WATERMARK SLAYER

Privacy

Every action is explicit. Remove watermark processes only the text you submit for that request and may use a hosted language model. This policy also covers the website's compatibility actions, Chrome extension, native Gmail add-on, and Outlook and Word add-ins.

Website removal

Pressing Remove watermark sends the exact draft and any words you chose to keep exact through the public entry point to the private processing engine. It performs cleanup and may use a hosted language model for that one request. Watermark Slayer does not store the source or clean result.

Deterministic inspection and cleanup

Inspect and Clean send the exact source through the public entry point to the private processing engine. Those deterministic actions do not call a language model and do not store the source or result.

Rewrite processing after an explicit action

Pressing Rewrite sends the draft and selected writing controls to the Watermark Slayer service and may send them to a hosted language model for transient processing. Before Check, Rewrite first inspects the exact source and includes every supported deterministic removal. After Check, only supported findings left selected are included; an empty selection requests wording changes without hidden cleanup. The request is used to produce the requested editorial result, not a detector outcome.

The rewrite provider may apply content filtering and abuse monitoring to prompts and completions. Flagged samples may be retained for abuse review. This provider-level handling is separate from the Watermark Slayer application boundary.

No draft history in the launch design

The Watermark Slayer application itself retains no drafts: it uses no database, object store, queue, temporary file, server result cache, or staff-retrieval path for source or generated text. Clear session removes browser-held draft and result state.

A production no-retention assurance is published only after deployment logging and telemetry are verified with a synthetic content canary.

No content-derived request state

The browser and service do not derive content hashes, cache results, or create processing receipts. The browser keeps the active tab's source and review state until the writer clears it or closes the tab, and may keep a signed guest-trial token in localStorage that contains no draft text.

WATERMARK SLAYER Chrome extension and Gmail add-on

The Chrome extension works on HTTP and HTTPS pages. It observes only the text you explicitly select, shows local controls, and sends that selection to Watermark Slayer only after you choose Rewrite. You review the proposal before choosing Replace selection or Copy. It does not collect browsing history, monitor keystrokes, or process page content in the background.

Text you explicitly select or enter may itself contain a name, address, email address, username, or other personal information. Watermark Slayer processes that information only as part of the requested writing action; it does not seek or retain those details.

On Gmail, the Chrome extension also offers explicit Check, Clean, and Rewrite actions for the new-message region of the current compose draft, skipping quoted history and signatures. It does not call the Gmail API, request mailbox scopes, read the inbox, scan while you type, or intercept Send.

The native Gmail add-on sends only text that you explicitly enter in its card. After review, Gmail inserts the result at the compose cursor or replaces the current selection. The add-on requests no mailbox-read, modify, or send scope and does not read messages or contacts.

The Chrome extension stores a revocable bearer connect key in Chrome local storage; the native Gmail add-on stores the same kind of key in that user's Apps Script properties. Watermark Slayer stores only the key hash with content-free account and revocation metadata. The key contains no selected text, draft text, Gmail identifier, or Google API token. Submitted text and proposals are discarded after the request and are not retained by Watermark Slayer.

Google Workspace data access and use

The native Gmail add-on does not read your inbox, messages, contacts, attachments, recipients, or existing draft body. It requests script.external_request only to send text you explicitly enter after you choose Check, Clean, or Rewrite. Its compose-action permission lets Gmail insert a result you reviewed at the cursor or replace the current selection; it does not grant Watermark Slayer permission to read the draft. The runtime-required gmail.addons.execute declaration is ignored for authorization and grants no mailbox access.

Google Workspace API data is used only to provide the visible Check, Clean, Rewrite, and insert features you choose. It is not used for unrelated profiling, advertising, credit decisions, or any hidden background action.

Google Workspace data sharing and AI processing

Check and Clean use Watermark Slayer's deterministic processing engine. Rewrite may transfer only the text you explicitly submit to a hosted language model provider, with your action as consent, solely to produce the result you requested. Under the provider's current service terms, prompts and completions are not used to train or improve generalized AI models without permission. Provider content filtering and abuse-review handling remain described above.

Google Workspace API data is not sold, used for advertising, or used to train or improve generalized AI models. Watermark Slayer does not transfer it to data brokers, advertising platforms, information resellers, or model-training datasets.

The use of information received from Google Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.

Google Workspace data safeguards, retention, and deletion

Google Workspace API data is protected with HTTPS in transit, bounded request sizes, a separately authenticated private processing engine, and content-free operational logging. The native add-on keeps its revocable connect key in Apps Script user properties; Watermark Slayer stores only a keyed hash and content-free issuance, use, and revocation metadata. The key contains no Gmail data or Google API token.

Watermark Slayer does not persist Google Workspace API data, submitted text, or generated results in application databases, files, caches, logs, or analytics. Text exists only for the explicit request and is discarded when that request finishes. A reviewed result remains only in the add-on card until you replace it or insert it into your Gmail draft.

Disconnecting deletes the connect key from Apps Script user properties. You can also revoke the key from your Watermark Slayer account, which invalidates future add-on requests. Because Watermark Slayer retains no submitted text or result, there is no stored Google content to recover or delete; text inserted into a draft can be edited or deleted with Gmail's own controls.

WATERMARK SLAYER Outlook add-in

The WATERMARK SLAYER Outlook add-in is part of this service, not a separate product. It runs as a compose task pane in Outlook.

Sign-in uses your WATERMARK SLAYER account email. We store a hashed add-in session token bound to that account. We do not store message bodies, subjects, recipients, or Outlook item identifiers.

Draft text is processed in memory for one Check, Clean, or Rewrite request. Check and Clean stay on the private deterministic engine. Rewrite may send that one request to a hosted language model, as described above.

Word add-in

The optional Word add-in sends only the current selection through the same public entry point used by the website. It runs in Word for Windows, Mac, and the web. Check and Clean stay on the private deterministic engine. Rewrite may send that selection to a hosted language model for one request. The add-in does not store document text in Word settings or on Watermark Slayer servers. Replacing the selection writes plain text back into Word.

Account, first-use verification, and website guest trial

You can paste text before signing in. When the first-use gate is enabled, pressing Remove watermark asks you to verify your email before any draft is sent. The secure email contains no draft, and successful sign-in only refreshes access in the original tab; you must press Remove watermark again.

Your account profile may store a display name, an optional use-case category, and a separately labeled product-updates choice that starts off. Watermark Slayer never joins submitted or generated text to your name, email, account, profile, or marketing preference.

When the first-use gate is off, the public website grants one successful anonymous Remove. That trial is bound to a signed first-party cookie and a signed token in browser localStorage for the same random identifier. Clearing only cookies or only localStorage does not start another trial.

When the public edge attests the client IP, Watermark Slayer derives a one-way UUID from that address and allows at most five successful guest trials from the same hashed network per UTC day. The raw IP address and user-agent are not stored, logged, or sent to the processing engine. A browser that already used its one trial stays denied after that daily network cap resets. Check does not consume the trial. Gmail, Outlook, and Word have no guest trial.

Content-free journey analytics

Watermark Slayer keeps a random first-party browser journey UUID for 35 days with fixed event and route codes, source platform, device, browser, and operating system categories, approximate city, region, and country, fixed outcome and campaign codes, timestamp, a server-classified traffic category, a fixed new, returning, or none landing classification, and a fixed tracked-link code only when the complete allowlisted Meta or TikTok link matches. The server creates the UUID only for the first landing and decides whether that landing represents a new or returning browser journey; the browser cannot supply this value. This is not a person or cross-device identity. Partial, duplicated, or arbitrary UTM values receive no tracked-link code. Missing or failed classifications appear as Unknown. These events never contain submitted or generated text.

The IP address and user-agent string are used transiently to produce those fixed categories and are never stored, hashed, logged, or sent to an analytics or location provider. Approximate location is resolved inside the Watermark Slayer web container with a local DB-IP City Lite database and can be inaccurate. The complete allowlisted link is reduced in the browser to fixed codes; the landing URL and arbitrary UTM values are not retained.

The production web runtime deletes only these prefixed product events once they are strictly older than 35 days. Fixed events may record that the email gate was viewed, authentication started/completed/failed, access was unavailable, or a profile was completed, but never the email address or profile values. The support dashboard counts random browser journeys, not verified individuals, and separates New, Returning, and Unknown journeys, raw landing views, and conversion by first landing route and source. It can show a paginated content-free row with a stable one-way journey pseudonym, confidential authenticated cursor, bounded timestamps, tracked-link code, route, approximate location, and fixed client classes. It returns no raw journey UUID and does not join the row to account identity. Cross-device secure-link completion can therefore be under-attributed. Historical events are not backfilled with fields that were not collected at the time.

Contact

Privacy questions go to hello@watermarkslayer.com.