This policy covers the Unmarked web app at tryunmarked.com and the Unmarked for Chrome extension. Data sent to a model provider is also governed by that provider's terms and privacy policy.
Shared commitments
These apply to every Unmarked product:
- Unmarked has a single purpose: inspecting, cleaning, and optionally rewriting content you explicitly choose. Your content is processed only to perform the transformation you requested.
- We do not sell or rent your data, and we do not use it for advertising, creditworthiness, lending, or profiling unrelated to that single purpose.
- We do not use your content to train models.
- When a model is involved, your text goes to the provider used for that rewrite — and that provider's terms and privacy policy govern what happens there. Review them before enabling rewriting.
The web app
Local by default
The free text cleaner inspects and cleans pasted text and dropped text files entirely in your browser. Its evidence report and SHA-256 hashes are generated there too. That text is not uploaded to Unmarked, stored by us, or sent to a model.
What reaches our servers
- Attachments. When you inspect or clean a file, the file, its filename, and its media type are sent to Unmarked's processing service. Temporary copies are deleted as soon as processing finishes; we do not keep your files.
- AI rewriting. When you run an Unmarked Pro rewrite (an account is required), your text and settings are sent through Unmarked's servers to Celeris-1 using Unmarked's shared provider key. Near the Celeris request-rate limit, Unmarked may instead send that model call through OpenRouter to GPT-OSS 120B hosted by Cerebras. Unmarked does not keep source text, prompts, provider output, or final rewritten text after the response is returned.
Your account
Creating an account stores your email address, name, and either a hashed password or your Google sign-in identifiers — never a plaintext password. Active sessions record an IP address and browser user-agent string for session security; these are removed when the session ends or is revoked.
Unmarked Pro usage metadata
Every account receives about 375,000 words of rewriting per calendar month. To enforce that allowance and support aggregate product decisions, trial extensions, and abuse prevention, we retain account ID, provider/model, client surface, rewrite intensity, input/output token and character counts, model-call and completed-stage counts, status/error category, timestamps, and duration. These records contain no source text, prompt, provider output, or final rewritten text.
Your OpenRouter connection
Connecting OpenRouter stores your API key encrypted at rest (AES-256-GCM), alongside its last four characters and a label so you can recognize it. The key is decrypted only to authenticate your own rewrite requests. You can disconnect it at any time from your account page, which deletes the stored key. The key itself lives in your OpenRouter account and is unaffected — manage or revoke it at openrouter.ai.
Voice profiles
Writing samples you submit to build a voice profile are analysed and then discarded by default; only the derived style description is saved. If you explicitly choose to retain excerpts, those excerpts are stored encrypted. Profile revisions are kept while the profile exists so changes can be audited and rolled back. You can delete individual profiles at any time, which removes their samples and revisions.
Product analytics and campaign tracking
The web app uses PostHog's US Cloud service to understand traffic, measure outreach campaigns, and learn which product features are useful. Browser analytics starts when the web app loads unless your browser sends a Do Not Track signal. We use this information to operate and improve Unmarked, not for advertising or tracking you across other companies' sites.
The analytics we intentionally collect includes:
- Page and device information. Page views, current page URL and campaign parameters, referring page, event time, browser, operating system, device category, and an analytics identifier.
- Feature use. The action performed and limited measurements or settings needed to understand it. Examples include tool and media type, cleaning policy, model and rewrite intensity, character and finding counts, file extension and byte size, processing time, copy actions, and sign-in method.
- Campaign-link visits. If you visit a short link under
/go/, the redirect records the link slug, whether it matched a campaign, campaign parameters, referring page, country, browser user-agent, and time. That click uses a new random identifier and is sent before the landing page loads, so browser Do Not Track settings do not prevent this single server-side event.
These events contain counts, sizes, settings, and technical context — never your pasted text, rewritten text, file contents, file names, passwords, or provider API keys. We disable PostHog's automatic interaction capture, session replay, heatmaps, dead- and rage-click capture, browser performance monitoring, and browser exception capture.
PostHog does not set analytics cookies on this site. It stores its identifier in your browser's localStorage so it can recognize a browser across visits. Anonymous activity remains anonymous until you sign in. At sign-in, we send PostHog your internal account ID, email address, and name and associate that account with the browser's earlier analytics activity. Signing out resets the identifier used for future activity on that browser, but does not erase events already collected. The web app separately uses strictly necessary cookies for sign-in, session security, and provider-connection flows.
Where data lives
Unmarked's service providers for the web app:
- Supabase — database hosting (Postgres, AWS us-west-2) for account data, encrypted keys, and voice profiles.
- Cloudflare — serves production traffic.
- PostHog — product analytics and campaign measurement (US region).
- Google — sign-in, if you use “Continue with Google”.
- Celeris — the default Unmarked Pro rewrite model provider.
- OpenRouter and the model provider you select — optional bring-your-own-provider rewriting requests and the Cerebras capacity fallback for Unmarked Pro.
Retention and deletion
Attachment content and rewrite text are not retained. The usage metadata described above and other account data are kept until you delete them: the Delete account action on your account page immediately and permanently removes your account, sessions, sign-in records, OpenRouter connection, voice profiles with their samples and revisions, and Unmarked Pro entitlement and usage metadata. Deletion is self-serve and cannot be undone.
PostHog analytics records are stored separately from the main account database. Deleting your Unmarked account does not automatically erase analytics events already collected. You can request access to or deletion of analytics associated with your account through the support contact below. Anonymous campaign clicks use one-time identifiers and may not be linkable to you.
The Chrome extension
Unmarked for Chrome transforms clipboard text only when you ask it to. It has no advertising or persistent content scripts and does not scan pages. Text cleaning runs locally. Hosted Unmarked Pro rewriting, optional account sync, and signed prompt updates contact Unmarked's service as described below.
Local sanitation
When you select Warp text, the extension reads text from the clipboard, removes eligible invisible Unicode characters locally, and writes the result back to the clipboard. The text is not retained and does not leave the device.
Model rewriting
Unmarked Pro is the recommended provider. It requires an Unmarked account and includes about 375,000 words of rewriting per calendar month. Every Unmarked Pro rewrite goes through Unmarked's service and normally then to Celeris-1 using Unmarked's shared provider key. Near the Celeris request-rate limit, a model call may instead go through OpenRouter to GPT-OSS 120B hosted by Cerebras. The extension streams step-level progress from the service while the rewrite runs.
Unmarked does not persist source text, the rendered prompt, provider output, or the final rewritten text. It stores only the usage metadata listed in the web-app section above. You can instead select OpenRouter, a custom OpenAI-compatible endpoint, or Ollama. In those modes, Unmarked sends the following either directly to the configured endpoint or, for an account-backed OpenRouter connection, through Unmarked's service:
- The clipboard text you asked it to rewrite.
- The rewrite instructions and selected style.
- Derived voice guidance, including short excerpts only when you explicitly opted to retain them.
- The provider credential required to authenticate the request.
The extension requests access only to a custom configured endpoint when you first use it. Direct-provider and Ollama requests do not pass through Unmarked. A connection test sends only a fixed test prompt, not clipboard text or a voice profile.
Data stored in Chrome
The extension uses chrome.storage.local to retain extension settings, encrypted provider credentials, derived voice profiles you save, a signed prompt cache, and — if you connect an Unmarked account — an encrypted account-session token. Provider credentials and the account-session token are encrypted at rest with AES-256-GCM. The ciphertext is stored in Chrome's local storage and the non-exportable encryption key is stored separately in IndexedDB. Code running inside the same unlocked Chrome profile can still ask the browser to decrypt those credentials, so use a limited provider key and protect the computer account and Chrome profile.
Full writing samples used to build a voice profile are sent to your configured model provider for the requested qualitative analysis and then discarded by Unmarked; derived observations are saved. Short source excerpts are saved and later sent with rewrite requests only when you enable the optional excerpt checkbox — off by default, with the resulting prompt shown before use. You can clear a stored key in settings, delete individual voice profiles, or remove all extension data by uninstalling the extension.
Optional Unmarked account sync
If you explicitly sign in to an Unmarked account from the extension, Unmarked issues a revocable extension session and stores its token only as a cryptographic hash on the server. The session record is associated with your account and includes its creation, expiry, and last-used times and the browser user-agent reported when it was created.
When you choose to sync voice profiles, the extension sends the derived profile name, style description, structured style data, sample counts, and analyzer/version metadata to Unmarked. It does not upload the raw writing samples, retained excerpts, provider credentials, or rewrite text through this sync. Unmarked stores the synchronized profile and its revisions with your account so it can be used across connected devices. Signing out revokes the extension session and clears the website session used by Chrome's authentication window when the service is reachable. It always removes the local token, identity, account settings, sync cursor, and synchronized-profile cache. Purely local voice profiles and unmigrated local provider credentials remain on the device. Deleting your Unmarked account removes its server-side sessions and synchronized profiles.
Signed prompt updates
The extension periodically requests a signed prompt-data file from tryunmarked.com and caches a verified newer version in Chrome's local storage. This anonymous request does not include clipboard or rewrite text, account credentials, an account token, or an installation identifier. If the request or signature check fails, the extension continues using its bundled prompts.
Chrome Web Store Limited Use
Unmarked's use of information received from Google APIs, including Chrome extension APIs, will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.
That information is used only to provide the extension's single purpose: transforming clipboard text after an explicit user action. It is transferred only to a model endpoint the user selects when optional rewriting is requested, as described above. It is not used or transferred for advertising, unrelated profiling, creditworthiness, or lending. The Unmarked developer does not receive the data or permit anyone acting on its behalf to read it.
Changes and contact
Material changes to this policy will be published here with an updated effective date. Questions can be sent through the support contact shown on Unmarked's Chrome Web Store listing.