Privacy Policy
Last updated: June 29, 2026
This policy explains how the WAV to MP3 converter (the “Service”) — available at wavtomp3.app and as the “WAV to MP3” Chrome extension — handles information when you use it. The same policy applies to both surfaces.
At a glance
- Your WAV and MP3 files stay on your device. We never upload, read, or store the contents of your audio.
- Conversion runs locally in your browser through WebAssembly (FFmpeg).
- We collect anonymous, aggregated usage events so we can fix bugs and improve the product. No accounts, no profiles, no personal identifiers.
- We honour your browser's Do Not Track and Global Privacy Control signals — when set, analytics are skipped.
- You can stop analytics at any time by removing the extension, clearing your browser storage, or enabling DNT.
What we collect
We collect a small set of anonymous events that describe how the converter is used, not what you converted:
- A randomly generated device identifier that is not linked to your name, email, or any account.
- The technical surface in use (“website” or “extension”).
- Conversion events: file size in bytes, selected bitrate, processing duration, output size, success or error code, batch size.
- Generic browser metadata that PostHog collects by default for any web event (browser family, operating system, country derived from IP, screen size). IPs are anonymised before storage.
- On the website only: page views (URL path, referrer) for the public pages of wavtomp3.app.
What we do NOT collect
- The contents of your audio files. WAV bytes never leave the browser tab or the extension's offscreen document.
- Your browsing history outside of the Service's own pages.
- The text you type, the pages you visit, or the files you open in other tabs.
- Your name, email address, or any identifier you have not voluntarily submitted via the contact form.
- Precise location, advertising identifiers, or behavioural-tracking pixels.
How conversion works
All audio conversion runs entirely on your device. The Service ships an FFmpeg WebAssembly build that decodes WAV input and encodes MP3 output inside a Web Worker (on the website) or an offscreen document (in the extension). At no point is your audio uploaded to a server, sent to a third party, or stored on remote infrastructure.
Downloads are produced as browser-local Blob objects and saved through your browser's standard download flow.
Analytics
We use PostHog (EU region, eu.posthog.com) as a privacy-respecting product-analytics processor. Events listed above are sent to PostHog's EU infrastructure. The project is configured with IP anonymisation, no session recording, no autocapture, and no third-party advertising integrations.
On the website, when an analytics ID such as NEXT_PUBLIC_GA_ID is configured, page views are additionally counted via Google Analytics 4 with anonymised IP. The extension does not load Google Analytics.
We will not record analytics if your browser reports Do Not Track or Global Privacy Control. We also block obvious bot traffic from our analytics by user-agent.
Cookies and local storage
- Website. PostHog sets a first-party cookie and writes to
localStorageto keep an anonymous device ID consistent across reloads. Your bitrate and auto-download preference are stored inlocalStorage. No third-party advertising cookies are set. - Extension. User preferences (default bitrate, auto-download), the local conversion queue, and the anonymous analytics ID are stored via
chrome.storage.localon your device. Nothing is synced across devices by default.
Third-party processors
- PostHog (EU). Anonymous product-analytics events. EU hosting, IP anonymisation, GDPR DPA available on request from the operator.
- Cloudflare. Edge hosting and CDN delivery for the website. Standard request logs (IP, timestamp, URL) are processed by Cloudflare for fraud, security and performance purposes per its privacy policy.
- Google Analytics 4 (website only, when configured). Anonymised page-view counts. See Google's privacy policy.
- Contact form provider (website only). If you write to us through the contact form, your message and the email address you provide are transmitted to our email-delivery provider so we can reply. No marketing use.
Chrome extension permissions
The extension declares the minimum set of permissions required to perform local conversion and remember your settings. Each permission is used only for the purpose listed below:
Permissions in active use
storage— saves your default bitrate, the “Download after conversion” toggle, the current conversion queue, and the anonymous analytics ID tochrome.storage.local. Nothing is uploaded.offscreen— opens a hidden offscreen document so the FFmpeg WebAssembly encoder can keep converting files after you close the side panel. Required because Chrome's service worker for MV3 extensions cannot run long-lived audio processing on its own.sidePanel— opens the converter UI as a Chrome side panel attached to the current window, so you can keep converting while browsing.
Permissions reserved for future updates
We may request these permissions in a future release. Each will be requested only at the moment the feature is enabled, and you will see the standard Chrome consent prompt before the permission becomes effective.
downloads— to save converted MP3 files via Chrome's native download manager, in addition to the current browser-anchor download flow.tabs/activeTab— to allow capturing the audio of the current browser tab and converting it to MP3 (planned feature; off by default).host_permissions— to surface the converter's action button as a contextual control on any website where you want to start a conversion. Used only to show the button; the extension does not read or modify page content.
None of the above permissions are used to track your browsing, read page content, send data outside your device, or modify pages you visit.
Data retention
- Anonymous analytics events are retained by PostHog for the duration of its standard EU retention window (currently up to 7 years for event data, configurable). They are not joined with any personal identifier.
- The local conversion queue and your settings remain on your device until you remove the extension, clear browser storage, or click “Clear all” in the side panel.
- Messages you send through the contact form are kept only as long as needed to reply, then deleted.
Your rights
If you are in the EEA, the UK, Switzerland, California, or another jurisdiction that grants individual data-protection rights, you may request access to, correction of, or deletion of any personal data we hold about you, and you may object to processing or withdraw consent at any time.
Because we do not maintain accounts or personally identifying records by default, most users will have no personal data on file. If you want the anonymous device identifier associated with your installation removed, contact us with a description of your situation and we will delete the corresponding PostHog person profile.
Children
The Service is not directed to children under 13. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us so we can delete it.
Changes to this policy
We may update this policy as the Service evolves or as legal requirements change. The “Last updated” date at the top of the page reflects the most recent revision. For material changes we will surface a notice inside the website or the extension before the change takes effect.
Contact
Questions about this policy or about data we may hold can be sent to mr.stan.mash@gmail.com.