Privacy · Last updated 27 August 2026
What is stored, and for how long.
No analytics, no tracking pixels, no advertising identifiers, no third-party scripts on any page.
| Data | Why | Kept |
|---|---|---|
| Email address | Sign-in, receipts, and the failed-payment notice. | Until you close the account. |
| Uploaded images | To write the metadata. Stored so you can re-download and so you can list them on a transparency page. | Free plan: 30 days. Paid: while the account is open. |
| Disclosure records | The XMP packet, source type, tool and creator for each image. This is the evidence of what you declared and when. | While the account is open. |
| Transparency page content | Published publicly at an address you choose. It is public by design. | Until you unpublish or delete it. |
| Stripe customer and subscription IDs | To match your account to your subscription. | While the account is open, then as Stripe's own retention requires. |
| Server logs | Errors and request diagnostics. They include IP addresses. | 30 days, then discarded by the hosting provider. |
The anonymous labeler stores nothing
The labeler on the front page does not write your image anywhere. The file is held in memory for the length of one request, marked, and handed straight back. There is no copy on disk and no record that the request happened beyond an ordinary server log line. Rate limiting keeps a count against your IP address in memory for an hour.
Who processes it
| Processor | Role | Region |
|---|---|---|
| Vercel | Hosting and edge network | EU and US |
| Supabase | Database, authentication, file storage | EU region |
| Stripe | Payment processing | EU and US |
| Resend | Transactional email | EU and US |
Legal basis
Running your account and processing your images is performance of a contract with you. Keeping server logs and rate-limit counters is legitimate interest in keeping the service working and not being abused. There is no processing based on consent, because there is nothing here that would need it.
Cookies
One set, from Supabase, holding your session. It is strictly necessary for sign-in and there is no way to use an account without it. There is no analytics cookie and no cookie banner, because there is nothing to ask you about.
Your rights
Under the GDPR and the UK GDPR you can ask for a copy of your data, ask for it to be corrected, ask for it to be deleted, or object to processing. Closing your account in the dashboard does the deletion immediately: images, records and transparency pages all go. For anything else, mail legal@disclosemark.com and I will respond within 30 days.
You also have the right to complain to a supervisory authority. In the UK that is the ICO; in the EU it is the authority in your member state.
Breaches
If a breach affects your data I will tell you by email within 72 hours of becoming aware of it, along with what happened and what I am doing. I will not wait until I have a complete picture to send the first message.
Children
This is a business tool and is not intended for anyone under 16. I do not knowingly hold data about children.