Privacy Policy
Last updated: 2026-09-17
1. The short version
Quick Clean runs entirely in your browser — text you paste for character cleaning never leaves your device. Deep Rewrite sends your text to a third-party LLM API (OpenRouter) solely to produce the rewrite. You can use the service anonymously; if you choose to sign in with Google, we store your basic profile (name, email address, profile picture) and set one first-party session cookie (session) so your quota can sync across devices — see the sections below. We use Google Analytics and Microsoft Clarity for aggregate, non-identifying usage statistics and session recordings; these providers may set cookies and process interaction data under their own privacy policies.
2. What stays on your device
Text processed by Quick Clean, and your tool usage history (the History drawer), are stored only in your browser's localStorage. We never receive or store this content on our servers. Your rewrite history is local-only: it lives exclusively in your browser's local storage and is never uploaded to or stored on our servers.
3. What our servers process
To enforce the daily Deep Rewrite quota, our servers store a random device identifier (generated in your browser). For abuse prevention, we also process — without storing — a non-reversible browser fingerprint hash and your IP address as seen by Cloudflare. Quota records are kept in Cloudflare KV and expire automatically after 8 days. Share links carry a random referral code; when someone opens your link, that code and the visitor's device identifier are recorded to credit the bonus. If you sign in with Google, your daily quota is tracked against your account in Cloudflare KV instead.
4. What Deep Rewrite sends to third parties
When you use Deep Rewrite, the text you submit is sent to OpenRouter (openrouter.ai), which routes it to the language model provider that serves the response. This transmission happens only when you click Deep Rewrite. Please review OpenRouter's own privacy policy for how they handle API traffic; do not paste sensitive personal data into Deep Rewrite.
5. Third-party services
The site is hosted on Cloudflare Workers and uses Cloudflare Turnstile to distinguish humans from bots — Turnstile may set a challenge cookie for that purpose. We use Google Analytics and Microsoft Clarity to collect aggregate, non-identifying usage statistics and, in Clarity's case, session recordings (such as mouse movements, clicks, and scrolls); these providers may set cookies and process interaction data under their own privacy policies. Fonts are loaded from Google Fonts. These providers process connection data (such as IP address) under their own privacy policies.
Google Sign-In. When you choose to sign in, we receive your Google account's basic profile (name, email address, profile picture) from Google's OAuth service. We store your profile in a Cloudflare D1 database to identify your account, and sync your quota — rewrite counts only, never your text — across devices via Cloudflare KV.
Session cookie. When you sign in, we set a single HttpOnly cookie (session) to keep you signed in. It expires after 30 days or when you sign out, and it contains a random token — never your Google data.
6. Data retention and deletion
Server-side quota and referral records expire automatically; click-deduplication records used for abuse prevention are kept without expiry. You can clear all locally stored data at any time by clearing your browser's site data for this domain. If you signed in with Google, you can request account deletion at any time via the contact channel listed on this site; we remove your profile row from the D1 database within 7 days.
7. Changes
We may update this policy from time to time. The date above reflects the latest version. Material changes will be reflected on this page.
8. Contact
Questions about privacy: open an issue on the project repository or contact the operator via the links in the footer.