The FBI Warned People About Fake File Converter Sites. Here's What Happens When You Hit Upload.
5 sites
found hosting the same password-stealing malware
disguised as music/file converters, per Cybernews
Article 5(1)(e)
GDPR's 'storage limitation' principle
personal data can't be kept 'longer than is necessary,' per the official regulation text
None of this means every free converter is a scam, most aren't. But 'processing' a file almost always means uploading it first, and what happens after that upload is set entirely by a company you probably never heard of until you needed a PDF converted at 11pm.
The three things that happen to a legitimate upload
- ✦It leaves your device. Even a conversion that takes two seconds routes your file through the service's servers first, that's what 'cloud-based' processing means by definition.
- ✦It may not delete on the schedule you'd assume. Privacy policies often use vague language like 'we delete files after a reasonable period' without stating a number, and retention windows of 24 hours to several days are common across the category.
- ✦Its terms of service usually cover more than conversion. Broad language granting a company the right to 'access, analyze, and process' what you upload is standard boilerplate for the category, not unique to bad actors, but worth reading before you upload something you'd mind someone else seeing.
The fake-converter scam is a different, worse problem
The FBI's Denver field office issued a public warning about websites posing as free document converters that install malware instead of converting anything. Separately, Cybernews traced a strain called Cuckoo malware, hidden inside a fake 'Spotify Music Converter' app, to at least five different converter sites, including tunesolo.com, fonedog.com, tunesfun.com, and tunefab.com. Cuckoo copies browser data, passwords, and crypto wallet secrets, and can run persistently in the background. That's categorically different from a legitimate service with a generous retention window, and from the outside, a URL alone won't always tell you which one you're on.
A real example of why the fine print matters
In June 2024, Adobe updated its Terms of Use with language broad enough that creators read it as a claim to train AI on their uploaded work. The backlash was loud enough that Adobe published its own clarification within days, stating flatly that it had 'never trained generative AI on customer content' and adding an explicit pledge to that effect in the terms themselves. Nothing about Adobe's actual practices changed, the wording did, and it changed because people pushed back after reading, not before uploading.
What actually reduces the risk
| Approach | Where your file goes | Effort |
|---|---|---|
| Use whatever converter ranks first in search | Their servers, retention varies by service | None |
| Skim the privacy policy before uploading | Same server, but you know the terms | A few minutes |
| Use a tool that processes the file in your browser | Nowhere, it never leaves your device | None, once you know it exists |
That third option used to be rare because browsers weren't fast enough to run real conversion logic locally. WebAssembly changed that for a lot of everyday formats, which is why tools like Image Converter, Audio Converter, and PDF Merger can do the same job as an upload-based converter without a server touching your file at all. It's not a universal fix, heavy video encoding and some large AI-driven tasks genuinely make more sense server-side, but for the everyday PDF-to-image or MP3-to-WAV job, there's rarely a reason to upload anywhere anymore.
Before you upload anything sensitive
- 1Check whether the tool runs in your browser or a server, its About or Privacy page usually says so directly.
- 2Skim the privacy policy for a specific retention window, 'immediately deleted' and 'kept for 30 days' mean very different things.
- 3Never download or run an installer a 'converter' site prompts you to add, that's the FBI's specific warning sign for the malicious kind.
- 4For anything genuinely sensitive, tax forms, medical records, ID scans, prefer an offline tool or a browser-local one regardless of who runs the upload-based alternative.
Do free file converters sell my data?
It varies by service and isn't usually the headline risk, retention and vague deletion timelines are more common concerns than an outright data sale. Read the specific privacy policy rather than assuming either way.
How can I tell if a converter runs locally or uploads my file?
Check its About or Privacy page for language like 'processed in your browser' or 'client-side.' If the site works with your internet disconnected after the page loads, that's a strong sign it's local.
Is it illegal for a converter to keep my file?
Not inherently, retention is usually disclosed somewhere in the terms of service. It becomes a legal issue if a service violates its own stated policy or, for EU users, keeps personal data longer than GDPR's storage limitation principle allows.
What should I do if a 'converter' site asks me to download software?
Don't. Legitimate browser-based and upload-based converters do the conversion on the page itself or return a download of the converted file, they don't need you to install an application first.
Are Starlight's tools different from a typical upload-based converter?
The ones linked in this article run the conversion in your browser rather than uploading the file to a server, so there's nothing to retain. That's a structural difference, not a claim about any other specific service's practices.
Tools in this guide
Try the tools ✦
Free browser tools that never upload your files.
