Privacy Policy

Last updated 28 September 2026
In short
  • Files you upload are used for one thing: converting them to Markdown.
  • They're deleted automatically 48 hours after upload, with no account needed.
  • No ads, no tracking cookies, only anonymous page-view counts. Nobody trains AI models on your files.

1. Who is responsible

MDify is run by DevBehindYou. For anything about your data, write to devbehindyou@gmail.com.

We are the controller of the personal data described here under the EU General Data Protection Regulation (GDPR).

2. What we process

  • The files you upload and everything inside them. Documents can contain personal data about you or other people, so please upload only what you need converted.
  • File details: name, type and size.
  • A job record for each conversion: when it started and finished, which of our servers handled it, and any error.
  • Technical request data: your IP address, browser type and the time of each request. Our hosting providers log these to deliver and protect the service.
  • Page-view statistics: which MDify page you opened, the website that linked to it, and your country, browser, operating system and device type. Our hosting provider's web analytics collects these without cookies. It recognises a returning visitor for at most 24 hours through a temporary code calculated from the request, and stores nothing on your device. File names and file content are never part of it, and the admin area is not counted.

We don't ask for your name, email address or any account. We don't use cookies for tracking or advertising.

3. Why we process it, and our legal basis

  • Converting your files and giving you the result. Legal basis: performing the service you request under our Terms (Art. 6(1)(b) GDPR).
  • Keeping MDify secure and working: blocking abuse, fixing errors and measuring capacity. Legal basis: our legitimate interest in running a safe, reliable service (Art. 6(1)(f) GDPR).
  • Recording that you accepted the Terms and this policy, so we can show which version you agreed to. Legal basis: Art. 6(1)(b) and (f) GDPR.
  • Counting page views, to see which pages people use and how they find MDify. Legal basis: our legitimate interest in improving the service (Art. 6(1)(f) GDPR). The counts are anonymous and need no cookies.

We never use your files or their content for advertising, profiling or training machine learning models.

4. How long we keep it

  • Uploaded files and converted results: deleted automatically 48 hours after your upload finishes. Our cleanup runs every 30 minutes and retries any deletion that fails.
  • Authorised administrators can delete a file earlier. In a specific case, such as investigating abuse or meeting a legal obligation, they can keep a file longer. Every such decision is logged.
  • File names: deleted together with the files. After that, a job record keeps only the file type, size, timings and outcome, with nothing that identifies you.
  • Technical request logs: kept by our hosting providers for the period set in their own policies.
  • Page-view statistics: kept by our hosting provider as anonymous counts, for the period set in its own policy.

Some conversions run fully in server memory without storing the file at all. The limits above are the maximum, not the norm.

5. Data kept on your device

MDify stores a few items in your browser's local storage. They stay on your device and are never sent to us:

  • Your light or dark theme choice.
  • Which version of these documents you accepted, and when.
  • Your last 5 conversions (the Markdown text and file details), so you can reopen them. Clear them any time from the Recent panel.

These items are needed for features you use, so the EU ePrivacy rules don't require a separate cookie consent for them.

6. Who else handles your data

We use a small number of service providers to run MDify. Each one processes data only on our instructions, under a data processing agreement:

  • hosting providers that run the website and our conversion servers, and count page views,
  • a cloud storage and database provider that holds uploaded files, results and job records until they are deleted.

You can ask us which providers we use by writing to devbehindyou@gmail.com.

The conversion software (open-source Microsoft MarkItDown and Tesseract OCR) runs on MDify's conversion servers. It does not send your files to Microsoft or to anyone else.

We don't sell or share your data with anyone else. We would disclose data to authorities only where the law requires it.

7. Transfers outside the EU

Some of our providers are based outside the EU, so your data may be processed in other countries, including the United States. We rely on the EU-US Data Privacy Framework where a provider is certified under it, and on the European Commission's Standard Contractual Clauses (Art. 46(2)(c) GDPR) otherwise. You can ask us for a copy of the safeguards.

8. Your rights

Under the GDPR you can ask us to:

  • show you the data we hold about you (Art. 15),
  • correct it (Art. 16),
  • delete it (Art. 17),
  • limit how we use it (Art. 18),
  • give it to you in a portable format (Art. 20),
  • stop processing it where we rely on legitimate interests (Art. 21).

Write to devbehindyou@gmail.com. MDify has no accounts, so tell us the file name and the approximate time of the upload, and we'll find it if it still exists. We reply within one month.

You have the right to complain to a data protection supervisory authority, in particular in the EU country where you live or work (Art. 77 GDPR).

9. Do you have to give us data?

No. Without a file we can't convert anything, but using MDify is voluntary. We make no automated decisions about you that have legal effects or affect you in a comparably significant way (Art. 22 GDPR). Conversion and text recognition are automatic, technical steps.

10. Security

  • All traffic is encrypted in transit (HTTPS).
  • Files sit in private storage. Download links expire after 10 minutes.
  • Only the conversion servers and authorised administrators can reach stored files, and administrator actions are logged.
  • Every file is checked before conversion, and unsafe or unsupported files are rejected.

11. Children

MDify isn't aimed at children under 16. If you're younger, please use it only with a parent's or guardian's permission.

12. Changes to this policy

We'll update the date at the top when this policy changes. If a change affects how we use your data, MDify asks you to accept the new version before your next conversion.