Skip to content
OrbitexPDF

File handling policy

Security

This document explains how OrbitexPDF handles files you upload - from selection in your browser through temporary storage, processing, and permanent deletion.

Last updated: August 2026

File handling at a glance

Uploaded file

Deleted the moment the job finishes, whether it succeeded or failed

Result

Deleted about a minute after you download it

Longest anything survives

30 minutes, even if you never come back for it

Where files are processed

Our own server in Germany - no third-party processor

Temporary storage

A disk spool the job reads once, never a library or an archive

Stored history

None. There is no list of your files, because none is kept

Third-party processing

Disclosed here before any vendor is enabled

Transport encryption

TLS on every upload and download

1.Overview

Files you process with Orbitex - PDFs, images, and exports - often contain personal, financial, or confidential information. This policy describes the full lifecycle of those files and our commitment to minimizing exposure.

Uploads reach our own server in Germany and are written to a short-lived disk spool. Nothing is copied elsewhere, no third-party processor is involved, and there is no archive - a healthy server holds close to zero bytes of anyone's data. The retention windows shown above are read from the running configuration, not written here by hand, so this page cannot claim one thing while the software does another.

File processing itself is not connected yet. Uploads are accepted and deleted on the schedule above; conversion arrives in the next release, and this page will be updated when it does.

2.How files are processed

When you select a file, the browser reads it using the File API. Image previews may use temporary object URLs that are revoked when you leave the page or replace the file.

When server processing is enabled, files will be transferred over TLS/SSL to isolated processing infrastructure. We do not inspect, analyze, or mine file contents for advertising or unrelated purposes.

Processing is performed solely to deliver the tool you requested - compress, merge, convert, edit, or similar operations.

3.Upload and temporary storage

Uploads are written to a spool directory on our server, under generated names that carry nothing of the original filename and cannot be guessed. Each job's files sit in their own directory, separate from everyone else's.

There are no backups of uploads or results. Backups exist for accounts and settings; the spool is deliberately excluded, because a file that survives in a backup has not really been deleted.

A sweep runs every minute and removes anything past its deadline, whether or not the normal deletion path worked. Files that outlive their expiry without being removed are logged as an error, because that is the only way the disk fills.

The retention windows above are read from the running server configuration, not typed into this page by hand.

4.Automatic and manual deletion

Approved product designs include automatic deletion after a job completes successfully or fails. Users will also see a manual Delete Now action on success states.

If you close the browser tab during an in-progress upload, incomplete server-side files will be purged according to the same retention schedule.

Account deletion (when available) will trigger removal of associated stored files within a documented window.

5.Who can access uploaded files

Orbitex staff do not routinely access user files. Limited access may occur for abuse investigation, legal compliance, or critical support cases with your permission.

Access controls, audit logging, and role-based permissions will be documented after security review.

6.Third-party services

Some specialized tools - such as OCR, advanced conversion, or background removal - may use trusted subprocessors bound by data processing agreements.

Before any third party is enabled, we will list provider name, processing region, purpose, and retention commitment in a table on this page.

We will not sell or license your file contents to third parties.

7.Security measures

We apply industry-standard technical and organizational controls to protect files during their temporary lifespan, including:

  • TLS encryption for data in transit
  • Encryption at rest on processing servers (when enabled)
  • Network isolation between customer jobs
  • Access logging and monitoring
  • Regular security review of infrastructure

8.Your responsibilities

Do not upload content you do not have the right to process. Do not use Orbitex for unlawful material.

If you handle regulated data (HIPAA, GDPR-sensitive, etc.), review this policy and contact us before processing - we can discuss DPAs and compliance needs for Business customers.

9.Changes to this policy

We update this policy when architecture, vendors, or retention practices change. Material updates will be posted here with a revised date.

Questions about this policy?

If you have specific concerns about how files are handled, our support team is available to help.

support@orbitexpdf.online

Related policies