successful result. Eligible failed jobs have a 30-minute retry window; non-retryable failures enter cleanup. |
| MP3 result | 60 minutes after successful completion, or earlier when Delete files is requested. |
| Download link | At most 5 minutes; never later than result expiry; still requires the owner session. |
| Temporary working copies | Removed when the native worker stops; unresolved writers delay confirmation. |
| Ledger and tombstones | Purged after 7 days from confirmed deletion. Unresolved cleanup records remain until reconciled. |
| Queue records | Completed/failed queue entries have a configured 7-day removal age. |
| Infrastructure error logs | HTTP access logs are disabled for this domain. Application container logs rotate at 5 MiB per file, with at most three files per container; there is no time-based expiry guarantee. Storage-container logging is disabled. Host-provider logs are unconfirmed. |
Access closure is different from confirmed deletion
Delete files immediately blocks new operations and requests cleanup. deletion_pending means cleanup has not yet been verified. The system waits for writers, stops native processes, removes all recorded object versions and multipart uploads and checks the storage before displaying “deleted”. A storage or termination problem can leave deletion_pending or deletion_failed for reconciliation. Healthy-storage cleanup targets five minutes; an outage can delay it.
Deleting temporary files cannot recall downloaded copies or a transfer already in progress. Reject optional does not request media deletion. Application backups contain PostgreSQL metadata only, are stored on this VPS for seven days and exclude the media storage and work volumes. Host-provider snapshots and infrastructure retention outside this application have not been confirmed. Verified deletion means recorded object versions and multipart uploads are absent; it does not promise forensic disk erasure.
Infrastructure, recipients and transfers
This deployment runs on one VPS. nginx serves HTTPS and proxies requests to private Docker services: Fastify, PostgreSQL, Redis/BullMQ, authenticated versioned SeaweedFS S3 storage and the isolated FFmpeg runner. Storage and processing use this VPS; no external object-storage service, CDN, advertising or optional analytics provider is enabled. Software names identify components, not the legal hosting provider. The provider, country and applicable transfer safeguards have not been supplied.
Network infrastructure necessarily receives connection information to deliver requests. No third-party analytics, advertising or optional diagnostics recipient is connected. Security/session values, filenames, media content, ID3, object keys, job IDs, upload tickets and signed URLs must not be sent to such recipients. External reference links navigate to independent sites only when you choose them; their own policies apply.
Security and operational records
The implementation uses owner authorization, same-origin and CSRF checks, private versioned storage, bounded upload tickets, native media isolation and verified cleanup. Temporary access links remain owner-bound. Minimal health observations and normalized failure codes support reliability and abuse protection; they do not create a marketing profile. Operational aggregate totals are derived from necessary ledger work. No security design can guarantee zero risk or permanent availability.
Choices, requests and complaints
Depending on applicable law, you may have rights to information, access, correction, deletion, restriction, portability and objection, and to complain to a competent authority. Email catalog.project.com@gmail.com for a privacy request. Cookie Settings withdraws optional permission without ending conversion access; Delete files requests media cleanup. Do not include private media, cookies or temporary links in your message.
No support form, mailbox provider or ticket retention policy is connected in this local installation. If a support channel is later configured, it must disclose the information received, purpose, recipients and retention. Browser choice withdrawal cannot erase data previously received by a provider.
Audience and policy changes
This general-purpose file tool is not designed or marketed as a service for children. No age verification system or child-specific representative is configured. If a child’s information is involved, the operator must assess applicable obligations. We do not invent a universal age threshold.
The update date appears above. New active optional purposes require a new choice for those additions; a saved rejection is not reset merely because you revisit. The Cookie Policy lists current browser storage and controls. The Terms explain authorized material and service limits.