Privacy Policy
Last updated: October 2026.
1. Who we are
This Privacy Policy explains how DataAnonymiser ("we", "us") collects and uses personal data in connection with the DataAnonymiser desktop application, this website, and the associated account and licensing services (together, the "Service"). For the purposes of the EU/UK General Data Protection Regulation (GDPR), we are the data controller for the personal data described below. Contact: support@dataanonymiser.com.
2. Our core principle: local-only processing
All content processing — detecting personal data, replacing it with placeholders, describing images, and producing risk reports — runs entirely on your device. We do not upload, log, stream, sync, or otherwise transmit your source text, images, document contents, prompts, anonymized outputs, placeholder mappings, risk reports, or filenames to our servers, to any analytics system, or to any third party. Your content is never processed in the cloud. This is enforced in the software itself, not just by policy.
3. Personal data we collect
We collect only account, device, and billing metadata:
- Account data: your email address, and one-time sign-in codes (stored only as salted, non-reversible hashes with a short expiry).
- Device & license data: a device identifier, application version, and operating-system platform, used to activate your license, enforce your plan's device limit, and issue your license. The license contains only account and subscription metadata (account ID, device ID, plan, entitlements, and expiry), never your content.
- Subscription & billing data: your plan tier, billing interval, subscription status, renewal date, any bonus-extension window, and the identifiers our payment processor assigns to your customer and subscription. Payment card details are entered directly with our payment processor (Stripe) and are never received or stored by us.
- Optional feedback submissions: if you voluntarily submit a "failure example" to help us improve anonymization, you must redact all real sensitive and personal data yourself before submitting it. We store the submitted example, a non-reversible fingerprint (hash), and submission status in our database so that we can review it, improve the Service, prevent duplicates, and record any reward. Please never include real personal data in a submission.
- Support communications: the content of emails you send us.
4. Website, cookies & analytics
This section is about this website only. It does not change anything in section 2: the desktop application and the browser extension send no content anywhere, and no analytics of any kind runs inside them.
- Strictly necessary storage: we store your theme preference and your cookie decision in your browser's local storage, and we keep you signed in during an account session. This storage is required for the site to work as you asked it to, is never transmitted to us, and needs no consent.
- Analytics (optional, off until you accept): if you accept, we use Google Analytics 4 to measure how this website is used — pages viewed, approximate region, referrer, and device type. Google sets cookies on this domain (
_ga,_ga_*) to distinguish visits. The Google Analytics script is not loaded and no request is made to Google until you accept, and advertising and personalisation signals are switched off permanently, so your visit is never used for ad targeting or shared for advertising purposes. - Advertising measurement (optional, off until you accept): if you accept, we also load the Meta Pixel from Meta Platforms Ireland Limited to measure our ads on Facebook and Instagram and to show our ads to people who have visited this site. It records the pages you view and sets cookies on this domain (
_fbp,_fbc). Automatic event detection is switched off, so it does not read forms, fields or buttons. The Meta Pixel is not loaded and no request is made to Meta until you accept. - Purchase reporting to Meta: when you buy a subscription, our server may tell Meta that a purchase happened (plan, price and currency), together with your email address and account ID in hashed form so Meta can attribute it to an ad. If you accepted cookies, it also passes on Meta's browser and ad-click identifiers and your browser type. If you made no cookie choice, we may send only the hashed email, hashed account ID and browser type, based on our legitimate interest in measuring our advertising. We never report your purchase to Meta if you rejected non-essential cookies or your browser sends a Global Privacy Control signal, and you can object at any time via Cookie settings or by emailing us.
- What analytics and Meta never receive: anything you type into the app or the extension, any document, image or file you process, any anonymised output, placeholder map or risk report, and any filename. None of that exists on this website in the first place.
The legal basis for analytics and advertising cookies is your consent (Art. 6(1)(a) GDPR and § 25(1) TDDDG). You can change or withdraw it at any time via Cookie settings in the footer of any page; withdrawal takes effect immediately, deletes the analytics cookies we can reach, and does not affect processing carried out before it. Google Analytics is provided by Google Ireland Limited as our processor, with transfers outside the EEA covered by the safeguards described in section 7. For the Meta Pixel and purchase reporting, we and Meta Platforms Ireland Limited are joint controllers for collecting and transmitting the data (Art. 26 GDPR); Meta then processes it as its own controller under its privacy policy.
5. Why we process it (legal bases under GDPR)
- Performance of a contract (Art. 6(1)(b)): to create and manage your account, activate and refresh your license, and deliver the subscription you purchased.
- Legitimate interests (Art. 6(1)(f)): to secure the Service, prevent fraud and abuse (including license and device-limit enforcement), and improve the product from voluntarily submitted feedback, and, where you made no cookie choice, to report a purchase to Meta in reduced, hashed form to measure our advertising (you can object at any time).
- Consent (Art. 6(1)(a)): for optional feedback submissions, and for the optional website analytics and advertising cookies and the purchase reporting described in section 4. You may withdraw consent at any time; withdrawal does not affect prior processing.
- Legal obligation (Art. 6(1)(c)): to meet tax, accounting, and record-keeping requirements relating to payments.
6. Service providers we share data with
We share the limited data above only with processors that help us run the Service, under contract and only as needed:
- Stripe: payment processing and subscription billing. Stripe handles your card details directly under its own privacy policy; we receive only subscription status and billing metadata.
- Microsoft (Exchange Online / Graph): delivery of transactional and account emails, and receipt of any feedback submissions you send for review.
- Google (Google Ireland Limited): website analytics, and only if you accepted analytics cookies. Google receives website usage data (pages viewed, referrer, approximate region, device type) under its own privacy policy. It never receives any content you process in the app or the extension.
- Meta (Meta Platforms Ireland Limited): advertising measurement, as described in section 4: website visits if you accepted cookies, and purchase events. Meta never receives any content you process in the app or the extension.
- Hosting provider: our account and licensing servers are hosted in Germany.
We do not sell your personal data. We share website-visit and purchase data with Meta only as described in section 4, to measure and target our own advertising.
7. International transfers
Our account and licensing infrastructure is operated in Germany. Where a processor (such as Stripe or Microsoft) processes data outside the European Economic Area, that transfer is covered by an appropriate safeguard under GDPR, such as the European Commission's Standard Contractual Clauses. The same applies to Google and Meta, which may process analytics and advertising data in the United States.
8. How long we keep it
- Account and subscription data: for as long as your account is active.
- Billing records: as required by applicable tax and accounting law after your account closes.
- One-time sign-in codes: minutes (they expire quickly and are single-use).
- Feedback submissions, fingerprints, and status: retained as necessary to review submissions, improve the Service, prevent duplicates, and record rewards.
9. Your rights
If you are in the EU/UK (GDPR): you have the right to access, rectify, erase, restrict, or object to processing of your personal data, the right to data portability, and the right to withdraw consent. You also have the right to lodge a complaint with your local data protection supervisory authority.
If you are a California resident (CCPA/CPRA) or in another US state with similar law: you have the right to know what personal information we collect and how we use it, to request access and deletion, to correct inaccurate information, and to opt out of any "sale" or "sharing" of personal information. We do not sell your personal information. We share limited data with Meta for advertising as described in section 4; you can opt out of that at any time via Cookie settings or by emailing us, and we honour Global Privacy Control signals. We will not discriminate against you for exercising your rights. To exercise any right, contact support@dataanonymiser.com; we may need to verify your identity via your account email.
10. Security
We use encryption in transit (TLS), store one-time sign-in codes only as salted hashes, and sign license tokens cryptographically. The desktop app stores its license token locally in its application data directory. Because your content is never transmitted to us, it is not exposed to any server-side breach of our systems. No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security.
11. Children
The Service is not directed to children and is not intended for use by anyone under 16 (or under 13 in the United States). We do not knowingly collect personal data from children.
12. Changes
We may update this Policy from time to time. Material changes will be reflected by the "Last updated" date above and, where required, notified to you.
13. Contact
Privacy questions or requests: support@dataanonymiser.com. See also our Terms of Service and Limitations.