Privacy
Last updated 17 August 2026
The short version: we do not keep your documents. This page explains exactly what that means and what we do keep.
Text and images you submit
Content you paste or upload is held in memory only for as long as it takes to produce the result, then discarded when the response is sent. It is never written to disk, never logged, never sent to a third party, and never used to train anything.
There is no history feature, no "recent scans" list, and no way for us to retrieve something you checked, including for you if you ask. That is a consequence of not storing it, not a policy we could quietly change without rewriting the software.
What we do store
A salted hash for rate limiting. To count free checks against the daily allowance we store a truncated SHA-256 hash of your IP address combined with a secret salt. Alongside it sit two counters and a date. Your IP address is never stored in the clear, the hash is not reversible in practice, and rows older than seven days are deleted.
Passes. If you buy a pass we store a random identifier for it, the plan, when it was bought, when it expires, the Polar identifiers (customer, order, checkout), plus the email address Polar collected for your receipt. The email is kept for one reason: so we can get you back in if you lose your access link.
Payments
Payments are processed by Polar, acting as merchant of record. We never see or handle your card details. Polar's own privacy policy governs what they collect. We receive a confirmation, the identifiers listed above, the billing email. Nothing else.
Cookies
One cookie of our own, aiwr_access, set only after you buy a pass. It is HttpOnly, SameSite=Lax, and expires when your pass does. It holds a random identifier for your pass and nothing else: no email, no name, no payment details.
The analytics cookies described below are the only others, and only if you allowed them. No advertising cookies, no cross-site trackers, no fingerprinting. Apart from Google Analytics after your consent, the only external resources this site loads are the two font files it serves from its own domain.
Analytics
We use Google Analytics 4 to count visits and see which pages are worth writing more of. It runs only if you press Allow on the banner. Until then — and permanently if you decline — the Google script is never downloaded, no request goes to Google, and no analytics cookie is set. This is a real gate, not a banner over a tracker that was already running.
If you do allow it, Google sets two cookies (_ga and _ga_<id>) holding a random identifier so a second page view is not counted as a second person. They last up to two years. Google receives your IP address — which it uses to derive an approximate country and then discards, rather than storing — plus the pages you visited, the referring link, and the coarse device and browser type.
We also record what happened, never what it happened to: that a check ran, how many characters or bytes it covered, how many hidden characters came back, and whether a pass was bought. The text and images you submit are never part of this. Not the content, not a fragment, not a filename, not a hash. Advertising and personalisation signals are switched off permanently, not just until you consent, so nothing here feeds ad targeting.
Google acts as our processor under the GDPR, with data transferred to the United States under the EU–US Data Privacy Framework. The legal basis is your consent, and you can withdraw it at any time — that is what the button below does. Withdrawing stops any further collection; it does not delete what was already counted, which is aggregated and not linked to you.
Server logs
Standard HTTP request logs (timestamp, path, status code, user agent) are kept for up to thirty days for operational and abuse-prevention purposes. Request bodies are never logged, so your content does not appear in them.
Your rights
Under the GDPR and comparable regimes you have rights of access, rectification, erasure, portability. In practice there is very little to exercise them against: we hold no identifiable record of your usage, and the rate-limiting hash cannot be linked back to you by us.
If you have bought a pass and want your purchase record deleted, emailsupport@aiwatermarkremove.com from the address you paid with. Note that deleting it invalidates your access link.
Children
This service is not directed at children under 13, and we do not knowingly collect data from them.
Changes
Material changes will be posted here with an updated date. If a change ever meant we started retaining submitted content, it would be announced prominently on the site, not buried in this page.