BMP stores raster pixels with little or no compression in a bitmap container.
ICO stores a raster icon for Windows applications and browser favicons.
The source is decoded as one image.
Alpha transparency is retained when it is present in the decoded source pixels.
The destination encoder can change pixel values, bit depth, color representation, or file size.
ICO output is limited to a single image no larger than 256 by 256 pixels.
The worker applies EXIF orientation, converts pixels to 8-bit sRGB, and removes source metadata before encoding.
ICO is an icon container used by Windows applications and accepted by browsers for favicon files. A square source usually fits icon layouts better than a wide photograph. Crop or prepare the source before conversion when the important artwork would become unreadable at small sizes.
This route converts the BMP through the private image worker and validates the ICO signature before download. It does not promise that one ICO contains every common icon size. Inspect the downloaded file in the target application and confirm the dimensions actually written by the selected conversion settings.
A BMP source may have no useful alpha channel. Converting it to ICO cannot infer which background pixels should become transparent. Prepare transparency in an image editor first when the finished icon must sit cleanly on different backgrounds.
Thin lines, small text, and photographic detail often fail at favicon scale. Test the icon at 16 by 16, 32 by 32, and the largest size required by the destination. A valid ICO signature proves the container type, not that the artwork remains legible in every interface.
Set an optional width or height, preserve or change the aspect ratio, and choose output quality. Transparency is retained when the destination supports it.
One image is processed per request. Animated WebP, GIF, and multi-page TIFF retain all frames only when the destination also supports multiple frames. The input limit is 25 MB.
The web application validates the file before forwarding it to a private worker. The worker validates the signature again, processes the file inside a unique temporary directory, validates the output, and removes the job directory in a guaranteed cleanup path. Files are not written to the database or retained for analytics.
When you import from a URL, the application fetches only a validated public HTTP or HTTPS address, checks the downloaded file in memory, and applies the same worker cleanup rules. The URL, filename, and file contents are not sent to analytics.