Privacy Policy
Last updated: 17 August 2026
Draft status: This policy is provided for product and legal review and is not legal advice.
Scope
This Privacy Policy explains how Watermark Lens handles information when you use watermarklens.com, its local character tools, account features, and AI text rewriting service. The service is currently intended for users in the United States and is provided in English.
Local Character Tools
Text pasted into the self-check or character-cleaning tool is processed entirely in your browser and is not uploaded to our application servers. Closing or refreshing the page clears that text unless your browser or an extension retains it independently.
AI Text Rewriting
When you intentionally submit text for AI rewriting, the text is sent through Cloudflare infrastructure to Wenwen AI so the selected model can generate a response. This transmission is necessary to provide the AI feature.
Our application does not intentionally store the submitted text or full rewritten result in its database, analytics, or application logs. We store operational metadata such as a one-way input hash, request and user identifiers, character and Token counts, selected model and prompt version, status, latency, estimated cost, and timestamps. Wenwen AI's own processing and retention are subject to its service terms and our provider agreement; do not submit secrets or highly sensitive personal information until those terms have been reviewed for your use case.
Account and Membership Data
If you create an account, we process your email address, authentication identifier, optional display name, account role and status, plan, subscription status, quota periods, usage ledger, and security or audit events. Supabase provides authentication and database infrastructure. If you use Google sign-in, Google and Supabase process the authentication information required to complete that sign-in.
Payments
If paid subscriptions are enabled, Stripe will process checkout and payment details. We expect to retain Stripe customer, subscription, invoice, payment-status, and billing-period identifiers needed to provide and reconcile the subscription. We do not receive or store full payment-card numbers.
Technical and Security Data
Cloudflare and our application may process IP address, request time, request path, user agent, security signals, request identifier, response status, and sanitized error information to deliver the site, prevent abuse, troubleshoot failures, and protect accounts. Passwords, full authorization tokens, API keys, submitted text, and rewritten text must not be written to application logs.
Analytics
We use a Plausible-compatible analytics service hosted at plausible.shipsolo.io to understand aggregate website traffic. The configured script does not use analytics cookies or persistent cross-site identifiers. It processes limited information such as page URL, referrer, browser, operating system, device type, and approximate location. See the Plausible data policy for the standard product's technical approach and our Cookie Policy for this site's configuration.
We also use Google Analytics 4 with measurement ID G-G04WGCK8BF to collect page views and understand use of the site. Google Analytics may use first-party analytics cookies and process information such as page URL, referrer, browser and device information, approximate location, and website interactions. We do not load the Google tag on the OAuth callback page, and we do not intentionally send submitted or rewritten text to Google Analytics. Google processes analytics data under its applicable terms and privacy policy.
How We Use Information
We use information to provide and secure the service, authenticate accounts, enforce quotas, process subscriptions, respond to support requests, diagnose errors, prevent fraud or abuse, measure aggregate service performance, comply with law, and establish or defend legal claims. We do not sell submitted or rewritten text or use it for targeted advertising.
Service Providers
Relevant service providers may include Cloudflare for hosting and security, Supabase for authentication and database infrastructure, Wenwen AI for model processing, plausible.shipsolo.io for aggregate analytics, Google for Analytics and optional OAuth, and Stripe if payments are enabled. Each provider processes information under its applicable agreement and privacy terms.
Retention
Local-tool text is not retained by our application. AI text is not intentionally persisted in our database, but it is processed transiently by the infrastructure and model provider. Account, subscription, usage, security, and audit records are retained only as long as reasonably necessary for the purposes above, including legal, accounting, fraud-prevention, and dispute requirements. Provider-specific retention periods must be confirmed in the applicable provider agreements before final legal approval.
Your Choices and US Privacy Rights
You may ask to access, correct, or delete account information by contacting us. Depending on your state and subject to legal exceptions, you may also have rights to obtain a copy of personal information, restrict certain processing, or appeal a denied request. We may need to verify your identity before completing a request.
Children
The account and AI services are not directed to children under 13, and we do not knowingly collect personal information from children under 13. Contact us if you believe a child has provided personal information.
Changes
We may update this policy when the service or legal requirements change. We will post the revised date and provide additional notice where required.
Contact
Email privacy and support requests to [email protected].
Legal review is still required before this draft is treated as a final policy.