Privacy note
Version 2026-09-22.
Who is responsible: Kirill Balakhonov. This is a personal project. You can contact me onLinkedIn.
What is collected and why
- Forms ("join the research" / updates): your email, your optional answers, the offer version you saw, and the UTM tags of the page you came from. Purpose: to reply to you personally about the problem you described and, if you opted in, to tell you when something you asked for is ready. Lawful basis: your consent.
- Usage analytics (PostHog): page views and explicit interaction events only. No form contents, no emails, no session recording, no autocapture. Result-copy actions and optional usefulness ratings include only the access tier, a text-length range, the slop setting and coarse review status. A short tab-local list of random run IDs prevents repeated copy/rating events; those IDs are not sent to analytics and are removed when the browser tab session ends.
- Ad measurement (OpenAI): the OpenAI Pixel records page views, accepted lead forms, checkout starts and confirmed purchases so that ChatGPT ads can be measured and optimized. Purchase events include the amount, currency and a random purchase reference. Automatic Advanced Matching can detect supported contact details you enter in forms, such as email, phone number or name; the Pixel normalizes and hashes them in your browser before sending the hashes to OpenAI. When a purchase is confirmed by Stripe, this site also sends one server-side purchase event to OpenAI with the hashed checkout email, the country of the checkout request, the amount and the ad-click reference the SDK stored in your browser. These hashes are used for matching and are not anonymous. Form answers and text submitted for rewriting are never included. Events are opted out of future user-level personalization. Measurement is on by default; turn it off with the link in the footer or open any page with
?analytics=off— the choice is stored in this browser and stops future browser measurement. Lawful basis: legitimate interest in measuring advertising; you can object at any time. - Optional reason for using the tool: signed-in users can describe what they were working on and why they tried it. This answer is saved with the account in D1, separately from release updates and feature requests. It is used to improve the tool and understand the need it serves, kept for at most 24 months, and never sent to analytics or a model provider. Sending it does not subscribe you to a newsletter. Lawful basis: your consent when you send the answer.
- Text tools: the submitted prose is processed for the operation you select. Watermark rewriting and humanizing mask web links beginning with http(s) or www, ASCII email addresses, single-line quoted spans, amounts marked with $, £ or €, and numeric percentages are masked before the model calls. Comparison and AI-style analysis send the full supplied texts to the model so it can inspect wording and meaning. Requests go through OpenRouter. Humanizer and watermark rewriting drafts go to DeepSeek V4.1 Flash on GMICloud or Phala; these endpoints are not limited to zero data retention. All other model calls go only to endpoints with zero data retention and no data collection: Qwen3.6 on DeepInfra and GLM-5.3-Flash on CoreWeave, Baseten or Together. Since August 31, 2026 the submitted text and the returned result are stored in D1, linked to the anonymous browser id or, for registered users, to the account, so I can understand what the tool is used for and improve it. They are never sent to PostHog, logs or any marketing platform, and are kept at most 12 months. Do not submit secrets or confidential personal data.
- Demo access tiers: an anonymous browser gets a random id in an HttpOnly cookie (
wr_anon) and a run counter keyed by that id and by a hash of the IP address. If you register by email, the one-time link is stored only as a hash until it is used; after confirmation your email is stored as an account and as a lead in thewatermark-remover-productionlist, a signed session cookie (wr_session, 180 days) identifies the browser, and monthly run counters are kept per account and shared across all four text tools, the website, API and MCP. Email is used to send the link and to tell you when the tool is available in production. Lawful basis: your consent; the confirmation click is the opt-in.
API and MCP access: API keys are stored only as hashes, with an account ID, label, creation time and revocation time. Requests use the same processing and text retention as the web tool. Request IDs, input hashes, progress and saved results let you retrieve an existing run without processing the text again. The local MCP client keeps active results in memory and does not save texts or keys to disk itself. Remote MCP supports OAuth and agent claim codes. Connection records include the app name, permissions, account ID, expiry and revocation status. OAuth grant data is stored in Cloudflare KV. Claim handles and agent access tokens are stored as hashes; claim codes use a keyed hash. The browser confirmation page checks your signed-in account before granting access. Background jobs keep the draft in Cloudflare Durable Object storage while it waits or runs, then remove that temporary copy. The D1 text and result records follow the tool's retention policy above. You can revoke agent connections on the integrations page.
Where it lives
Purchases: Stripe processes the payment details you enter at checkout. This site stores the checkout email, an account-linked purchase reference, payment status and the number of purchased characters used or refunded. The checkout email connects the purchase to an account and allows access from another browser. Card details do not enter this site's database or analytics. This information is used to provide the purchased service, reconcile payments and handle refunds.
Form data is stored in a Cloudflare D1 database owned by me and is not sent to marketing platforms as raw form records. The hashed contact identifiers described above may be shared with OpenAI for ad measurement. Processors: Cloudflare (hosting, bot protection), PostHog (aggregate analytics), OpenAI (ad measurement), OpenRouter (model routing), GMICloud, Phala, DeepInfra, CoreWeave, Baseten and Together (model inference) and Resend (magic-link emails). The rewrite demo stores aggregate daily run counters, per-browser and per-account run counters, and registered emails in D1.
Retention and your rights
Form records are kept while the related experiment or update list is active, at most 24 months. You can ask at any time what is stored about you, ask for correction, or ask for deletion. Message me on LinkedIn and it will be removed within 7 days. Every update email (if you opted in) will include an unsubscribe method.