Draft for review. This document has not been reviewed by a lawyer and is not yet in force.
Version: draft 1, 10 October 2026. Effective date: [to be set when this document is approved].
This policy explains what Demarker collects when you use the website and the API, why, how long we keep it, and who else handles it. Demarker is operated by [Legal entity to be decided], [Postal address to be decided] ("Demarker", "we", "us"). Questions and requests go to [email protected].
1. The short version
- We scan and clean images that you upload. We keep your original for 24 hours after the last run on it finishes (or 24 hours after upload if you never process it), and for up to 72 hours while a job waits for payment.
- Results are kept for 24 hours if you are not signed in, 7 days if you are signed in on the web, and 72 hours if you use the API. You can delete an image and its results at any time with Delete now.
- We do not use your images or results to train AI models, and we do not use them for research.
- We do not sell your personal information.
- We do not load analytics tools until we add a consent control.
- We keep a record of each job for 6 to 12 months. It does not contain the image.
The rest of this page gives the detail.
2. What we collect
2.1 Your images and results
When you upload an image we store it, a smaller preview of it, the scan report, and, if you run a clean, the cleaned image. An image that we refuse (for example because it looks like adult content or carries a third-party overlay) is deleted at once. Cleaning work files on our workers and on the GPU host are deleted when the job ends, including when it fails.
2.2 A record of each job
For each job we keep a record that does not contain the image. It holds the job ID, the account or API key it belongs to, the tier you chose (Quick clean or GPU pass), the size band, which signals the scan found and which were removed, which author and copyright fields were present and kept, the versions of the terms and attestation wording that you accepted and when, the country we derived from your IP address and your billing country, timestamps, and a hash (a fingerprint) of the input and output files. We keep these records to run the Service, to handle refunds and disputes, to prevent abuse and to meet legal duties.
2.3 IP address and country
We read your IP address to work out your country, so that we can apply the country restrictions in the Terms of Service. We keep a salted hash of your IP address for 48 hours to enforce free-use limits and to detect abuse. The long-lived job record holds the country, not the hash.
2.4 Account information
If you create an account we collect your name, your email address, how you sign in (a password, a magic link, a passkey or Google), and the security data that goes with it, such as a hashed password, passkey details and two-factor settings if you turn them on. For abuse prevention we also keep the IP address you signed up from and the IP addresses of your most recent sign-ins (up to five), and we keep session records with the IP address and browser details of each session. We keep your credit balance and the history of credits added, used, refunded or reversed.
2.5 Payments
Payments are taken by a third-party payment processor. We receive an identifier for the payment, the amount, the date, your billing country and the email address you used. We do not receive or store your full card number.
2.6 API use
If you use the API we store your API keys, how often each key is used, the credits used through it, and the webhook addresses and signing secrets that you register.
2.7 Messages you send us
If you write to us or use the contact form, we keep the message and your email address so that we can reply. Contact form messages may be passed to a workflow tool that routes them to us [tool to be confirmed].
2.8 Service emails
We send emails that the Service needs, for example to verify your email address, tell you that a job is done or has failed, warn you that your credits are low, or reply to a refund request. If we ever send marketing email, you will be able to unsubscribe from it, and service emails will still be sent.
2.9 Server logs and error reports
Our servers and our network provider keep technical logs of requests (such as the address requested, time, IP address and browser type) so that we can run the Service securely. If something breaks, an error report with technical details about the failure may be sent to our error-tracking provider [to be confirmed].
2.10 Cookies and analytics
See section 7.
3. How we use it
We use personal information to:
- scan and clean your images and return the results;
- run accounts, credits, payments, refunds and support;
- apply the country restrictions, free-use limits and other abuse controls described in the Terms of Service;
- keep the Service secure and fix faults;
- keep the records described above and meet our legal duties;
- understand, in aggregate, how the Service is used, but only through analytics that we load after we add a consent control.
We do not look at your images as a matter of routine. We may look at one to investigate abuse, to fix a problem you have reported or to meet a legal duty. We do not sell personal information, and we do not use images or results for advertising or for training or improving AI models, and we do not use them for research. If that ever changes, we will ask you first and you will be able to say no.
4. How long we keep it
Our cleanup job runs every 15 minutes, so deletion can lag the times below by a few minutes.
- Original image and preview. 24 hours after the last run on it finishes, or 24 hours after upload if it is never processed. Up to 72 hours while a job is waiting for payment. At once if you choose Delete now or if we refuse the image.
- Direct upload that never became a job. 1 hour.
- Cleaned result. 24 hours if you are not signed in, 7 days if you are signed in on the web, 72 hours through the API, or earlier if you choose Delete now.
- Work files on our workers and the GPU host. Deleted when the job ends, including when it fails.
- Record of a processed job (section 2.2). 6 to 12 months [exact period to be decided].
- Record of a job that was only scanned. Job ID, account or key ID, country, time and counts of signals. The detail and the file hash are dropped after [period to be decided].
- Record of a refused image. Reason, score, file hash and country, kept on the same schedule as a processed job.
- Free-use counters and the salted IP hash. 48 hours.
- Log of blocked attempts, with no image. 12 months.
- Account information. Until you delete your account (section 9).
- Payment and tax records. As long as the law requires [period to be decided].
- Backups. [Retention to be confirmed.]
- Analytics and error data. [Per provider settings, to be confirmed.]
Exceptions are in section 8.
5. Who handles your data
We use the providers below to run the Service. They act for us, and they may only use the data to provide their service to us. Some entries are not yet settled, and they are marked.
- GPU compute host [to be decided]. Runs the GPU pass. Sees the image for the duration of the job.
- Server and storage hosting [droplet host to be decided]. Runs the website, the database and the CPU workers. Holds everything described in section 2, including images while they are stored.
- Cloudflare [role to be confirmed]. Network, security and delivery, and possibly file storage. Sees requests to the site, your IP address and, if it stores files, the files.
- Payment processor [to be decided]. Takes payments and handles refunds and disputes. Sees payment details, your billing country and your email address.
- Email provider [to be decided]. Sends service emails. Sees your email address and the content of each email.
- Google. Sign in with Google, if you choose it. Sees your sign-in identity. If we later add Google Analytics, we will do it only behind a consent control, and it would see page visits and device details.
- PostHog, US host [to be confirmed]. Error tracking, and product analytics only behind a consent control that we have not added yet. Sees technical error details, and page visits and device details if analytics are later switched on.
We may also share information with a court, regulator or law-enforcement body when the law requires it, with our professional advisers, and with a buyer or successor if we merge, are sold or reorganise, in which case this policy continues to apply to your data unless we tell you otherwise.
6. Never used for training, never sold
Your images and results are used only to provide the Service to you. They are not used to train or improve AI models, they are not used for research, they are not sold, and they are not shared with advertisers. This also applies to the GPU host and our other providers: we only send them what they need to run your job.
7. Cookies and analytics
We use a small number of essential cookies and similar storage that the site needs in order to work, for example to keep you signed in and remember your language.
We do not load Google Analytics or PostHog analytics until we add a consent control. When we do, they will load only after you accept them, and if you decline, or do not choose, they will stay off. This policy will change when that happens. We do not send your images to analytics tools. You can clear the site's cookies and storage in your browser at any time.
8. Illegal content and legal holds
Some content must not be processed and cannot simply be deleted. We refuse child sexual abuse material and intimate images shared without consent. For these, the usual deletion schedule, Delete now, the API delete call and storage expiry do not apply. We may keep the image, the related job record and the information needed to identify the upload, in restricted storage, for as long as the law or a competent authority requires or permits, and we may report it to the authorities. We may use automated tools, including matching against databases of known illegal imagery, to find such content [provider to be decided]. We may also keep other data under a legal hold when we receive a lawful request or order, or when we need to protect our legal rights. The periods and access rules are set by the law that applies, and we will update this policy when we have settled them.
9. Your rights and choices
- Delete an image. Use Delete now on a job, or the delete call in the API. If the job is still waiting to start, its credits go back to your balance.
- Delete your account. You can do this in your account settings. We then delete your profile, sign-in details, API keys, credit balance and credit history. Job records stay for the periods in section 4 without the link to your account. Payment and tax records stay as the law requires.
- Access, correction, a copy and other rights. Depending on where you live, you may have rights over your personal information, for example to see it, correct it, receive a copy, object to some uses, withdraw consent that you gave, or complain to a data protection authority. Write to [email protected] and we will answer within the time that applicable law requires. We may need to confirm that the request comes from the owner of the account.
- Analytics. We do not load analytics until we add a consent control (section 7).
- Emails. Service emails cannot be turned off while you have an account. If we send marketing email, every one will carry an unsubscribe link.
Because the job record does not contain your image, we cannot recover an image after it has been deleted.
10. Children
Demarker is for adults. You must be 18 or older to use it. We do not knowingly collect personal information from anyone under 18, and if we learn that we have, we will delete it.
11. International transfers
Some of our providers, such as PostHog's US host, process data in the United States, and others may process data in other countries. [Where Demarker and its providers store and process data, and the legal basis for each transfer, to be decided.]
12. Security
We protect data with measures such as encrypted connections, private file storage with short-lived download links, hashed passwords, and access limited to people who need it. No system is completely secure, and we cannot promise that nothing will ever go wrong. We have not been independently certified under any security or privacy standard.
13. Changes to this policy
We may update this policy. If a change is material we will tell you by email or in the app before it takes effect, and the new version will show its date. Earlier versions are available on request.
14. Contact
Privacy questions, deletion requests and anything else about this policy: [email protected].
[Legal entity to be decided]
[Postal address to be decided]