Privacy Policy
Updated 10 October 2026
Who is responsible
Graysphere LLC, a Wyoming limited liability company at 30 N Gould St Ste N, Sheridan, WY 82801, USA, is the controller of personal data processed by Markedfile. The contact email is contact@graysphere.com. The company site is https://graysphere.com.
Account data
When you register, we store your name, your email address, and a hash of your password in an authentication database on the server that runs the service. We also store sessions so you stay signed in. A session lasts up to 30 days. We do not ask for a phone number or a postal address.
You can change your name, email, and password from profile settings. Changing the email sends a confirmation to the new address when email delivery is configured, and the address stays the same until that link is opened. Registration can send a verification message. The login screen can send a password reset link when email delivery is configured. You can turn on an authenticator app from profile settings. While it is on, signing in asks for a current code from that app. We store an encrypted authenticator secret and encrypted backup codes. The plain codes are shown once. A backup code can be used once to sign in, and then it no longer works. From profile settings you can see the devices signed in to this account, when each session started, and sign out another device or every other device. That list shows an approximate browser and system. It does not include session tokens or network addresses.
Product records
A separate database stores workspaces, members (name and email), invitations, and file records. An invitation stores the invited email and a hash of the token, not the token itself, and it expires after 7 days. A file record stores the identifier you assigned, the file name and type, processing layers, timestamps, status (active, paused, or expired), and a detection token while the file is active. An Enterprise workspace can store API keys. We store the name, a short prefix, and a SHA-256 hash of the secret. The secret is shown once and is not stored. An audit row records who created or revoked a key, and each mark or detection made with that key: the time, the key prefix, the action, and the identifier you assigned. It does not store the file. A report of abuse, or of a file someone believes is theirs, stores the date, the requester's name and email, a short description, and the kind of request. It does not store the file.
File contents
Uploaded bytes and marked copies are processed in memory and are not written to disk. Do not send a file if you do not want it processed for watermarking or detection.
Cookies and local storage
better-auth.session_token keeps you signed in. It is HttpOnly and lasts up to 30 days. On HTTPS the name may use a secure prefix.
theme and theme-color store your appearance (light, dark, or system). The same choice is stored in localStorage under the key theme.
markedfile_workspace remembers the workspace you selected. It is HttpOnly.
markedfile_locale remembers the language you choose. It is HttpOnly.
mark_session is a legacy cookie from an older anonymous session. It is read only to move old file records onto your account. New sessions do not rely on it.
When Resend is configured, with an API key and a from-address, Markedfile can send a branded workspace invitation through Resend in English, Spanish, or German. That message includes the recipient address, the workspace name, and an invitation link. A failed invoice sends one message to the workspace billing email, in English, Spanish, or German, with a link to Manage subscription. If that invoice is paid later, one message says the payment went through. The invoice id is stored so the same notice is not sent twice. A public report sends one notice to the public inbox and to each configured admin address. The notice includes the requester's name and email, a short description, and a link to the admin page. The file is not attached. Resend processes the message as the email provider. When Resend is not configured, no invitation email is sent and the owner copies a link. On a local machine the unsent message can be previewed; a public production server does not store it. Markedfile does not send marketing email.
Payments
When Stripe is configured, checkout and the billing portal are provided by Stripe. Markedfile would receive subscription status (plan, status, and period end) and a customer reference. Card numbers are handled by Stripe and are not stored by Markedfile. When Stripe is not configured, we do not send payment data to Stripe and we do not charge you.
Analytics
Marketing and legal pages load a script served by this site. Your files and the rest of the signed-in app do not. The script sends the page address, the title, the browser language, the screen size, and the referrer to this site. This site forwards that visit, your network address, and your browser name to Umami so we can see which public pages are used and from which country. Umami does not use cookies. File contents are not included. The admin dashboard does not show an analytics view.
Retention
Account data is kept while the account exists. An account that is still unverified 7 days after registration is deleted, along with its sessions and personal workspace. About one day before that, one reminder is sent when email delivery is configured. From profile settings you can download a ZIP of your profile, the workspaces you belong to, and the file records you can see. That file lists the identifier, file name, type, dates, and status. It lists API key names and prefixes, not the secrets. It does not include file contents or detection tokens, and it does not include another person's account. The same settings can delete the account after you enter your password. Deleting the account removes the login and the memberships. A shared workspace you own goes to the earliest other member. Files in a workspace you do not own stay in that workspace. Paid subscriptions on workspaces you own are canceled. If you cannot sign in, you can ask Graysphere LLC at contact@graysphere.com to delete the account. A file stays detectable while it is active. Records stay until you delete them or they expire. Deleting a file ends detection and frees a slot. On Free, an active file expires 6 calendar months after marking, and the detection token is removed. Expired records can remain as history without a token.
Who we share data with
We do not sell personal information. Public pages forward the visit details described above to Umami. Umami does not use cookies. We share other information with Resend or Stripe only when those services are configured and only for the purpose above. We may disclose information if the law requires it.
Contact
Privacy questions go to Graysphere LLC at 30 N Gould St Ste N, Sheridan, WY 82801, USA, or by email at contact@graysphere.com. The company site is https://graysphere.com.