Privacy Policy
Last updated August 12, 2026
What we collect
Account details from your sign-in provider: your email address, name and avatar if you have one. We never see or store your password.
The text you submit, and the cleaned result we produce from it.
Billing records held by Stripe. We store a customer id and subscription id; card details never reach our servers.
A device fingerprint generated in your browser, used only to detect one person creating many accounts to farm free words.
How we use your text
Text you submit is processed to produce your result, and saved to your history so you can retrieve it later. That is the whole purpose.
It is not used to train any model, ours or anyone else's.
It is not sold, rented or shared with advertisers.
The character-level scan runs entirely in your browser. Text you only scan and never clean is never sent to us at all.
Processors
Clerk handles authentication. Supabase hosts our database. Stripe handles payments. The rewrite runs on a third-party model API. Resend sends transactional email if configured. Each receives only what it needs to do its job.
Retention
History entries are kept until you delete them or delete your account. Deleting your account removes your row and, by cascade, all of your history.
Results held behind a one-off payment are deleted automatically 24 hours after they are created if they go unpaid.
Your choices
You can delete any history entry at any time from the history page.
You can delete your account from your account settings, which removes everything we hold about you apart from billing records Stripe is legally required to keep.
For anything else, email team@duckwatermark.com.
Security
Traffic is encrypted in transit. Database access from the application uses a service role held only on the server, and row-level security is enabled so a leaked public key cannot read other users' rows.