FileIO — System Documentation
Confidential
FileIO
FileIO
Complete System
Documentation
Generated: September 07, 2026  ·  Confidential  ·  Internal Use Only
ASP.NET Core MVC (.NET 10) Entity Framework Core 10 SQL Server Razorpay Payments AES-256 Encryption 59 Features 3 Plans
1 System Overview

FileIO is a full-stack web platform built with ASP.NET Core MVC (.NET 10) that provides secure file sharing and a comprehensive suite of image, PDF, and AI-powered tools. Users earn or purchase credits to access premium features, with access controlled through a subscription plan system.

Technology Stack
🖥 Frontend
Razor Views (.cshtml) · Bootstrap 5 · Bootstrap Icons · Vanilla JS · Canvas API · face-api.js · exifr.js
⚙ Backend
ASP.NET Core MVC · C# · Entity Framework Core · ASP.NET Identity · Background Services · Email (SMTP)
🗄 Data
SQL Server · EF Core Migrations · DataSeeder (auto seeds plans, features, packages on startup)
🔌 External Services
Razorpay (payments, INR) · jsDelivr CDN · Bootstrap Icons CDN · Google Fonts
Key Design Principles
PrincipleImplementation
SecurityAES-256 encryption for stored files; TLS 1.2+ in transit; bcrypt password hashing; CSRF tokens on all forms; XSRF stripped from CDN requests
PrivacyFiles auto-deleted after 24 hours; IP stored only as hash; no advertising trackers
Credit systemEvery tool costs a defined credit amount; credits deducted server-side after validation; 401 if unauthenticated, 402 if insufficient credits
Guest accessFile sharing works without an account (GuestId cookie); other tools require login
Plan gatingNav items rendered per plan via ViewComponent; controller re-validates on every request
2 Subscription Plans
Free
₹0 / month
30 credits / month
  • Max file size: 10 MB
  • File sharing
  • QR Code Generator
  • Image to PDF
  • Crop, Resize, Rotate & Flip
  • Color Picker
  • File expiry: 1 hour
Pro
₹899 / month
1,000 credits / month
  • Max file size: 500 MB
  • Everything in Free
  • Image Upscale (AI)
  • Remove Background
  • OCR Text Extraction
  • Full PDF tools suite
  • Document conversions
  • Blur Faces, Metadata, Change DPI
  • Replace Background
  • File expiry: up to 7 days
Business
₹1,999 / month
5,000 credits / month
  • Max file size: 1 GB
  • Everything in Pro
  • AI Image Generator
  • Remove Image Watermark
  • QR Code Reader
  • URL Screenshot
  • Password-protected sharing
  • Add & Remove PDF Watermark
  • Edit PDF & PDF Editor Pro
  • AI PDF Summarizer
  • AI Writer
  • File expiry: up to 30 days
Yearly Billing Discount: 20% off — calculated as monthly price × 12 × 0.8. Credits are multiplied by 12 (full year allocation granted upfront).
PlanMonthly PriceYearly PriceCredits/moMax File SizeFile Expiry Cap
Free₹0₹03010 MB1 hour
Pro₹899₹8,6301,000500 MB7 days
Business₹1,999₹19,1905,0001 GB30 days
3 Credit Packages (Add-On)

Users on paid plans can purchase additional credits at any time. Add-on credits stack on top of monthly plan credits and do not expire.

PackageCreditsPrice (INR)Per Credit
Small500₹199~₹0.004
Medium1,500₹499~₹0.003
Large5,000₹1499~₹0.003
Credit Balance: Total = Plan Credits (remaining) + Add-On Credits. Credits are deducted only after successful tool execution. Failed or unauthenticated requests do not consume credits.
4 Feature Catalogue (59 Features)
#Feature KeyDisplay NameCategoryCredit CostFreeProBusiness
AI TOOLS
1AIImageGenerateAI Image GeneratorAI Tools5 / 7
2AIPdfSummarizerAI PDF SummarizerAI Toolsdynamic
3AIWriterAI WriterAI Tools3
CORE
4FileShareFile ShareCore0
5PasswordProtectionSharingPassword ProtectionCore0
6QRReaderQR Code ReaderCore2
7QRGeneratorQR GeneratorCore2
8UrlToScreenshotURL ScreenshotCore2
DOCUMENT
9CsvToJsonCSV to JSONDocument1
10JsonToCsvJSON to CSVDocument1
11JsonToXmlJSON to XMLDocument1
12JsonToYamlJSON to YAMLDocument1
13MarkdownToHtmlMarkdown to HTMLDocument1
14XmlToJsonXML to JSONDocument1
15YamlToJsonYAML to JSONDocument1
IMAGE TOOLS
16BlurFacesBlur FacesImage Tools1
17ChangeDPIChange DPIImage Tools1
18ColorPickerColor PickerImage Tools1
19CropImageCrop ImageImage Tools1
20ExtractTextExtract Text (OCR)Image Tools3
21ImageCompressImage CompressImage Tools2
22ImageConverterImage ConverterImage Toolsdynamic
23ImageMetadataImage MetadataImage Tools1
24ImageUpscaleImage UpscaleImage Toolsdynamic
25RemoveBackgroundRemove BackgroundImage Tools3
26RemoveImageWatermarkRemove Image WatermarkImage Tools5
27ReplaceBackgroundReplace BackgroundImage Tools4
28ResizeImageResize ImageImage Tools1
29RotateFlipRotate & FlipImage Tools1
30TextWatermarkText WatermarkImage Tools4
31PassportPhotoPassport PhotoImage Tools3
32MemeGeneratorMeme GeneratorImage Toolsdynamic
PDF & ADVANCED
33AddPDFWatermarkAdd PDF WatermarkPDF & Advanced4
34CompressPDFCompress PDFPDF & Advanceddynamic
35EditPDFEdit PDFPDF & Advanceddynamic
36ExcelToPDFExcel to PDFPDF & Advanceddynamic
37ExtractPDFTextExtract PDF TextPDF & Advanceddynamic
38HTMLToPDFHTML to PDFPDF & Advanced3
39MarkdownToPDFMarkdown to PDFPDF & Advanced2
40ImageToPDFImage to PDFPDF & Advanceddynamic
41MergePdfMerge PDFPDF & Advanceddynamic
42PDFToExcelPDF to ExcelPDF & Advanceddynamic
43PDFToImagePDF to ImagePDF & Advanceddynamic
44PDFToJPGPDF to JPGPDF & Advanceddynamic
45RemoveWatermarkRemove PDF WatermarkPDF & Advanced5
46RotatePDFRotate PDFPDF & Advanced1
47SignPDFSign PDFPDF & Advanced2
48SplitPDFSplit PDFPDF & Advanceddynamic
49TextToPDFText to PDFPDF & Advanced1
50WordToPDFWord to PDFPDF & Advanceddynamic
51LockPDFLock PDFPDF & Advanced2
52UnlockPDFUnlock PDFPDF & Advanced2
53DeletePDFPagesDelete PDF PagesPDF & Advanced2
54ReorderPDFPagesReorder PDF PagesPDF & Advanced2
55ExtractPDFPagesExtract PDF PagesPDF & Advanced2
56AddPageNumbersAdd Page NumbersPDF & Advanced2
57PDFEditorProPDF Editor (text, shapes, forms, links, signatures)PDF & Advanceddynamic
58ComparePDFCompare PDFPDF & Advanceddynamic
59PDFToMarkdownPDF to MarkdownPDF & Advanceddynamic
Dynamic credit cost means the cost is calculated per-use in the controller (e.g. based on number of pages for PDF tools, or file size for upscale). 0 cost means the feature is free to use but may require an account.
5 How Each Feature Works
5.1 — File Share

The core feature. Users upload one or more files which are encrypted with AES-256 and stored on the server. A unique ShareId (passcode) is generated and shared with recipients.

Select Files Chunked Upload AES-256 Encrypt Generate ShareId Share Link/QR Recipient Downloads Auto-Delete
DetailValue
Max file size10 MB (Free) · 500 MB (Pro) · 1 GB (Business)
Expiry1 h (Free/Guest); 24 h default for Pro/Business — extendable up to 7 / 30 days by plan
Password protectionBusiness plan only — bcrypt-hashed password required to download
Guest accessNo login required; tracked via GuestId cookie
EncryptionAES-256, unique key per upload stored encrypted in DB
Multi-fileMultiple files zipped on download
Credit cost0 (free)
5.2 — Image Tools (Client-Side Processing)

All basic image tools run entirely in the browser using the Canvas API — no image data is sent to the server. A POST request is made only to deduct 1 credit after the operation completes.

ToolHow It WorksMax SizeCreditsPlan
Crop ImageTouch-friendly canvas overlay with corner handles, rule-of-thirds grid, live dimensions.7 MB1Free+
Resize ImageUser enters target width/height (with optional aspect-ratio lock). Canvas redraws and exports resized image.7 MB1Free+
Rotate & Flip4 buttons: Rotate CW, Rotate CCW, Flip Horizontal, Flip Vertical. Canvas transforms applied cumulatively.7 MB1Free+
Color PickerClick anywhere on the uploaded image to sample the pixel color. Displays HEX, RGB, HSL values with one-click copy.7 MB1Free+
Blur Facesface-api.js (TinyFaceDetector) detects all faces; each region is pixelated using Canvas block averaging.7 MB1Pro+
Image Metadataexifr.js reads EXIF data client-side. Displays: File Info, Camera settings, Exposure, GPS, Colour profile.7 MB1Pro+
Image UpscaleServer-side AI upscaling (4× enhancement via ONNX Real-ESRGAN model). Credits based on longest side: ≤500 px = 2, ≤1000 px = 3, ≤1200 px = 4.7 MB2 – 4Pro+
Remove BackgroundServer-side AI background removal.7 MB3Pro+
Replace BackgroundRemove background then composite a new background image.7 MB4Pro+
Image CompressServer-side compression with quality control.2Pro+
Image ConverterConvert between JPG, PNG, WebP, BMP, SVG, HEIC, AVIF, TIFF, ICO formats.dynamicPro+
Text WatermarkAdd custom text overlay with font, size, position, opacity controls.4Pro+
Remove Image WatermarkAI-powered watermark removal from images.5Business
Extract Text (OCR)Optical Character Recognition — extract text content from images using Tesseract.7 MB3Pro+
Change DPIRewrites the DPI/PPI metadata of an image. Pixels unchanged — metadata only.7 MB1Pro+
Passport PhotoCountry-preset passport photos with white or solid-color background. Print-ready 4×6" sheet with multiple copies.7 MB3Pro+
Meme GeneratorUpload any image and add top/bottom caption text. Supports Classic (single image with text) and Panel (2–4 image comic strip) modes. Font size, colour, and stroke customisable. Credits: Classic = 1, Panel 2–3 = 2, Panel 4 = 3.7 MB1 – 3Free+
5.3 — PDF Tools (Server-Side Processing)

All PDF operations are processed server-side. Files are uploaded, processed in memory, and the result is returned for download.

ToolHow It WorksCreditsPlan
Image to PDFConverts one or more uploaded images into a single PDF document.dynamicFree+
Merge PDFCombines multiple PDF files into one, maintaining page order. Max 20 MB per file; up to 20 PDFs per merge.dynamicPro+
Split PDFSplits a PDF by page range, or (when no range is given) splits every page into its own PDF. Credits scale with the input PDF's page count; explicit range is discounted one tier vs. no range. Max 20 MB.dynamicPro+
Compress PDFReduces PDF file size by optimising embedded images and resources.dynamicPro+
PDF to ImageRenders each PDF page as a high-resolution image (JPG/PNG).dynamicPro+
Extract PDF TextExtracts all text content from a PDF into a plain-text file.dynamicPro+
Add PDF WatermarkStamps a text or image watermark on every page of a PDF.4Business
Remove PDF WatermarkAttempts to remove watermark layers from a PDF document.5Business
Word to PDFConverts .doc/.docx to PDF via LibreOffice headless. Preserves fonts, tables, layout. Max 20 MB.dynamicPro+
Excel to PDFConverts .xls/.xlsx to PDF via LibreOffice headless. Preserves formatting. Max 20 MB.dynamicPro+
Rotate PDFRotates pages by 90°, 180°, or 270°. Supports All / Odd / Even page selection. Max 20 MB.1Pro+
PDF to JPGRenders each PDF page as JPEG (quality 10–100%). Returns all pages in a ZIP archive. Max 20 MB.dynamicPro+
Text to PDFConverts plain text into a formatted PDF. Supports font size and alignment options.1Pro+
HTML to PDFConverts raw HTML to PDF using Playwright Chromium headless. Renders full CSS styling.3Pro+
Markdown to PDFPaste or upload Markdown; rendered through Markdig into a GitHub-styled A4 PDF via Playwright headless.2Pro+
Edit PDFAdd text annotations to PDF pages. Canvas-based editor with font, color, drag-to-reposition. Applied via PdfSharpCore.dynamicBusiness
Sign PDFDraw signature on canvas or upload image, place on any page. Composited via SkiaSharp, reassembled via QuestPDF.2Pro+
PDF to ExcelExtracts text and tabular data from PDF to .xlsx. Uses PdfPig + ClosedXML. Column detection via whitespace analysis. Max 20 MB.dynamicBusiness
Lock PDFAdds AES-128 password protection via PdfSharpCore. Restricts copying, editing, annotations while allowing reading.2Pro+
Unlock PDFRemoves password protection. User must supply correct password. Credits refunded on wrong password.2Pro+
Delete PDF PagesClient renders thumbnails via pdf.js; user clicks pages to mark for deletion. Server rebuilds via PdfSharpCore.2Business
Reorder PDF PagesClient renders thumbnails via pdf.js; SortableJS enables drag-drop reordering. Server rebuilds in submitted order.2Business
Extract PDF PagesUser selects pages to keep; server builds a single combined PDF. Differs from Split (which returns a ZIP).2Business
Add Page NumbersAdds page numbers with position (6 choices), format, font size, margin, skip-first-page toggle. Uses PdfSharpCore.2Business
PDF EditorFull visual editor: text, images, signatures, shapes, freehand, highlights, whiteout, links, form fields. Canvas via Fabric.js; server-side via PdfSharpCore + iTextSharp; autosave drafts; saved signature slots (3); find & replace; page thumbnail rail. Max 20 MB.dynamicBusiness
Compare PDFUpload two text-based PDFs; server extracts text via PdfPig, runs an LCS (Longest Common Subsequence) diff, and returns a side-by-side colour-coded diff table (green = added, red = removed, grey = unchanged). Toggle to show/hide unchanged lines. Max 20 MB each.dynamic (3–8)Business
PDF to MarkdownExtracts text from a PDF using PdfPig with font-size analysis to detect headings (H1/H2/H3), bold labels, and bullet/numbered lists. Monospace fonts are wrapped in fenced code blocks. Outputs a clean .md file for download with an inline preview. Max 20 MB.dynamic (2–7)Pro+
5.3b — Document Conversion Tools
ToolHow It WorksCreditsPlan
JSON to CSVParses a JSON array and converts to CSV. Handles nested flat objects.1Pro+
CSV to JSONParses a CSV file (with header row) and converts to a JSON array of objects.1Pro+
XML to JSONParses an XML document and converts to a JSON object representation.1Pro+
JSON to XMLConverts a JSON object or array to a well-formed XML document.1Pro+
YAML to JSONParses a YAML file and converts to a JSON object.1Pro+
JSON to YAMLConverts a JSON object to YAML format.1Pro+
Markdown to HTMLRenders a Markdown document as a styled HTML page. Supports headings, lists, tables, code blocks.1Pro+
5.4 — Core & AI Tools
ToolHow It WorksCreditsPlan
AI Image GeneratorGenerates images from a text prompt using Pollinations.ai (FLUX model) — free, no API key required. Square (1024×1024), Landscape, or Portrait size options.5 / 7Business
AI PDF SummarizerUpload any text-based PDF (max 20 MB). PdfPig extracts text locally; Groq API (openai/gpt-oss-20b) generates a structured summary with Overview, Key Points, and Conclusions. Dynamic credit cost by page count.3–12Business
AI Writer12 writing tools powered by Groq API: Essay, Paragraph, Complete Text, Story, Article, Grammar Fix, Summarize, Rewrite, Bullet Points, Email, Blog Post, Sentence Improver. Up to 5,000 characters input; optional tone and language settings.3Business
QR GeneratorGenerates a QR code from any text or URL. Client-side rendering with download as PNG/SVG.2Free+
QR ReaderUpload an image containing a QR code; server decodes and returns the embedded text or URL.2Business
URL ScreenshotCaptures a full-page screenshot of any URL using Playwright Chromium. Returns a PNG or JPG image.2Business
6 Credit System
User registered Assigned Free plan (30 credits) Uses tool Server validates credits Credits deducted Tool executes
EventEffect on Credits
New registrationFree plan assigned → 30 credits added
Plan subscriptionPlan credits added for the billing period
Plan renewal (monthly)Credits reset to plan allocation
Yearly subscriptionPlan credits × 12 added upfront
Credit package purchaseAdd-on credits stacked on top of plan credits
Tool usageCreditCost deducted; transaction logged in CreditTransaction table
Plan downgradeUnused credits do not carry over
0 creditsServer returns HTTP 402; UI redirects to pricing page after 5 seconds
Credit balance formula: Total Credits = RemainingCredits (plan) + AddOnCredits
Both stored in UserSubscription table per user. Every tool use records an entry in CreditTransaction with action name and timestamp.
6.1 Credit Cost Breakdown

All credit costs are defined as constants or static methods in Service/CreditCalculator.cs — the single source of truth. Controllers never hardcode credit amounts.

Fixed-Cost Features
FeatureCredits Deducted
Crop Image1 credit
Resize Image1 credit
Rotate & Flip1 credit
Blur Faces1 credit
Image Metadata1 credit
Color Picker1 credit
Rotate PDF1 credit
Text to PDF1 credit
JSON to CSV / CSV to JSON / XML to JSON / JSON to XML / YAML to JSON / JSON to YAML / Markdown to HTML1 credit each
QR Code Generator2 credits
QR Reader2 credits
Image Compress2 credits
URL Screenshot2 credits
Markdown to PDF2 credits
Sign PDF / Lock PDF / Unlock PDF2 credits each
Delete / Reorder / Extract PDF Pages / Add Page Numbers2 credits each
Image OCR / Extract Text3 credits
Remove Background3 credits
HTML to PDF3 credits
Passport Photo3 credits
Text Watermark (image)4 credits
Add PDF Watermark4 credits
Replace Background4 credits
Remove Image Watermark5 credits
Remove PDF Watermark5 credits
Change DPI1 credit
Dynamic-Cost Features
FeatureConditionCredits
AI Image GeneratorSquare (1024×1024)5
Landscape (1366×768)7
Portrait (768×1366)7
Image UpscaleLongest side ≤ 500 px2
Longest side ≤ 1000 px3
Longest side ≤ 1200 px4
Image ConverterSVG / HEIC / AVIF / TIFF / ICO conversions2
All other conversions1
Image to PDF1 – 5 images0
6+ images1 per additional 5 (ceiling)
PDF MergeN PDFs mergedN credits
PDF Split (with explicit range)1 – 10 pages1
11 – 50 pages1
51 – 100 pages2
Over 100 pages3
PDF Split (no range → split every page)1 – 10 pages1
11 – 50 pages2
51 – 100 pages4
Over 100 pages6
PDF Compress / PDF to Image / PDF to JPG / OCR PDF1 – 10 pages1 – 2
6 – 20 pages4
11 – 50 pages2 – 4
Over 20 / 50 / 100 pages4 – 6
Word to PDF / Excel to PDFUp to 1 MB2
1 MB – 5 MB3
Over 5 MB5
PDF to ExcelUp to 1 MB3
1 MB – 5 MB4
Over 5 MB6
AI PDF Summarizer1 – 5 pages3
6 – 20 pages5
21 – 50 pages8
51+ pages12
AI WriterAll 12 tools (flat rate)3
Edit PDF1 – 5 pages2
6 – 20 pages3
21+ pages5
PDF Editor ProBase: 1 – 5 pages3
Base: 6 – 20 pages5
Base: 21+ pages8
+1 per 10 elements; +2 if AcroForm; max 20variable
Meme GeneratorClassic meme (single image)1
Panel (2 – 3 images)2
Panel (4+ images)3
Compare PDFTotal pages ≤ 103
Total pages ≤ 405
Total pages > 408
PDF to Markdown1 – 5 pages2
6 – 20 pages3
21 – 50 pages5
51+ pages7
Source of truth: All values above map directly to constants and methods in Service/CreditCalculator.cs. To change any cost, update only that file — controllers read from it automatically.
7 Authentication & User Accounts

Authentication is built on ASP.NET Core Identity with SQL Server storage.

FeatureDetail
RegistrationEmail + password; email confirmation required. Required profile fields: Full Name, Address, State, Country (locked after first save), Postal Code.
LoginCookie-based; optional "Remember me" (30-day persistent cookie)
Password storagebcrypt hash — plaintext never stored
Password resetEmail link with time-limited token
RolesUser, Admin — Admin can access Admin Panel
Guest uploadsFile sharing works without account via GuestId cookie
Profile pageShows plan, credits used/remaining, subscription end date, billing cycle, days remaining; subscription alerts
Two-Factor Authentication (2FA)TOTP-based 2FA available on Profile page. User scans QR code with authenticator app. Also supports email-based 2FA. Recovery via email code if TOTP device is lost.
Account deletion Soft delete — data not immediately destroyed. Immediately: Uploads marked DeletedAt=now; DeletedAccounts row created with PurgeAt = +30 days; Identity locked out; confirmation email sent.

After 30 days (background job): Hard-deletes all user data (files, credits, subscriptions, Identity record). Marks Purged=true.
Account reactivation Available within 30-day soft-delete window. User enters email → receives reactivation link with 24-hour token → link unlocks Identity, restores uploads, removes DeletedAccounts record.
8 Billing & Payments

Payments are processed via Razorpay (INR currency). No card data touches our servers.

User selects plan Checkout page Razorpay order created User pays Signature verified Subscription activated Confirmation email sent
ScenarioBehaviour
New subscriptionCreates UserSubscription record; credits added; email sent
RenewalExisting subscription extended; credits refreshed
Upgrade mid-cycleNew plan applied immediately; credits updated to new plan allocation
CancellationSets CancelAtPeriodEnd = true; access continues until period end; cancellation email sent
Credit purchaseSeparate Razorpay order; credits added to AddOnCredits; receipt email sent
RefundsAll purchases are final (per Terms of Service), except where required by law
Transaction recordStored in Checkout / CreditPurchase tables with TransactionId from Razorpay
8.1 Multi-Currency Display & Payment

Prices across the platform can be displayed and charged in INR (₹), USD ($), or SAR (﷼). Currency selection affects both the displayed price and the actual Razorpay order amount.

AspectDetail
SelectionCurrency dropdown in navbar. Choice saved to localStorage under key fs-currency. Sent as currency field in the CreateOrder JSON body.
Exchange ratesFixed rates loaded at startup from appsettings.json → CurrencyRates into the singleton CurrencyRateService. Also injected into the page as window.CURRENCY_RATES.
Server-side conversionBillingController.ConvertPrice() multiplies the base INR price by the selected rate and converts to the smallest currency unit before creating the Razorpay order.
PaymentRazorpay order is created with the converted amount and the selected currency code. International payment support must be enabled in the Razorpay dashboard for non-INR currencies.
Allowed currenciesValidated server-side against _allowedCurrencies HashSet. Unknown values fall back to INR.
Order sessionCurrency stored in server-side session alongside planId and cycle so verify endpoints cannot be spoofed.
Checkout recordCheckout.Currency field records which currency was charged for audit and admin revenue display.
Admin pagesRevenue pages use data-inr attributes; refreshInrSpans() converts them on load and on currency change.
Supported Currencies
CurrencySymbolRate source
Indian Rupee (INR)Base — rate 1.0 (no conversion)
US Dollar (USD)$appsettings.json → CurrencyRates:USD
Saudi Riyal (SAR)appsettings.json → CurrencyRates:SAR
Adding a New Currency
  1. Add the rate to appsettings.json → CurrencyRates and map it in CurrencyRateService.
  2. Add the currency code to _allowedCurrencies in BillingController.
  3. Handle the new rate in BillingController.ConvertPrice() switch expression.
  4. Add the currency option to the navbar dropdown and update window.CURRENCY_RATES in both layouts.
  5. Enable the currency in your Razorpay dashboard (Settings → International Payments).
To update exchange rates: Change the values in appsettings.json → CurrencyRates and restart the app. No code changes required.
8.2 Subscription Grace Period

When a paid subscription expires, users are not immediately downgraded. A 5-day grace period is granted, during which the account retains full plan access.

StateConditionEffect
Activenow ≤ EndDateFull plan access; DaysRemaining ≥ 0
Grace periodEndDate < now ≤ EndDate + 5 daysFull access retained; Profile shows "X days left in grace period" warning
Expirednow > EndDate + 5 daysBackground service downgrades user to Free plan and sends expiry email
Grace period constant: SubscriptionGraceRules.GracePeriodDays = 5. Change only this value to adjust the grace window.
Profile Page Alerts
DaysRemainingAlert shownStyle
= 0"Your subscription will end today."Danger
1 – 3"Your subscription will end in N day(s)."Danger
4 – 10"Your subscription will end in N days."Warning
< 0 (grace)"Your subscription has expired. X day(s) left in grace period."Danger
9 Navigation & UI System

The navbar dynamically renders features based on the logged-in user's plan using a ViewComponent (SubscriptionMenuViewComponent). Features not in the user's plan are simply not shown.

Nav GroupTypeDescription
File Share, URL Screenshot, QR Generator, QR ReaderCore flat linksDirect nav links, always visible if plan includes them
Image ToolsMega menu4-column mega menu: Edit · Enhance · Analyze · Privacy, plus AI Image Generator promo card
PDF & AdvancedMega menu4-column mega menu: Convert · Organize · Optimize · Protect, plus Upgrade Plan promo card
DocumentCompact panel dropdown420 px panel with 2-column grid for JSON conversions and Markup. Pro+ only.
AI ToolsStandard dropdownSimple dropdown for AI Image Generator and AI Writer
Mega menu positioning: Uses CSS :has() selector — .nav-dropdown:has(.mega-menu) { position: static; } — so the absolute-positioned menu stretches full-width relative to the sticky navbar.
UI Themes

The app supports light and dark mode toggled via a button in the navbar. Theme preference is saved in localStorage and applied via data-theme="dark" on the <html> element.

10 Core Data Models
ModelKey FieldsPurpose
SubscriptionPlanName, Price, Credits, MaxFileSizeBytesDefines plan tiers and their limits
UserSubscriptionUserId, PlanId, StartDate, EndDate, RemainingCredits, AddOnCredits, BillingCycle, CancelAtPeriodEndTracks active subscription per user
FeatureKey, DisplayName, Category, CreditCost, ControllerName, ActionName, SortOrderAll 59 platform features with routing info
PlanFeaturePlanId, FeatureIdMany-to-many: which features belong to which plan
CreditPackageName, Credits, Price, ActiveAdd-on credit bundles available for purchase
CreditTransactionUserId, CreditUsed, Action, CreatedAtAudit log of every credit deduction
CreditPurchaseUserId, CreditsAdded, Amount, TransactionIdRecord of every credit package purchased
UploadShareId, FileName, FileSize, ExpiresAt, IsPasswordProtected, EncryptedKeyUploaded file metadata and encryption key
DownloadShareId, DownloadAt, ClientIpHashDownload audit per share link
CheckoutUserId, PlanId, Price, Credits, Duration, Status, TransactionIdPayment intent and result for plan purchases
11 Security Architecture
LayerMeasure
TransportTLS 1.2+ enforced; HTTPS redirect middleware
File encryptionAES-256 at rest; unique key per upload; key stored encrypted in DB
Passwordsbcrypt hash with work factor 12 (ASP.NET Identity default)
CSRFAnti-forgery tokens on all POST forms and AJAX requests; stripped from CDN calls
Rate limitingUpload and download endpoints rate-limited by IP
Credit gatingServer-side validation on every tool endpoint; client-side JS does not control access
Plan gatingController checks HasFeature() on every tool request; plan from DB, not session
IP loggingStored as hash only (not plaintext) in Download records
File auto-deleteBackground service purges expired uploads every hour
Virus scanningEvery uploaded file is scanned by Windows Defender before being written to disk
11.1 Virus Scanning

Every file is scanned for malware before it is encrypted and stored. Scanning is handled by Windows Defender via MpCmdRun.exe — no third-party service required.

How It Works
File received Written to temp path MpCmdRun.exe scans Clean → encrypt & store
Threat detected Temp file deleted HTTP 400 returned Upload blocked
AspectDetail
ScannerWindows Defender (MpCmdRun.exe -Scan -ScanType 3 -File)
Location%ProgramFiles%\Windows Defender\MpCmdRun.exe
Exit codes0 = clean · 2 = threat found · other = scan error
On scan errorUpload proceeds (non-fatal) — scan errors do not block users
If Defender missingScan is silently skipped — upload proceeds
Temp fileWritten to Path.GetTempPath(), deleted immediately after scan regardless of result
Config keyappsettings.json → VirusScan:Enabled (true/false)
Service classService/VirusScanService.cs
Test Endpoint

Admins can verify scanning is active by visiting /Admin/TestVirusScan. It scans the standard EICAR test string.

Response StatusMeaning
workingDefender detected EICAR — scanning is fully active
disabled_or_not_detectedVirusScan:Enabled is false, or Defender path not found
errorUnexpected exception — message field contains details
To disable scanning: Set "Enabled": false under VirusScan in appsettings.json and restart. Useful for development environments without Windows Defender.
12 Email Notifications
TriggerEmail Sent
RegistrationEmail confirmation link
Password resetReset link with time-limited token
Subscription activatedPlan confirmation with credits and expiry date
Subscription cancelledCancellation confirmation; access-until date
Subscription expiring soonExpiry reminder (sent via background service)
Subscription expired / grace periodGrace period notice; downgrade warning
Credit purchaseReceipt with credits added and new balance
Account deletionDeletion confirmation; explains 30-day recovery window before permanent purge
Account reactivation linkReactivation link with 24-hour expiry token
2FA / verification codeOne-time code for two-factor login or email verification flows
13 Background Services

Three hosted services run continuously in the background. All are registered in Program.cs via AddHostedService<>.

ServiceFileIntervalWhat It Does
FileService Service/FileService.cs Every 5 minutes 1. Expire uploads: Finds Uploads where ExpiresAt ≤ now (and not already soft-deleted). Deletes the .enc file from disk, removes the Upload DB row.

2. Purge deleted accounts: Finds DeletedAccounts where PurgeAt ≤ now and Purged = false. Hard-deletes all user data (files, credits, subscriptions, Identity record). Sets Purged = true.
SubscriptionExpireService Service/SubscriptionExpireService.cs Every 1 minute Finds active paid subscriptions where EndDate + GracePeriodDays < now. Downgrades each to the Free plan: resets RemainingCredits to Free plan credits, updates SubscriptionId, sets AddOnCredits = 0.
SubscriptionExpireEmail Service/SubscriptionExpireEmail.cs Every 24 hours Sends expiry reminder emails. Targets subscriptions expiring in exactly 1, 3, or 7 days (configurable). Uses EmailHtml.GetSubscriptionExpireEmailHtml() for HTML template. Sends grace-period notice via GetGracePeriodEmailHtml() for subscriptions past EndDate but within the grace window.
Overlap protection: SubscriptionExpireService and SubscriptionExpireEmail run independently. Email is sent based on days-until-expiry check; downgrade only happens after the grace period expires. No flags are written to prevent double-processing — the time condition is the guard.
14 Admin Panel

Accessible only to users with the Admin role at /Admin/. Uses a separate layout (_AdminLayout.cshtml) with its own sidebar navigation and currency display.

PageRouteWhat It Shows / Does
Dashboard/Admin/DashboardTotal users, active subscriptions, revenue (INR / converted), recent signups, plan distribution chart, today's credit usage.
Users/Admin/UsersPaginated list of all users with plan, credits, subscription status, join date. Search by email. View individual user details. Manually adjust credits.
Revenue/Admin/RevenueChronological list of all Checkout and CreditPurchase transactions. Filter by date range or plan. Export to CSV. Currency-convertible display.
Expiring Subscriptions/Admin/ExpiringSubscriptionsLists subscriptions expiring within a configurable number of days. Highlights urgency: red (≤2 days), amber (≤7 days).
Feature Seeder/Admin/SeedFeaturesRe-runs DataSeeder to add any missing features or plan assignments without wiping existing data.
Test Virus Scan/Admin/TestVirusScanScans the EICAR test string to verify Windows Defender is active. Returns working, disabled_or_not_detected, or error.
Credit Packages/Admin/CreditPackagesCreate, edit, activate, or deactivate add-on credit packages available on the Buy Credits page.
Role assignment: The first admin account is seeded at startup from appsettings.json → AdminUser. Additional admins must be assigned the Admin role directly in the database — there is no in-app role management UI.
15 Quick Register & Checkout Flow

On the Pricing page, unauthenticated users clicking a paid plan button open a modal (Quick Checkout modal) that registers the account and redirects to Checkout in a single step.

Click plan button Quick Checkout modal opens Fill details POST /Account/QuickRegister Account created & signed in Redirect to /Billing/Checkout
DetailValue
EndpointPOST /Account/QuickRegister — returns JSON { success, redirectUrl, error }
Fields collectedFull Name, Email, Password, Confirm Password, Street Address, City, State, Country, Postal Code
Plan & cycleHidden fields in the modal form; forwarded to checkout URL as query params
Client validationInline JS validates all fields before submitting (required, email format, password strength: 8+ chars, uppercase, number, special char)
On server errorJSON error message mapped to the relevant field (email already taken, weak password, etc.)
Billing cycleReflects whatever toggle (Monthly / Yearly) was active when the modal opened