File Safety
Your files are processed, not hosted.
FormatOS processes your file for the action you choose. No galleries, no public hosting, no file library, no selling of your uploaded files.
Last reviewed: June 29, 2026
In your browser
Tools run on your device
Not uploaded
Files stay on your device
No galleries
No public file hosting
Your files
Not published or sold
Designed for
Everyday file work. Nothing risky.
FormatOS is built for practical, lawful file preparation. Only upload files you own or have clear permission to process.
What the workspace is built for:
On every upload
What we check before touching your file.
Every upload goes through a validation pass. Dangerous or unsupported files are rejected cleanly — not silently broken mid-process.
Dangerous types blocked
Executable and script extensions (.exe, .js, .bat, .cmd, .sh, .msi, .dll, .apk, .jar, .vbs, .ps1, .scr, and similar) are denied. Only recognized, non-executable file types are accepted.
Filename safety
Path-traversal sequences like "../" are blocked and illegal characters are sanitized, so a crafted filename can't escape the intended handling.
Size limits enforced
Each category has its own size limit. Files over the current limit are flagged before processing begins, not after wasting your time waiting.
Extension vs. detected type
The file's extension is compared against its detected type. When they don't confidently match, the available actions are limited rather than guessing — so a mislabeled file isn't pushed through the wrong tool.
Where files go
On your device. Always honest.
Every current FormatOS tool processes your file right in your browser — it is not uploaded to our servers. If any future tool ever needed temporary server-side processing, its own page would tell you before you upload. We never hide it.
In your browser
Every current FormatOS tool runs entirely in your browser tab — image, PDF, archive, data, e-book, scan cleanup, text, and bank statement actions. Your file is not uploaded to or stored on our servers for these operations.
If that ever changes
No current tool needs server-side processing. If a future tool ever did require temporarily sending a file to a server, that tool's own page would clearly disclose it before you upload anything — never silently.
Hard limits
Things FormatOS doesn't do.
These are not corner-case limitations — they are deliberate decisions. FormatOS is not built for these workflows and never will be.
If you encounter anything on this site that appears to enable these workflows, please report it via the Contact page. That would be a bug, not a feature.
Honest note
Metadata removal isn't magic.
We reduce common hidden metadata — we don't guarantee perfect anonymization.
Metadata removal tools strip common fields like GPS location, camera model, author name, and document history. But metadata is complex — some fields may survive depending on the format, tool, or conversion path.
If you're handling sensitive files — legal documents, medical records, personal photos with location data — review the output carefully before sharing. And keep your originals until you're confident.
We'd rather be honest about this than claim something we can't fully deliver.
More detail
Related policies worth reading.
File Safety is the overview. These pages go deeper on specific areas.
Simple rule for safe use:
Only upload files you own or have permission to process.