Effective and last updated: September 14, 2026
Publisher: 陳譽文 (CHEN, YU-WEN)
Contact: fishanyvalue@gmail.com
1. Scope
This notice applies only to Watermark Studio. It does not replace the separate RabbitSubtitle website privacy notice, the Watermark Studio listing’s Data Sharing Declaration, or the privacy terms of Capafy, your Agent Client, an AI provider, your operating system, or another service you choose to use.
Watermark Studio is a downloadable skill. Capafy may process account, purchase, delivery, security, and marketplace-use data under its own privacy terms. After delivery, the skill runs in the Agent Client you use: a language model may interpret your instructions and job context, while the bundled deterministic conversion program performs the actual watermark transformation locally.
2. Files and settings processed locally
To perform a requested job, the conversion program may read the files and settings you select on your device. Processing may include:
- documents, images, videos, filenames, file paths, and basic media metadata;
- watermark text or an authorized watermark image;
- position, opacity, size, color, timing, motion, output format, and conflict-handling choices; and
- local quality-assurance information such as hashes, page counts, dimensions, duration, codecs, and output status.
3. No media upload or conversion telemetry
The bundled watermark conversion program processes media in the local runtime and does not proactively upload your source media or outputs to the publisher or an undeclared service. The conversion program contains no telemetry, analytics SDK, advertising tracker, or AI API call, and it requires no API credential.
FFmpeg and LibreOffice, when needed, run as local external programs. Installing Watermark Studio or its dependencies may contact the applicable software or package source, but that is separate from processing your media.
4. Agent Client and AI-provider processing
The AI provider used for a job is determined by your Agent Client and its settings. Depending on how you invoke the skill, the Client or provider may receive or generate your prompt, attachments, filenames, local path strings, metadata, previews, watermark text and settings, QA or delivery-manifest summaries, hashes, and output links. A Client may upload an attachment before making a local file path available to the skill.
These conditional third-party data flows are not performed by the bundled conversion program and are outside the publisher’s control. Review the actual Agent Client and AI provider named in your configuration, including their retention and model-training choices, before supplying sensitive material. The Watermark Studio privacy page supplements, but does not replace, the Data Sharing Declaration shown on its Capafy listing.
5. Temporary files, outputs, and retention
During processing, the local runner may create a working copy under your operating system’s temporary directory. The runner attempts to delete its internal temporary data after each processed item. An unexpected error, forced termination, power loss, or operating-system failure may prevent that cleanup and leave temporary data behind. You may remove stale Watermark Studio temporary data after confirming that no watermark job is running.
The input job JSON is read by the runner but is not deleted by it. It may contain local paths and watermark settings, and remains wherever you or your Agent Client created it until you or the Client remove it.
Watermarked outputs, QA reports, delivery manifests, and any quarantined failure artifacts are intentionally retained in the output location you selected. They may include filenames, source and output paths, hashes, watermark text or image filename, and job settings. You control and delete those files; the publisher does not receive or retain a copy through the conversion program.
6. Sale, advertising, sharing, and model training
The publisher and the bundled local conversion program do not sell your personal data, use your files or settings for advertising, or use them to train AI models. The conversion program does not share your media with third parties.
This commitment describes the publisher and the bundled conversion program. Capafy, an Agent Client, an AI provider, or another service may process information under its own privacy terms, including any choices it offers about retention or model improvement.
7. Website access
This website may record a random session identifier, page view, selected locale, referral source, and explicitly selected website actions for basic first-party service measurement. It does not receive the media you process with Watermark Studio. Cloudflare may also process standard network and security logs when serving this page. See the general RabbitSubtitle privacy notice for the website’s broader disclosure.
Website measurement records are kept only while reasonably needed to understand use, maintain reliability and security, and resolve incidents; the retention period is determined by those purposes rather than a fixed schedule. Capafy retains marketplace data under its own terms.
8. Your choices and security
You choose the input files, watermark settings, output directory, Agent Client, and AI provider. Keep sensitive source and output files in appropriately protected folders, review the normalized job and QA report, and delete local files you no longer need. Backups, operating-system logs, and third-party client caches are controlled by you or those services, not by Watermark Studio.
9. Contact and requests
Because the conversion program normally sends no media to the publisher, access and deletion are generally performed by managing your own local files. If you contact the publisher for support, your address, message, and any material you choose to provide are sent through Google Gmail and handled under Google’s applicable privacy terms. The publisher keeps support correspondence only while needed to answer and follow up on the request, protect legal rights, or meet a legal obligation.
For privacy questions, contact the address below. Where applicable, you may ask the publisher to access, correct, delete, restrict, or provide a portable copy of personal data the publisher holds, object to processing, or withdraw consent. You may also complain to the competent data-protection authority. These rights may be limited by applicable law. Do not attach sensitive source media, passwords, tokens, or API keys to a support message.