Privacy Policy

Brief image retention without advertising profiles.

Image processing

Image files use a third-party processor with private, temporary file storage. Inputs are deleted once processing finishes or fails. Successful results stay accessible for no more than one hour, backed by a final 24-hour storage deletion rule.

Optional provider checks

The OpenAI checker only transfers your selected image to OpenAI after separate consent; OpenAI says this check is not eligible for Zero Data Retention. The Google checker uses Gemini, where you send the image directly to Google. Terms from the selected provider apply.

Abuse prevention and records

To enforce limits, we use anonymous browser identifiers and keyed network identifiers rather than stored raw IP addresses. Temporary upload data is cleared after seven days. We keep limited processing history without a time limit, including opaque job and batch references, timestamps, results, dimensions, costs and numeric processing statistics. No images, filenames, extracted text, account details, network identifiers or access credentials are kept in this history. Cloudflare may use routine request data for network protection and analytics.

Accounts and sign-in

Sign-in uses a verified email and associated provider identifiers, or a separate username identity protected by a salted password hash and a recovery-code hash. An email address is optional when choosing the username method, which cannot be linked to email or social accounts. We retain neither plaintext passwords or recovery codes nor card details or provider access tokens. Supported providers are Google and GitHub, plus Microsoft or Facebook if configured, and new links must verify an email. Codes and challenges expire in 10 minutes and sessions in 30 days, followed by removal through routine authentication cleanup. Cloudflare sends email-based users their login codes and signup welcome message. Authorizing GitHub gives email access only and no access to repositories.

For this website, we retain a keyed email hash and a minimal grant record across our websites to prevent repeat signup offers.

Account follow-up

We can ask new members for feedback and offer extra credits in one email after three days with no purchase. We prevent repeat offers across sites using a keyed email hash, signup time, delivery state, opt-out and redemption record. Withdraw in Account or via email; authentication mail continues. Cloudflare sends in English and directs replies to support. We collect no open or click tracking.

API keys

API access records key names, masked prefixes and keyed hashes; full keys are not retained. A key is revealed just once when created. Account lets you revoke keys; revoked key records remain for seven days before removal. API uploads use the website's temporary image storage and deletion schedule.

Payments and account deletion

Stripe processes the payment details and collects a checkout email regardless of whether the account uses email or a username to sign in. The checkout email does not create a login identity or merge accounts. Our seven-year financial retention covers dollar-balance entries and minimal payment/refund receipts, kept apart from uploaded images. Financial history refers to opaque job IDs rather than image files, filenames or extracted text. Deletion and refund requests can come from the account email or through the support form after sign-in. Necessary payment, dispute and obligation-related records may still be retained.

Support mailbox

Messages to support@chatgptwatermarks.com, including permitted attachments, are saved in a private operator mailbox to support our response. Active conversations remain until an operator chooses to delete them. Trash becomes deletable at 30 days and is removed during the next daily maintenance run. Cloudflare supports mailbox routing, storage, access control and transactional delivery. Never send credentials or highly sensitive personal data.

Feedback may contain your chosen reply address and, if you are authenticated, a server-added account reference. The support mailbox stores this information with the retention period described above. We do not turn the feedback address into a login credential.

Offer layout testing

The pricing layout trial is over; detailed experiment records are kept for 90 days, then only aggregate totals without browser or account identifiers remain.

Tracking and controls

This website has no advertising pixels, profiling for ads or data-broker integrations. Essential local storage maintains upload progress and quotas. Small original previews are removed from the browser on image deletion, replacement of the saved batch or reopening expired results. An account also stores private previews for use on other devices, removed with results after their one-hour access period and covered by the 24-hour deletion backstop. “Delete now” and support@chatgptwatermarks.com are available for assistance; keep job credentials out of email.