PRIVACY & SECURITY

Privacy Policy

Effective Date: September 29, 2026

Zero-Cloud Privacy Guarantee

ChameLeo is built upon an uncompromising zero-upload and local WebAssembly architecture. You never upload your files to any remote server; all conversions take place 100% locally inside your web browser. Your files never leave your device, are never stored on remote disks, and remain completely private.

1. Zero-Upload Architecture & Local Browser Processing

Conventional cloud file converters require uploading your files to remote server infrastructure where they are converted and temporarily stored. ChameLeo operates fundamentally differently: • Zero Server Uploads (No Upload): ChameLeo does not have any upload functionality. When you select or drag a file, it is never transmitted over the internet; it is opened directly in your local browser's memory (RAM) and processed on-device via WebAssembly. Not a single byte of file data is ever sent to our servers or any external party. • Immediate Memory Disposal: Converted files exist strictly as temporary in-memory buffers (local Blob objects) on your device. When you download the result or close the browser tab, the allocated memory is instantly purged by your browser's garbage collector. We do not maintain any server retention windows, cloud storage, or processing queues.

2. Information We Do Not Collect

Because our processing engine runs strictly client-side on your hardware, ChameLeo does not have access to, inspect, or collect: • The contents, text, audio tracks, or imagery of your files; • File names, directory paths, or file size metadata; • Embedded metadata, EXIF camera tags, author details, or GPS coordinates; • Account credentials or billing data (we do not offer paid tiers, subscriptions, or require user registration).

3. Contact Form & Optional Email Submissions

When you voluntarily contact us through our on-site Contact form, you provide a message subject, category, message content, and an optional email address (if you wish to receive a direct response). This data is securely transmitted and stored in our encrypted database solely for customer support, bug tracking, and responding to your inquiry. We never sell, rent, or lease your email address or contact information to third parties, nor do we use contact information for marketing, newsletters, or profiling. If you do not provide an email address, your message is submitted anonymously.

4. Legal Requests & Inability to Disclose Files

In traditional cloud services, user files and transmission logs can be subpoenaed or disclosed under court orders. At ChameLeo, it is technically impossible for us to produce, inspect, or hand over your files to any court, law enforcement agency, or government authority because we do not possess them. Your files never leave your device and are never recorded on our servers. For general infrastructure logs or contact form submissions, we comply strictly with lawful court orders as required by applicable legislation.

5. Browser Sandboxing, HSTS & Memory Security

Security is built into every layer of ChameLeo's web application: • HTTPS & Strict Transport Security (HSTS): All communications with our web delivery network use TLS 1.3 encryption and HSTS to prevent tampering or interception. • COOP & COEP Isolation: We enforce Cross-Origin Opener Policy (COOP) and Cross-Origin Embedder Policy (COEP) headers. This isolates browser memory threads and protects local processing buffers from cross-origin attacks or side-channel exploits. • No Public Download URLs: Output files are generated as volatile local object URLs (`blob:`). No external party or IP address can access or download your converted files from the internet.

6. Cookies, Tracking & Local Storage

Zero Advertising Cookies: ChameLeo does not deploy third-party advertising networks, does not use tracking pixels, and does not sell user behavioral data. Zero Cross-Site Tracking: We do not track you across other websites. We do not use third-party analytics scripts that profile individual users. Local Preferences Only: We utilize standard browser `localStorage` solely to store your UI preferences (dark/light theme, selected language, and favorite tools). This data remains strictly on your device and is never transmitted to our servers. You can clear it anytime in your browser settings.

7. External Requests & Third-Party Links

ChameLeo minimizes external network interactions to the strictest possible degree: • Static Content Delivery: Static assets (HTML, CSS, JavaScript, and compiled WASM libraries) are delivered via high-speed, secure Content Delivery Networks (CDNs). • Live Currency Rates: When using the Currency Converter tool, real-time exchange rates are fetched from public financial rate APIs. These requests transmit only currency ticker symbols (e.g., USD, EUR) and contain zero personal or file data. • Third-Party Links: External links on our site (such as format specifications) are provided for reference. We are not responsible for the privacy practices of external third-party sites.

8. GDPR, CCPA & KVKK User Rights

ChameLeo adheres to the European General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and the Turkish Law on the Protection of Personal Data (KVKK No. 6698): • For File Processing: Because files never leave your device, ChameLeo does not act as a cloud data processor of your files. Processing is executed directly by you on your own hardware under principles of Privacy by Design and Data Minimization. • For Contact Inquiries: ChameLeo Team acts as Data Controller for information voluntarily submitted via our Contact form. You have the right to request access, rectification, or permanent erasure of your submitted support inquiries by contacting us.

9. Children's Privacy

ChameLeo does not knowingly collect, solicit, or maintain personal information from children under the age of 13 (or under the applicable age of consent in your jurisdiction), complying with the Children's Online Privacy Protection Act (COPPA). Because our core conversion tools operate without user accounts or personal data capture, the service is safe for all audiences.

10. Policy Updates & Contact Information

We may update this Privacy Policy periodically to reflect new browser capabilities or regulatory standards. The effective date at the top of this document indicates when changes take effect. If you have questions, feedback, or privacy-related requests, please contact ChameLeo Team through our on-site Contact form or via email at support@chameleo.tools.

Privacy & Security FAQ

How does ChameLeo differ from traditional cloud converters regarding file retention?
Traditional cloud converters upload your files to remote servers and retain them for hours. ChameLeo features zero server uploads: your files are never transmitted to any server, and all processing runs 100% locally in your browser memory via WebAssembly and is purged the instant you close the tab.
Are my converted files accessible to anyone else via a URL?
No. Unlike cloud converters that generate server download URLs, ChameLeo generates local Blob URLs that exist only inside your browser. No one on the internet can access or download your files.
Is ChameLeo safe for sensitive, personal, or confidential documents?
Yes. Thanks to our zero-upload architecture, your files never travel across the internet or touch any remote server. Confidential documents, bank statements, ID scans, and private media are processed strictly within your device's browser memory (RAM), making third-party access technically impossible.
Can courts or government agencies compel ChameLeo to hand over my converted files?
No. Because files never touch our servers and are never saved on our disks, it is technically impossible for us to produce or disclose your files to anyone.
Does ChameLeo track users or use advertising cookies?
No. ChameLeo does not track you across other websites, deploy behavioral tracking cookies, or build user advertising profiles. We only use your browser's local storage (localStorage) to remember basic UI preferences like theme and language; this data remains strictly on your device and is never sent to any server.