blotmarked.app

Privacy Policy

LAST UPDATED 19 September 2026
The short version: the documents you redact are never uploaded. They're opened, scanned, and rebuilt entirely in your browser, on your device, and are never sent to blotmarked.app or anyone else. The only data our server ever stores is limited account/business data described below. Never a file, a detected value, or anything read from inside a document.

1. Who this policy covers

This policy explains how Derrick Tawah, trading as Leanstart Africa ("we", "us") handles personal data in connection with blotmarked.app: the redaction tool itself (at /app), the marketing pages, and the administrative console at /admin used by our own staff. It does not cover third-party sites we link to.

2. What we never see or store

The redaction tool works like this, on purpose:

  • Every file you open is read, scanned for personal data, and rebuilt entirely in your browser.
  • Text detection reads a PDF's own text layer locally; scanned pages/images run through on-device OCR (Tesseract, bundled with the app). There is no third-party OCR or AI API called with your content.
  • The redacted output is generated on your device and handed to your browser's normal download, never uploaded anywhere by us.
  • No file, page image, detected value (name, email, phone, ID number, etc.), or redaction you draw is ever transmitted to our servers, logged, or retained by us in any form.

Our database is intentionally structured so this is a technical fact, not just a policy: it holds only the account/business records described in §3. It has no table, column, or field capable of holding a document or its contents.

3. Data we do collect, and why

Using the redaction tool (no account required). We don't collect anything just to open and redact a document, and nothing about a document reaches us. Your working session - the files you have open, every redaction decision, the page-by-page review - lives only in your browser's memory and disappears when you close or reload the tab, unless you save a file yourself.

What the app does keep on your device. A small number of values are stored in your browser, by the browser, and are never sent to us. None of them is used for analytics or tracking, and none of them describes a document:

  • Your credit code and balance, so that credits you have paid for survive closing the app. This is the one item that matters: without it a purchase would be lost the moment the tab closed.
  • That you agreed to the terms, so you are not asked again on every visit.
  • That you have seen the introduction, and that you dismissed the install prompt, so neither reappears every time you open the app.
  • A credit code in transit, held for the few seconds between the payment page and the app, then deleted. It is kept here rather than put in the address bar, where it would end up in your browser history.

You can clear all of it at any time through your browser's site-data settings. Clearing it removes your credit balance from this device as well, so keep the code from your receipt first - it is the only way to restore the balance.

Requesting tester access. If you submit the "request access" form, we store the email address and optional note you provide, to review and respond to your request. If you are accepted we send two reminders as the test period ends, and every one of those carries a link that stops them for good.

Tester feedback (optional). While you are testing, the screen after an export offers a short feedback form. If you send it, we store your answers (whether it was useful, what kind of document you were redacting), the note you wrote, and an email address only if you chose to give one for a reply, and we email the same to ourselves so it is read. It never includes your document, a page, or anything found in it - please do not paste anything from your document into the note. Without an email address it does not identify you.

Notifications about test access (optional). If, and only if, you have asked for tester access and then chosen "Notify me on this device", your browser creates a push subscription and we store it against the email address you already gave us, along with the browser identifier your push service issues. We use it for two things and nothing else: telling you a request was approved, and reminding you before a test period ends. It is never offered or used in connection with redacting a document, and no notification ever contains anything about a document. You can turn it off on the same screen, or in your browser's site settings, and we delete the subscription when you do.

Redeeming an invite or credit code. Redeeming a code only sends the code itself; looking up a credit code returns its remaining credit balance. Neither requires an account or collects an identifier beyond the code.

Requesting a refund. The refund form sends your credit code or payment reference, a reason, and an optional note, so we can locate the matching payment and decide on it. We don't ask for or need a user ID, because none exists.

Cash/manual payments. If a payment is recorded manually (e.g. bank transfer) rather than through a card processor, we store the amount, an email or label you gave us for that payment, and the credit code it generated, for accounting and support purposes.

Card payments. Checkout is handled by Stripe on their own hosted page. Your card details go to them, never to us. Stripe also asks for an email and a phone number so we can send you a payment receipt (by email, and by SMS/WhatsApp if you gave a number); we receive that email and phone number once, at the moment of payment, to send the receipt and email is then kept alongside the payment record for support/refund lookups, the same as a cash payment, but the phone number is never stored anywhere by us, it's used for that one message and discarded.

Signing in to the admin console. This section only applies to our own authorized staff, not to people using the redaction tool. Admin sign-in is a one-time emailed link tied to an email address on an invite list; optionally, an admin can sign in with Google, which shares only their verified email address with us (no other Google profile data is requested). A signed session cookie keeps that admin signed in for up to 12 hours.

Audit log. Every administrative action (approving a tester, editing pricing, deciding a refund, etc.) is recorded with the acting admin's email, the action, and its target, so changes to pricing, policy, and money are always traceable.

4. Cookies and tracking

There are no analytics, no advertising, and no third-party tracking scripts of any kind, anywhere on this site. Nothing here profiles you, and nothing here is shared with an advertising network.

Cookies. Using the redaction tool sets no cookies at all. The only cookies on this site are set when an authorized admin signs in at /admin: a strictly-necessary httpOnlysession cookie, and a short-lived state cookie if that admin chooses to sign in with Google. Neither is set for members of the public, and neither identifies anything about you.

Browser storage. The app does store a few values on your own device, listed in section 3 above. They are strictly for making the app work - remembering the credits you paid for, and not repeating a prompt you have already answered - and they stay in your browser. We cannot read them, because they are never sent to us.

5. Legal basis for processing

Where GDPR/UK GDPR applies: tester requests, tester feedback, refund requests, and payment records are processed under legitimate interest and/or to take steps requested by you before or in connection with a contract; admin accounts and the audit log are processed under our legitimate interest in operating the service securely and accountably.

6. Who we share data with

We don't sell data, and we don't use ad networks or analytics providers. The limited data described in §3 may be shared with:

  • Our email delivery provider, to send magic-link sign-ins, tester decisions, refund decisions, and payment receipts, and to forward tester feedback to us.
  • Our SMS/WhatsApp provider (Twilio), only to send a payment receipt to the phone number given at checkout. We don't pass them anything else, and we don't keep that number ourselves afterward.
  • Our payment processor(s) (Stripe and/or Wero), only for the transaction data needed to process a payment or refund.
  • Google, only if an admin chooses "Continue with Google" to sign in and is limited to verifying their email address.
  • Vercel, which hosts the site and handles the ordinary request data any web server sees.
  • Supabase, which hosts the database described above: payment records, credit codes, tester requests, tester feedback and the admin audit log.
  • Your browser's push service (Apple, Google or Mozilla, depending on your browser), and only if you turned notifications on.

None of them ever receives a document, a page image or anything detected inside one, because none of that reaches us in the first place.

We may also disclose data if required by law or to protect the security of the service.

7. International transfers

Because document content never reaches our servers, there is no cross-border transfer of your document data to consider. The limited account/business data in §3 is processed on infrastructure operated by us and our processors named in §6; where that involves a transfer outside your jurisdiction, we rely on the applicable safeguards required by law (e.g. standard contractual clauses).

8. How long we keep data

Documents and anything read from inside them: not retained at all. We never receive them in the first place.

Tester requests, invite codes, credit codes, payment records, and the audit log are kept for as long as needed for support, accounting, and legal/tax obligations, after which they may be deleted or anonymized.

Tester feedback is deleted automatically 12 months after it was sent.

Asking us to delete your data. Write to the address at the end of this policy. Tell us the email address you used, or the credit code, so we can find the right record - we hold no other identifier, so without one of those there is nothing to search. We will answer within one month.

What we can delete: your tester request and any note you wrote on it, feedback you sent with a reply address, your notification subscription, and the email address stored against a payment. What we cannot delete, and will tell you so rather than quietly keeping it: the payment record itself, which German and EU tax law requires us to retain, and the admin audit log, which exists so that changes to money and policy stay traceable. Deleting the email address from a payment leaves the amount, the date and the credit code, which identify a transaction rather than a person.

Deleting the email on a payment also ends our ability to help with it, since that address is the only way we could match a support question to a purchase. Your credit code keeps working either way - it is held on your device, not by us. Admin accounts are retained until revoked.

9. Security

We built the service around not holding sensitive data in the first place, plus:

  • All document processing, OCR, and file rebuilding happens locally using self-hosted code. There is no third-party CDN or API that ever receives your file or its content.
  • Security response headers are set on every response (no MIME sniffing, no referrer leakage, cross-origin isolation).
  • Admin sign-in is passwordless (magic link or Google), and admin sessions use a signed, time-limited token rather than a stored password.
  • Administrative actions are individually role-checked on the server and permanently logged.

No system is perfectly secure, and we can't guarantee absolute security of any data transmitted to us.

10. Your rights

Subject to applicable law, you may have the right to access, correct, delete, or export the personal data we hold about you (as described in §3), object to or restrict its processing, and withdraw consent where processing relies on it. Because we don't collect document content or run any account system for the redaction tool itself, most of these rights are already satisfied by how the product works. To exercise a right over the limited data we do hold (a tester request, a refund request, an admin account, etc.), contact us at leanstart.africa@gmail.com. You can also lodge a complaint with Berliner Beauftragte für Datenschutz und Informationsfreiheit (BlnBDI).

11. Children

blotmarked.app is not directed at children under 16, and we do not knowingly collect personal data from them.

The terms of use set a higher bar of 18 for buying credits or asking for test access. The two are answering different questions rather than contradicting each other: 16 is the age at which somebody can consent to an online service handling their data, and 18 is the age at which they can enter into a purchase. Redacting a document requires neither, because it involves no account and no data reaching us at all.

12. Changes to this policy

We'll update this page if what we collect or how we use it changes, and update the date at the top.

13. Contact

Questions about this policy, or a request to exercise a data-protection right: leanstart.africa@gmail.com. This policy is governed by German law.