Legal

Privacy Policy

Last updated October 8, 2026

On this page

MELIURA LTD (“we,” “us,” or “our”) operates The Margin, the web application at themarginapp.com (the “Service”). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.

For the purposes of the UK GDPR, the data controller is MELIURA LTD, a company registered in England and Wales under number 17456307, whose registered office is at 128 City Road, London, EC1V 2NX, United Kingdom. Questions about your data, or a request to see, correct or delete it, go to privacy@themarginapp.com.

1. Information We Collect

1.1 Account Information

When you create an account, we collect your email address. If you sign in with Google, we also receive your name and profile photo as provided by Google OAuth. If you sign in with Apple, we receive the name and email address Apple shares with us, which may be a private relay address Apple creates for you. We never see or store your Google or Apple password.

1.2 User Content

We store the content you create within the Service, including boards, cards, notes, checklists, habits, expenses, focus sessions, and any comments or file attachments. This data is necessary to provide the Service.

1.3 Usage Data

We collect minimal usage data to maintain and improve the Service, including device type, browser type, and pages visited. We do not use third-party analytics trackers. We do not sell or share analytics data with advertisers.

1.4 Local Data

The Service uses local storage (IndexedDB / SQLite via WASM) in your browser for offline functionality. This data resides entirely on your device and is not transmitted to our servers except during sync operations.

2. How We Use Your Information

We use the information we collect to:

  • Provide, operate, and maintain the Service
  • Authenticate your identity and manage your account
  • Sync your data across devices in real time
  • Process AI features (Margin Intelligence) when you explicitly invoke them
  • Connect to third-party integrations you authorize (Google Sheets, Google Calendar)
  • Send transactional emails (for example, magic link sign-in links and notices about your account)
  • Respond to support requests
  • Detect, prevent, and address technical issues and abuse

3. AI Features & Data Processing

Margin Intelligence and the other AI features run on third-party language models, named in full under Third-Party Integrations below. When you use these features:

  • Only the content you explicitly reference or query is processed to fulfil your request
  • We use semantic embeddings stored in our own database for context retrieval
  • Your data is not used to train any models
  • AI features are optional and can be disabled

4. Third-Party Integrations

When you connect third-party services (Google Sheets, Google Calendar), we access only the scopes you explicitly authorize via OAuth. Sign-in requests only your basic profile and email; the Google Sheets and Calendar scopes are requested separately, on demand, only when you choose to connect that specific feature. We keep the refresh token Google gives us in our database so the sync can keep running; only our servers read it, and it is not separately encrypted. You can revoke access at any time from your Google account settings or from The Margin's settings page.

Canva: if you connect a Canva account, we ask Canva for read-only access to your designs. We use it to list and search your designs while you choose one, to have Canva render the pages of a design you bring in, to export a PDF when you ask for one, and to open a design in Canva when you want to edit it. We never create, change or delete anything in your Canva account. For each design you bring in, we keep its title, Canva's link to it, the text on its pages and the rendered page images, stored privately with your workspace. All of it is deleted when you delete the design, the workspace or your account. PDFs are not stored; you download them from Canva's own link. Your Canva tokens are encrypted before they are stored. Disconnecting Canva in Settings, Integrations deletes them and ends our access at Canva, and so does deleting your account. You can also remove The Margin from your Canva account settings.

Google API Services Limited Use

The Margin's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

  • We use Google Sheets and Calendar data only to provide and improve the sync features you explicitly enable (two-way board ↔ spreadsheet sync; pushing and pulling calendar events).
  • We do not transfer this data to others except as needed to provide those features, for security, or to comply with law.
  • We do not use Google user data for advertising, and no humans read it except with your explicit consent, for security, or where required by law.
  • We never use Google user data (raw, aggregated, or derived) to train, and we never transfer it to any third-party service to train or improve, generalized or foundational machine-learning or artificial-intelligence models. AI features that process your content do so through third-party AI provider APIs on paid tiers whose terms do not permit training on submitted data.
  • The AI providers we use, in full: there is one, OpenRouter, an API gateway we use on standard pay-as-you-go API terms. Every request to it carries the routing flag data_collection: deny, which limits routing to hosts whose data policy prohibits training on inputs, and zdr: true, which limits it to endpoints classified as zero data retention. Prompt logging is off in our account. Three models are used: DeepSeek V4 Flash for the assistant (served by SiliconFlow, DeepInfra, Fireworks or Novita; never by DeepSeek's own API, which the flag excludes), DeepSeek V4 Flash again as a background model that summarises your own content for recall, and OpenAI text-embedding-3-large for retrieval embeddings, served by Azure OpenAI under the same two flags, and Google Gemini Flash-Lite to turn voice recordings into text, served by Google under the same two flags. The embeddings are stored in our own database. No other provider receives your data, and we run no self-hosted or offline model. This list is exhaustive; if it changes, this page changes with it.
  • Voice: when you dictate, the words appear first from your own device's speech recognition, which stays on the device. When you let go of the mic, the recording is sent once, through the route above, to be turned into cleaned-up text, and is then discarded. We keep the text you save, never the audio. The names in your personal dictionary are sent with a recording as spelling hints. You can keep dictation entirely on your device in Settings, Voice.

Webhook and Zapier integrations send event data only to endpoints you configure. Webhook payloads are signed with HMAC-SHA256 so you can verify authenticity.

5. Data Storage & Security

  • Data is stored in PostgreSQL on one server we rent from Hetzner in Ashburn, Virginia, in the United States. Attachments and the nightly database backups are stored in Cloudflare R2
  • All connections are encrypted in transit with TLS (HTTPS)
  • The database is backed up every night and each copy is kept for 30 days. Cloudflare R2 encrypts the copies it stores at rest. We add no encryption of our own to the database disks or the backup files
  • Two-factor secrets and Canva connection tokens are encrypted with AES-256-GCM before they are stored. Google connection tokens are not separately encrypted
  • We use Cloudflare for DDoS protection and CDN

6. Data Sharing

We do not sell, rent, or trade your personal information. We share data only in the following circumstances:

  • With your consent: When you share a board or workspace with other users
  • Service providers: the companies that run parts of the service for us (Hetzner, Cloudflare, AI model providers reached through OpenRouter, Tavily, Stripe, Resend, Sentry, Google, Apple, Canva, Discord, GitHub), each receiving only what its job needs. Our trust page says what each one receives
  • Legal requirements: When required by law, regulation, or legal process
  • Safety: To protect the rights, property, or safety of our users or the public

Link previews

When you save a web address in a capture or a note, our server requests that page once to build its preview card (the site's name, the page's title, a short description and a small picture). This is the one case where something you saved causes a request to a site you did not connect: the site receives the address itself and a request from our server. It does not receive your IP address, your account, any cookie or any other content. We store the title, description and a small re-encoded copy of the picture with your workspace; your device never loads anything from the site. The stored preview, including the address, is visible to every member of that workspace, which is why only items the whole workspace can already see cause one: links in chat messages and on board cards are never requested, and neither are links inside a PIN-locked note, in the Vault, or hidden from memory. Addresses that look like single-use links (sign-in, confirmation, password reset, invitation or unsubscribe links) are never requested either. A preview is not shared between workspaces, and one that nobody has looked at for a week after it expires is deleted. You can turn previews off for your account in Settings, and links still open.

7. Data Retention

We retain your data for as long as your account is active. If you delete your account:

  • Your account information is deleted within 30 days
  • Your user content is deleted within 30 days
  • Backups containing your data expire within 30 days
  • Local data on your device remains until you clear your browser storage

8. Your Rights

Depending on your jurisdiction (including GDPR and CCPA), you may have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your data
  • Export your data in a portable format
  • Object to or restrict processing of your data
  • Withdraw consent for optional processing (e.g., AI features)

To exercise these rights, email us at privacy@themarginapp.com.

9. Cookies & Local Storage

Five things, and here is all of them:

  • Session cookie: Authenticates your login session (httpOnly, secure, SameSite=Lax)
  • Theme preference: Stored in localStorage to prevent flash of unstyled content
  • Offline database: IndexedDB stores your synced data for offline access
  • First-touch cookie (margin_first_touch): If you arrive from a link we tagged or from another site, this records which one, for 30 days. It holds no identifier of any kind, so two people who followed the same link get identical cookies and it cannot tell you apart or follow you between visits. It is set by our own server, read only by our own server, and deleted the moment you create an account. Arrive by typing the address and nothing is stored at all. If your browser sends Global Privacy Control or Do Not Track, it is never set.
  • Try-it sandbox (margin_sandbox): If you open Try it now, the sandbox lives in this browser: a cookie holding the sandbox's random id, a database in the browser's storage, and a one-word label for where you came from, such as "reddit" or "direct". Nothing you make there is sent to us. We count a few steps as plain numbers per day under that label: a sandbox opened, the first thing made in it, the offer to keep it shown, Keep pressed, a sandbox kept. The counts hold no identifier and cannot be joined to anything. If you keep the sandbox, the label moves into your new account the way the first-touch cookie would. Global Privacy Control or Do Not Track turns off the label and the counts; the sandbox itself still works. The sandbox clears itself after two days.

Once, when you first set up your account, we also ask how you found The Margin. Answering is optional, there is a Skip beside every way forward, and we never ask again whichever you choose. What we keep is the channel you pick from a short list, plus a line of your own if you choose “a friend” or “somewhere else”. It is used for one thing: knowing which channels are worth our time. It is not linked to anything outside your account and it is never shared.

We do not use advertising cookies, tracking pixels, or fingerprinting. No third-party analytics script runs on this site: every script the page loads is served from themarginapp.com, and our Content-Security-Policy allows no analytics host, so your browser would refuse one even if somebody added it.

Two things do watch the software itself. We count events (requests, errors, sync failures) on our own servers, and those counters have no user attached. And we use Sentry for crash reports, which can include a session replay: a recording of which controls were used in what order when something broke. Replays are masked, so what they show is the shape of what happened and never the words you wrote, and crash reports reach Sentry through our own domain rather than as a request from your browser to theirs.

10. Children's Privacy

The Service is not directed to children under 13. We do not knowingly collect information from children under 13. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.

11. International Transfers

Our server is in Ashburn, Virginia, in the United States, so your data is stored and processed in the United States. Files and backups in Cloudflare R2 are placed by Cloudflare in its own data centers and are not limited to one country. If you are located outside the United States, your data will be transferred subject to appropriate safeguards as required by applicable law.

12. The Phone App (iOS and Android)

Everything above applies to The Margin's phone app as well, and where this policy says “the Service” it includes that app. This section is the list of what is different about a phone, and it is the whole list.

12.1 A copy of your data on the device

The app keeps a real SQLite database inside its own sandbox on the phone and reads and writes to that first, which is what lets it work with no signal. Our sync service streams the rows your account has access to into that database and sends your changes back up when a connection returns. It holds the same content described in section 1.2 and nothing further. Signing out deletes it, along with any PINs this device remembered, and removing the app takes it with it.

12.2 Your sign-in token

Signing in happens on themarginapp.com in the phone's own browser, so no password is ever typed into the app. What the app keeps afterwards is an access token and a refresh token, stored in the iOS Keychain or the Android Keystore rather than in ordinary app storage. The same place holds any PIN you ask the phone to remember for a sealed note.

12.3 Notifications, and the device token

Nothing is sent to your phone until you turn notifications on. The moment you do, the app asks the operating system for this device's push token (Apple's APNs on iOS, Google's FCM on Android) and sends it to our server so a reminder can reach you. It is an address for one installation on one handset. Turn notifications off, or sign out, and we delete the record of it.

12.4 Camera and photo library

The app asks for the camera or your photo library only at the moment you attach a picture to a note, a card or a chat message, and the system asks you first. The picture is uploaded at its original quality to our own storage, and the app reads no EXIF metadata from it, so the camera model, the timestamp and any GPS coordinates your phone wrote into the file do not travel with it. Pictures only: the app cannot pick a video, an audio file or a document.

12.5 Crash reports

The app sends crash reports and a fraction of its performance traces to Sentry. There is no session replay on the phone, unlike the web app described in section 9, and the reports go directly from the device to Sentry's United States ingest rather than through our own domain. Each event carries your account identifier and no other personal detail: no email, no name, no photo. Before an event leaves the device, authorization headers, OAuth codes, access and refresh tokens, passwords and PINs are stripped out of it. The trail attached to a report records which screens were opened and which requests to our own API were made; it does not carry what you wrote.

12.6 What the app does not do

  • No analytics SDK. There is no product analytics library in the app at all.
  • No advertising identifier and no tracking. The app does not read Apple's IDFA or the Android advertising ID, shows no App Tracking Transparency prompt because it has nothing to ask for, carries no attribution or ad SDK, and sends nothing to a data broker. Nothing you do in it is linked to you across other companies' apps or sites.
  • No location. The app declares no location permission, contains no location library, and cannot read one from a photo either, per section 12.4.
  • No contacts. The app never reads your address book. Finding a person searches the people who already share a workspace or a connection with you.
  • No in-app purchase. Nothing is sold inside the app and no billing library is installed. Plans are managed on themarginapp.com, so no payment detail of any kind reaches the phone.
  • Searches stay on the phone. Recent search terms are kept in the app's own storage and are never sent to us.

12.7 Getting your data out, and deleting the account

The app exports what Margin has learned about you as a file from the phone itself, and no plan gates it. Deleting your account starts in the app's Settings and finishes on themarginapp.com in the phone's browser, for the same reason section 12.2 gives about sign-in: account-level acts belong on a surface that holds a real session. What deletion removes, and when, is section 7 above and is the same on both.

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting a notice within the Service or sending an email. Your continued use of the Service after changes take effect constitutes acceptance of the revised policy.

14. Contact Us

If you have questions about this Privacy Policy, contact us at:

The Margin
Email: privacy@themarginapp.com