Marginly Privacy Policy

Effective Date: August 29, 2026

Marginly Inc. ("Marginly," "we," "us," or "our") respects your privacy and is strongly committed to keeping secure any information we obtain from you or about you. This Privacy Policy describes our practices with respect to personal information we collect from or about you when you access Marginly and its associated services (collectively, the "Services").

1. Personal Information We Collect

We collect information that alone or in combination with other information in our possession could be used to identify you ("Personal Information") as follows:

  • Account Data: When you register for a Marginly account, we collect your full name, email address, company name, and authentication credentials (such as Google OAuth tokens).
  • Financial Data: When you process payments or manage quotes via the Services, our third-party payment processors (e.g., Stripe) collect your billing information. Marginly does not directly store full credit card numbers.
  • Client Data: Information you input about your clients (names, emails, project details) is securely stored to provide the scope management services. You represent that you have the authority to provide this data to us.
  • Automated Usage Data: We automatically collect diagnostic data, log files, IP addresses, browser types, and timestamp metrics when you interact with the Services.

2. How We Use Your Information

We use your Personal Information for the following core operational purposes:

  • To provide, administer, and maintain the Marginly platform and its core functionalities.
  • To securely process OAuth logins via Google and maintain session integrity via Supabase.
  • To generate AI-driven project insights using your supplied AI API keys (via the "Bring Your Own Key" architecture). Your keys are encrypted at rest and never shared with unauthorized third parties.
  • To detect, investigate, and prevent fraudulent transactions, unauthorized access, and other illegal activities.
  • To comply with our legal and regulatory obligations.

3. Data Security and Infrastructure

Marginly implements commercially reasonable, enterprise-grade technical, administrative, and organizational measures designed to protect your Personal Information.

Our database infrastructure is powered by Supabase and PostgreSQL. All data is encrypted at rest using AES-256 encryption, and all data in transit is encrypted using TLS 1.3. We utilize strict Row Level Security (RLS) policies to ensure that your workspace data is cryptographically isolated from all other users on the platform. Despite these measures, no internet transmission is ever completely secure, and we cannot guarantee absolute security.

4. Third-Party Integrations and AI Subprocessors

Marginly connects with third-party APIs (e.g., Google Calendar, OpenAI, Anthropic) to provide enhanced functionality.

Artificial Intelligence Data Usage: When you utilize the "Connect AI" functionality using your own API keys, Marginly transmits the specific text you wish to analyze to the respective AI provider (e.g., OpenAI). By using these integrations, you agree to the respective privacy policies of those providers. Marginly strictly configures these API requests to opt-out of data training where supported by the provider, ensuring your project data is not used to train public foundational models.

5. Your Data Rights (GDPR & CCPA compliance)

Depending on your jurisdiction, including the European Economic Area (EEA) and California, you may possess the following statutory rights:

  • Right to Access: You may request a comprehensive export of all Personal Information Marginly holds about you.
  • Right to Rectification: You may correct inaccurate or incomplete data directly through the Marginly Dashboard settings.
  • Right to Erasure ("Right to be Forgotten"): You may permanently delete your account and all associated workspace data at any time via the "Danger Zone" in your Settings panel. This action executes a hard deletion in our primary databases.
  • Right to Opt-Out of Sale: Marginly does not, and will never, sell your Personal Information to third parties.

6. Data Retention

We retain your Personal Information for only as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law. Upon account deletion, your data is immediately purged from our active databases, though encrypted residual copies may temporarily persist in automated disaster recovery backups for up to 30 days before being permanently destroyed.

7. Contact Information

If you have any questions, concerns, or requests regarding this Privacy Policy or your Personal Information, please contact our Data Protection Officer at:

Marginly Legal Department
Email: legal@marginly.com