Privacy Policy
Last updated: 15 June 2026
This Privacy Policy explains how Unmarkr ("we", "us") collects, uses, shares and protects your personal data when you use https://unmarkr.io and our tools and API. Unmarkr is available worldwide, and we apply the core protections described here to every user, wherever you are. We process data lawfully and transparently under the EU General Data Protection Regulation (GDPR) and the French Data Protection Act, and we honour other applicable data-protection laws where they apply to you — including the UK GDPR, US state laws (such as the CCPA/CPRA), Brazil's LGPD, and Canada's PIPEDA.
1. Who is responsible for your data
Unmarkr is operated by Yacine Tazerout, an individual sole trader (entrepreneur individuel) established in France. We are the "data controller" for the personal data described here. For any privacy question or to exercise your rights, contact us at support@unmarkr.io.
2. The short version
- Images you clean are processed transiently to remove watermarks/metadata, then deleted right after — we don't store them and never use them to train models.
- We collect only what we need: your account email, payment records (via Stripe — we never see your full card), basic usage and security data.
- Non-essential analytics/marketing cookies load only if you consent via the cookie banner.
- You have rights over your data (access, deletion, etc.) — just email us.
3. Data we collect
Account data
When you create an account, our authentication provider (Neon Auth) stores your email address, a hashed password, and your display name.
Images you upload
To remove a visible watermark, your image is sent over an encrypted connection to our processing engine, cleaned, and returned. We do not persist your source or cleaned images, and we never use your images to train any model. They exist only in memory / transient storage for the few seconds needed to process them. (On the free in-browser tool, metadata detection happens locally in your browser; visible-watermark removal requires the upload just described.)
Payment data
Payments and subscriptions are handled by Stripe. We never receive or store your full card number. We keep a record of your purchases, plan, credit balance, customer ID and invoices so we can provide and account for the service.
Usage & technical data
- Removal events and credit usage (to meter your plan and the API).
- A hashed form of your IP address, used purely to rate-limit the free tool and prevent abuse — we do not store raw IP addresses for this.
- Standard server logs and, if you consent, analytics data (see Cookies below).
4. How we use your data & legal bases
- To provide the service (process images, manage your account, deliver API/HD results) — legal basis: performance of our contract with you.
- To take payment and manage subscriptions/credits — performance of a contract; compliance with accounting/tax law.
- To keep the service secure and prevent abuse (rate limiting, fraud prevention) — our legitimate interests.
- To understand and improve usage via analytics — your consent (where required) or our legitimate interests for privacy-friendly, cookieless measurement.
- To communicate with you about your account or essential service changes — contract / legitimate interests.
5. Cookies & analytics
We use a small number of cookies and similar technologies:
- Strictly necessary — sign-in/session and security cookies, and your cookie-consent choice. These are required for the site to work and don't need consent.
- Analytics (cookieless) — Vercel Web Analytics, which measures aggregate traffic without cookies and without tracking you across sites.
- Analytics & marketing (consent-based) — if enabled, tools such as Google Analytics and the Meta (Facebook) Pixel set cookies and load only after you accept in the cookie banner. You can decline, or change your choice later via "Cookie preferences" in the footer.
6. Who we share data with (processors)
We don't sell your personal data. We share it only with service providers who process it on our behalf under appropriate agreements:
- Vercel — website hosting & cookieless analytics.
- Neon — managed database & authentication (account data).
- Railway — hosts the image-processing engine (transient image processing).
- Stripe — payment processing & subscription billing.
- Google — analytics (only if you consent).
- Meta Platforms — advertising/measurement pixel, if and when enabled (only if you consent).
We may also disclose data where required by law or to protect our rights.
7. International data transfers
Some of our providers are based in, or process data in, the United States and other countries outside the European Economic Area. Where personal data is transferred outside the EEA, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses and providers' certifications (e.g. the EU–US Data Privacy Framework, where applicable).
8. How long we keep data
- Uploaded images: not retained — deleted immediately after processing.
- Account data: for as long as your account exists; deleted on request or a reasonable period after closure.
- Payment/invoice records: as required by tax and accounting law (typically up to 10 years in France).
- Security/usage logs & hashed IPs: short retention windows appropriate to abuse-prevention.
9. Your rights
Under the GDPR — and equivalent rights under your local law — you have the right to access, rectify, erase, restrict or object to processing of your personal data, to data portability, and to withdraw consent at any time. To exercise any of these, email support@unmarkr.io. You also have the right to lodge a complaint with your supervisory authority — in France, the CNIL (cnil.fr).
US residents (CCPA/CPRA and similar):we do not sell or "share" your personal information for cross-context behavioural advertising without consent. You have the right to know, delete, correct, and opt out; we will not discriminate against you for exercising these rights. Contact us at the same address.
10. Security
We use encryption in transit, hashed credentials and IPs, access controls and reputable infrastructure providers. No method of transmission or storage is 100% secure, but we work to protect your data and to limit what we collect in the first place.
11. Children
Unmarkr is not directed to children under 16, and we do not knowingly collect their personal data. If you believe a child has provided us data, contact us and we will delete it.
12. Changes to this policy
We may update this policy from time to time. We'll change the "last updated" date above and, for material changes, take reasonable steps to notify you.
13. Contact
Questions or requests: support@unmarkr.io. See also our Terms of Service.