Privacy Policy

Effective Date: July 1, 2026

1. Introduction

Welcome to DMCA Bunny. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Chrome browser extension, iOS mobile app, and associated website services at dmcabunny.com (collectively, the "Service"). We are committed to protecting your privacy and ensuring you remain in control of your data.

The same DMCA Bunny account may be used across the extension and the iOS app. Data associated with your account is stored on our servers unless this policy states otherwise.

2. Information We Collect

To provide our Service, we collect the following types of information:

  • Google Account Information: When you authenticate using Google Sign-In (in the Chrome extension or iOS app), we request access to your basic profile information (name and profile picture) and email address (userinfo.email and userinfo.profile) to create and manage your DMCA Bunny account.
  • Sign in with Apple Information: When you authenticate using Sign in with Apple on the iOS app, we receive your Apple user identifier and, on your first sign-in only, your name and email address. Apple may provide a private relay email address (for example, @privaterelay.appleid.com). We use this information solely to create and manage your DMCA Bunny account.
  • Profile and Takedown Data: We store the sender profiles, letter templates, contact details, creator URLs, and platform settings you configure in the Service. We also store the infringing URLs, abuse-contact lookups, saved targets, and takedown send history (recipient emails, timestamps, and URLs sent) associated with your account on our servers.
  • Content You Submit: We collect the URLs, images, and text you actively choose to save or process through the Service, including via the extension's context menus or keyboard shortcuts, domain and image search queries, and Cloudflare abuse submissions when you use that feature.
  • Device and Local Storage: The Chrome extension stores some templates and profile details locally on your device (chrome.storage.local) to persist your work between sessions. The iOS app stores authentication tokens and preferences locally on your device (for example, in the iOS Keychain or app storage). Server-synced data is described above and is not limited to local storage.
  • Authentication Tokens: We securely store OAuth and API session tokens required to keep you signed in and to communicate with Google APIs on your behalf when you send takedown notices.
  • Subscription and Trial Data: We store your trial usage (start date and actions used), subscription status, and payment-provider records. For Apple In-App Purchases, we store transaction identifiers (such as original_transaction_id), product ID, expiry date, and subscription status. We do not receive or store your full payment card number — billing for Apple purchases is handled entirely by Apple.
  • Guest Session Data: Before you sign in, the iOS app may assign a guest session identifier to enforce usage limits and store temporary targets. This data is not linked to an account until you sign in.

3. How We Use Your Information (Google Workspace APIs)

DMCA Bunny requires access to the Gmail API (https://www.googleapis.com/auth/gmail.send) strictly to fulfill the core function of the Service: sending DMCA takedown notices on your behalf.

  • Sending Emails: We only use this permission when you explicitly initiate a send within the extension or iOS app. The Service drafts the takedown notice based on your templates and sends it directly via your connected Gmail account to the selected abuse contacts.
  • No Inbox Access: DMCA Bunny does not request, nor do we have, permission to read, modify, or delete any existing emails in your inbox. We cannot see your personal correspondence.

4. Google API Services Limited Use Disclosure

DMCA Bunny's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

  • We do not use Google API data to develop, improve, or train generalized AI and/or machine learning models.
  • We only use the data to provide or improve user-facing features that are prominent in the requesting application's user interface.
  • We do not transfer Google API data to third parties unless doing so is necessary to provide or improve these user-facing features, comply with applicable law, or as part of a merger, acquisition, or sale of assets.

5. Subscriptions and In-App Purchases

DMCA Bunny offers paid subscriptions. On iOS, subscriptions are purchased through Apple In-App Purchase (StoreKit). On the website and Chrome extension, subscriptions may be purchased through Stripe. These are separate billing systems — an Apple subscription and a Stripe subscription are managed independently.

  • Restore Purchases: If you previously subscribed through the App Store and reinstall the iOS app or sign in on a new device, you can use Restore Purchases in the app. This sends your App Store transaction records to our servers so we can re-link your active subscription to your signed-in account.
  • Auto-Renewal: Apple subscriptions automatically renew unless you cancel at least 24 hours before the end of the current billing period. You can manage or cancel an Apple subscription at any time in your device's Settings → Apple ID → Subscriptions.
  • Billing and Refunds: Payment processing for Apple In-App Purchases is handled by Apple. We do not have access to your payment card details. Refund requests for Apple purchases must be submitted to Apple. Stripe subscribers can manage billing through the Stripe Customer Portal linked from the Service.

Apple's terms apply to App Store purchases. See Apple's Licensed Application End User License Agreement. Our Terms of Service also describe subscription use of the Service.

6. Data Sharing and Disclosure

We do not sell, rent, or trade your personal information or API data to third parties. We share information only as needed to operate the Service:

  • Our servers (dmcabunny.com/api) — to process abuse-contact lookups, manage subscriptions, sync profiles and takedown history, and maintain your account.
  • Apple — for Sign in with Apple authentication, In-App Purchase validation, App Store Server Notifications (renewals, cancellations, refunds), and token revocation when you delete your account.
  • Google — for Google Sign-In, Gmail send functionality, and optional image search when you use that feature.
  • Stripe — for website and extension subscription billing when you choose that payment method.
  • Cloudflare — when you submit a Cloudflare abuse report through the Service, we transmit the domain and URLs you provide on your behalf.
  • Public RDAP/WHOIS sources — to resolve domain registrar and hosting abuse contacts from the domains you look up.

We may also disclose information if required by law, to protect our rights, or as part of a merger, acquisition, or sale of assets.

7. Account Deletion and Data Removal

You may delete your DMCA Bunny account at any time from within the iOS app or Chrome extension (Settings → Delete Account). When you confirm deletion, we permanently remove your account and associated data from our servers, including:

  • All sender profiles, templates, and profile settings
  • Saved targets and infringing URLs
  • Takedown send history (recipients, dates, and URLs)
  • Sign-in records (Google and Apple)
  • Trial usage data
  • Our server-side subscription records (Apple and Stripe)
  • All active API session tokens

Deletion takes effect promptly upon a successful delete request. If you signed in with Apple, we also revoke our Apple authentication token as part of the deletion process.

Important — Apple subscriptions: Deleting your DMCA Bunny account does not cancel an active App Store subscription or stop billing by Apple. You must separately cancel your subscription under Settings → Apple ID → Subscriptions on your device to avoid future charges.

Guest users: If you have not signed in, you can clear locally stored data using the Clear my data option in the iOS app, which removes guest session data from our servers associated with your device.

If you are unable to delete your account through the app, contact us at contact@dmcabunny.com and we will process your request.

8. Data Security and Retention

We use industry-standard encryption (HTTPS) for all data transmitted between the Service, our servers, and third-party APIs. Authentication tokens are stored securely.

We retain your account data for as long as your account is active. When you delete your account, we remove the data described in Section 7 without undue delay. We may retain limited information where required by law (for example, billing records we are legally obligated to keep) or in anonymized, aggregated form that cannot identify you.

You may revoke the Service's access to your Google account at any time via your Google Account Security settings, which will disable the ability to send emails through Gmail on your behalf.

9. Children's Privacy

DMCA Bunny is not intended for users under 18 years of age. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us at contact@dmcabunny.com and we will delete it.

10. Contact Us

If you have questions or concerns regarding this Privacy Policy, please contact us at: contact@dmcabunny.com