Your data

Where it lives, every way to get it out, what the Vault hides and what it does not, and what deleting something deletes.

Checked against the running product on 6 min readMarkdown

On this page

Where it lives#

On your device first, in a real database. It syncs to our servers, and that copy is what reaches your other devices and survives a lost laptop. A local-first app that loses its server keeps working; a cloud app that loses its server is a blank screen.

Two things live only on the server, because they are built there: what the Mind has learned, and your conversations with the assistant.

Getting it out#

WhatWhereWhat you get
A noteThe note's menu, Export as MarkdownOne Markdown file, with its folder named at the top and [[wikilinks]] left as you wrote them
The whole workspaceSettings→Data, Export JSONOne JSON file: boards with their columns, cards, labels and comments, plus notes, checklists, habits and their entries, expenses and their categories, focus sessions, and the household: chores, points, pocket money, savings goals, the family ledger, income, money owed and its payments, recipes, the meal plan, the family calendar, the shopping lists and their items, the pantry, the rewards shelf and every reward asked for, expense splits and settle-ups, budgets, the houses and House Cup seasons, who is who in the family (roles, nicknames and faces), and a child shared with another household. Note folders, whiteboards, card templates and saved views come along as rows
What the Mind knowsSettings→Your BrainJSON to import into another Margin, or Markdown to read
A whiteboardThe canvas menuExport image... for a picture, or Save to... for an .excalidraw file that imports back
RecipesRecipes, the menu beside the search box, Export all recipesOne JSON file that reads straight back into this workspace or another, with a note inside explaining the format
ExpensesExport on the Expenses pageCSV
A chat threadThe thread's info sheet, Download the transcriptPlain text anyone can read, on Margin or not
A whole Team workspace (owners and admins)Team, the Security tab, Download the zipA zip of JSON and CSV with every board in the workspace, including ones you are not on, its notes, whiteboards and checklists, the members, guests and invitations, the workspace's rules and its security log. See Team hub

Export is on every plan, including Free and after a trial ends, and it is deliberately never going to be gated. Everything above except the Mind's file is built in your browser from the copy already on your device, so there is no server that could refuse it. The Team export is the other exception: it is built on our servers, because your device only holds the boards you are on. See Plans and limits.

A board synced to Google Sheets is the other way out: it already lives in a spreadsheet you control. See Integrations.

The Vault#

The Vault is a private part of your workspace, sealed with a passphrase you choose (at least 6 characters) in Settings→Your Brain. Put a note, card, board, checklist or whiteboard in it with Move to Vault. Each person has their own Vault in each workspace.

  • While it is locked, sealed items are hidden on screen for everyone in the workspace, you included, and the assistant cannot see them. Other members see "A private item" in its place, sealed in another member's Vault, and have no way to open it on screen. They are never retrieved, so they cannot be paraphrased into an answer about something nearby.
  • Connected AI (any assistant or agent you connect over MCP) never sees a sealed item, locked or unlocked. Asked for one by id, it is told the item was not found.
  • Unlocking lasts fifteen minutes from the moment you unlock. Working does not extend it, and closing the tab or signing out does not end it early; Lock now does.
  • Offline, you can unlock the screen to read your sealed items. The assistant's side stays sealed until you unlock again with a connection.

What is encrypted, exactly: only the copy of each sealed item that Margin's memory keeps, with a key made from your passphrase, and we store neither the passphrase nor that key. The item itself is not encrypted. It still syncs to the devices of everyone in the workspace like anything else, and the Vault hides it on screen while it is locked. This is not end-to-end encryption, and we do not claim it is.

Hide from memory and private weaving#

The lighter controls. Hide from memory, on a note's menu, keeps the note in your notes and your own search but never lets the Mind embed or recall it. Use it for things that are not secret but are nobody's business, the machine's included.

Weave privately goes further in the other direction: the Mind still learns from the item, but keeps it quiet in suggestions and recall, and out of every memory file and pack. See The Mind for all four controls side by side.

Deleting#

  • A note or card is removed on your device and everywhere it has synced. On its next background pass, within about fifteen minutes, the Mind drops it too, along with the connections and mentions built from it.
  • A memory is deleted from Settings→Your Brain at once.
  • A workspace is deleted by its owner from Settings→Workspace, Delete workspace. It takes the boards, notes, whiteboards, checklists, habits, expenses and its Mind with it, and anyone else in it is told. You cannot delete your only workspace.
  • Your account is deleted from Settings→Data, under Danger zone.

Privacy, plainly#

Your content is not training data, and it is not sold. Nobody at The Margin reads it unless you share something with us for support, or security or the law requires it.

When you use the assistant, the content it needs is sent to a model provider to answer that request, and only to hosts whose terms forbid training on it and that keep none of it. The Vault and Hide from memory are how you decide what never goes. Full detail, including every provider, is on the privacy page.

Where the servers are, what is encrypted, how backups are tested, which companies handle your data and what a Team admin can and cannot see are all on one page: Trust and security.

When you save a web address in a capture or a note, Margin's server reads that page once to make its preview card. The site sees a request from Margin, not from your device, but it does learn that someone saved its address. The stored preview is visible to everyone in the workspace, so links in chat messages and on board cards never cause one, and neither do links in a PIN-locked note, in the Vault or hidden from memory, or single-use links such as a sign-in or password reset link. One switch in Settings turns previews off for your account. See Links and previews.