Security Center
How PullDL handles files and media
PullDL uses different processing paths for different jobs. Browser-local conversion tools operate on files selected on your device. The downloader uses server-side extraction to inspect supported remote media URLs and retrieve the source stream needed for the requested download.
Browser-local file tools
Supported converter and compressor workflows process the selected file in the browser. PullDL does not need to upload the file itself for those tools. Practical limits depend on browser capabilities, available memory, and the complexity of the operation.
Downloader infrastructure
Downloader requests require remote media extraction. The browser receives an opaque, short-lived download target instead of a raw upstream stream URL. The target is validated before the server retrieves the source.
URL validation
PullDL accepts HTTP(S) media URLs and rejects local/private network targets during extraction and upstream retrieval. Redirects are validated as they are followed, which reduces common server-side request forgery risks.
Download tokens
Download targets are stored with a short time-to-live. The token is intentionally opaque and is separate from the upstream media address. In production, PullDL can use Redis for shared state across multiple backend instances.
Local activity history
Recent tool activity can be stored locally in the browser to make repeat workflows easier. This local history is separate from server-side download infrastructure and can be cleared from the interface.