Privacy Policy
Last updated 13 September 2026
The short version: checking and cleaning happen entirely inside your browser and never reach us. Text sent for rewriting is passed to our model provider, returned, and discarded — we do not store document contents and we do not train on them. We retain only a coarse use category, word-count range and repetition signal so we can understand usage and prevent abuse.
What happens to your text
Checking and cleaning are local. The artifact scanner and cleaner are JavaScript running on your device. Your text is not uploaded, not logged, and never leaves the page. You can verify this in your browser’s network tab — pressing the checker produces no request.
Rewriting is a server round trip. When you use the rewrite engine, your text is sent to our server and on to our model provider (DeepSeek, hosted on Microsoft Azure AI Foundry) to be processed. The result is returned to you. We do not write document contents to our database, and we do not retain them after the request completes. Before the text is discarded, software classifies the request into a broad category such as academic, marketing, professional, creative, technical, personal or suspicious test input. We store that category, a word-count range and whether the text was highly repetitive. We do not store a sample, title, hash or excerpt.
We do not train on your text, and we do not sell it or share it with anyone beyond the model provider needed to fulfil the request you asked for.
Your browser stores an unsent draft and your most recent rewrite locally so that signing in or losing a connection does not lose your work. Rewrite recovery data is saved on your device before credits are charged. These contents are not stored on our servers and are cleared when you sign out or clear this site’s storage.
What we do store
- Account — your email address, a hashed password (or the identifier from Google/GitHub if you used those), and account timestamps.
- Sessions — a session token, plus the IP address and user agent of the sign-in, used for security and abuse prevention.
- Credit ledger — every grant, spend and refund, including the word count of each job. We record how many words were processed, never which words.
- Usage classification — a broad content category, word-count range and repetition flag for rewrite attempts. This lets us distinguish product use from automated or deliberately repetitive abuse without retaining document contents.
- Billing reference — an identifier from our payment provider so purchases can be matched to your account.
Payments
Payments are handled by Dodo Payments as merchant of record. Card details are entered on their systems and are never seen by, sent to, or stored by us. We receive only a payment reference and the plan purchased.
Processors we use
- Vercel — hosting and delivery
- Neon — database (accounts, sessions, credit ledger)
- Microsoft Azure AI Foundry — model inference for the rewrite engine
- Dodo Payments — payments and tax
- Google / GitHub — only if you choose to sign in with them
Analytics
We use privacy-respecting product analytics to count page views and which features and broad rewrite categories get used, so we can tell whether the product works and which audiences it serves. We do not record the contents of your text, and we do not sell data to advertisers. We use Vercel Analytics for traffic, Umami for product events when configured, and our own database for signup, checkout, and usage metrics.
Cookies
We set a session cookie when you sign in. We also set two small first-party cookies while you browse: one recording where you arrived from (the referring site or campaign tag, and the page you landed on), and one holding a random identifier so we can tell that two visits came from the same browser. Both last 90 days.
No advertising cookies, no cross-site tracking, and nothing reads what you type. Before sign-in, the random identifier contains no personal information. After sign-in, our own database connects that browser’s earlier recorded events to your account so we can see that someone read the pricing page before creating an account, rather than counting them as two unrelated strangers. Clearing your cookies removes both, and nothing on the site stops working without them.
Your rights
You can request a copy of your data or ask us to delete your account and everything attached to it. Deletion removes your account, sessions and ledger; we may keep a minimal payment record where we are legally required to. If you are in the EU or UK, the GDPR rights of access, rectification, erasure, portability and objection apply, and our legal basis for processing account data is performance of the contract between us.
Children
The service is not directed at children under 13, and we do not knowingly collect their data.
Contact
For any privacy request, contact us through the support channel linked from your dashboard or the address on your payment receipt. See also our Terms of Service.
Claude Watermark is independent and not affiliated with Anthropic, OpenAI or Google.







