Privacy Policy

Updated 8 October 2026

Who is responsible

Graysphere LLC, a Wyoming, United States company, is the controller of personal data processed by Markedfile. The company site is https://graysphere.com.

Account data

When you register, we store your name, your email address, and a hash of your password in an authentication database on the server that runs the service. We also store sessions so you stay signed in. A session lasts up to 30 days. We do not ask for a phone number or a postal address.

You can change your name, email, and password from profile settings. Changing the email sends a confirmation to the new address when email delivery is configured, and the address stays the same until that link is opened. Registration can send a verification message. The login screen can send a password reset link when email delivery is configured. You can turn on an authenticator app from profile settings. While it is on, signing in asks for a current code from that app. We store an encrypted authenticator secret and encrypted backup codes. The plain codes are shown once. A backup code can be used once to sign in, and then it no longer works.

Product records

A separate database stores workspaces, members (name and email), invitations, and file records. An invitation stores the invited email and a hash of the token, not the token itself, and it expires after 7 days. A file record stores the identifier you assigned, the file name and type, processing layers, timestamps, status (active, stopped, or expired), and a detection token while the file is active.

File contents

Uploaded bytes and marked copies are processed in memory and are not written to disk. Do not send a file if you do not want it processed for watermarking or detection.

Cookies and local storage

better-auth.session_token keeps you signed in. It is HttpOnly and lasts up to 30 days. On HTTPS the name may use a secure prefix.

theme and theme-color store your appearance (light, dark, or system). The same choice is stored in localStorage under the key theme.

leakcatcher_workspace remembers the workspace you selected. It is HttpOnly.

leakcatcher_locale remembers English or Spanish. It is HttpOnly.

mark_session is a legacy cookie from an older anonymous session. It is read only to move old file records onto your account. New sessions do not rely on it.

Email

When Resend is configured, with an API key and a from-address, Markedfile can send a branded workspace invitation through Resend in English or Spanish. That message includes the recipient address, the workspace name, and an invitation link. Resend processes the message as the email provider. When Resend is not configured, no invitation email is sent and the owner copies a link. On a local machine the unsent message can be previewed; a public production server does not store it. Markedfile does not send marketing email.

Payments

When Stripe is configured, checkout and the billing portal are provided by Stripe. Markedfile would receive subscription status (plan, status, and period end) and a customer reference. Card numbers are handled by Stripe and are not stored by Markedfile. When Stripe is not configured, we do not send payment data to Stripe and we do not charge you.

Analytics

No analytics script loads unless both an Umami script URL and an Umami website id are configured. When they are, public pages may load that script. The admin dashboard may embed an Umami share view when a share URL is configured. That embed is not shown to ordinary visitors. When those values are unset, no analytics script is rendered.

Retention

Account data is kept while the account exists. An account that is still unverified 7 days after registration is deleted, along with its sessions and personal workspace. About one day before that, one reminder is sent when email delivery is configured. The product has no self-serve account deletion. You can ask Graysphere LLC, through the company site, to delete an account. File records stay until you delete them, you stop detection, or they expire. On Free, an active file expires 6 calendar months after marking, and the detection token is removed. Stopped and expired records can remain as history without a token.

Who we share data with

We do not sell personal information. We share it with Resend or Stripe only when those services are configured and only for the purpose above. We may disclose information if the law requires it.

Contact

Privacy questions go to Graysphere LLC, through https://graysphere.com. This page does not publish a street address or a dedicated privacy inbox.