creatorvalet

← Converter Privacy Index

How the index is measured

The index answers two narrow questions with repeatable HTTP requests. It does not test an upload, inspect runtime network traffic, audit security controls, or assign a safety score.

1. Homepage resources

The script requests each public homepage with the same disclosed user agent. From the HTML returned by the server it collects absolute resources referenced by script, link, img, and iframe elements. A host is counted when its registrable domain differs from the service’s own domain.

Canonical links, relative same-site resources, data: URLs, and subdomains of the service are not counted as third parties. The published count retains the host list so the number can be checked.

2. Public data-handling source

The script requests one public privacy or data-handling page for each service. Before any excerpt can be used, the response must be HTTP 200, HTML, long enough not to be a typical error page, and contain multiple privacy markers. Navigation, scripts, styles, templates, and markup are removed before the remaining text is hashed.

Candidate sentences must mention storage or deletion, a time expression, and file context. A small number of manually selected excerpts avoid a nearby sentence about server logs, accounts, or employment records. Those excerpts must still occur verbatim in the freshly fetched source or the run fails. No published excerpt is longer than 14 words.

3. Failure semantics

A timeout, challenge page, unexpected content type, broken source, or stale manual excerpt is reported as not measured. It can never become zero. Likewise, “not found” means the text search did not find a qualifying sentence; it does not mean the service has no retention statement elsewhere.

The boundary that matters most

The homepage measurement reads only server-delivered HTML. It does not run JavaScript. A consent manager, analytics client, advertisement, or application request inserted at runtime will not appear. A zero is therefore evidence about the delivered markup, not a complete inventory of browser traffic.

The method also never uploads a file. That avoids sending material to another service, avoids imposing conversion work on its infrastructure, and prevents a synthetic upload from being mistaken for evidence about every user or product mode.

Scope and selection

The baseline contains 25 services across general conversion, PDF, image, and video workflows, including CreatorValet. It is a deliberately broad comparison set, not a market share ranking or a claim that no other converter matters. The same fields and failure rules apply to the CreatorValet row.

Reproducing and citing a measurement

The project command is pnpm competitors --public-json. The publication snapshot was measured with the user agent below. The JSON export includes source hashes and exact host lists; the CSV is a flat projection of the same snapshot.

CreatorValetCompetitorCheck/1.0 (+https://creatorvalet.com; scripts/competitors.mjs; measuring third-party origins and public privacy policies)

Interpretation

A server can provide OCR, proprietary codecs, large-file queues, cloud history, collaboration, APIs, and cross-device workflows that a local browser tool cannot. The index records a difference in what a visitor can inspect; it is not an allegation that a server-based service is unsafe or acting improperly.