Trust

Trust and security

Last updated October 3, 2026

On this page

Before you put a team's work somewhere, you should know where it is kept, who can see it, how it is protected and how to reach a person. This page answers each of those plainly, including the things we do not do yet. An automated test checks its facts against our code and configuration every time either changes.

At a glance

  • Where: one server in Ashburn, Virginia, files and backups in Cloudflare R2, and a copy on each of your devices.
  • Who sees it: the members of each workspace. Team admins cannot open anyone's personal workspace or read their assistant conversations.
  • Protection: HTTPS everywhere, row-level security in the database, two-factor sign-in a Team can require, and a security log nobody can edit.
  • Backups: nightly, kept 30 days, and restored as a test every week.
  • Help: [email protected]. On Team, a person replies within one business day.
  • Not yet: SAML, SOC 2, a choice of data location or an uptime guarantee. We do not encrypt the database disks ourselves.

Who runs The Margin

The Margin is made by MELIURA LTD, a company registered in England and Wales under number 17456307. You can check that on the public register. The contact page has every way to reach us.

How we know: The UK company register.

Where your data lives

  • The database. Your account and your workspaces are stored in PostgreSQL on one server we rent from Hetzner in Ashburn, Virginia, in the United States. The app, sync and Margin Intelligence (the built-in AI assistant) run on the same server.
  • Files. Attachments, pictures and kept voice recordings are stored in Cloudflare R2, Cloudflare's file storage, and so are the nightly database backups. We did not pick a region for it, so Cloudflare places it in its own data centers; it is not limited to one country.
  • Your devices. The app keeps a real database on each device you use and writes there first, then syncs when it has a connection. Signing out of the phone app deletes the phone's copy.
  • If the server fails. There is one server, not a cluster. If it goes down, the app keeps working on your devices from the copy they hold, and we rebuild the server from the most recent nightly backup. We have not set a recovery-time target.
  • Server only. Two things are built on the server and live only there: what the Mind (the part of Margin Intelligence that learns from your notes) has learned, and your conversations with Margin Intelligence.

How we know: Hetzner's own record of where our server is (its us-east region, Ashburn data center), and the storage address in our live configuration.

Encryption

  • In transit. Every connection to themarginapp.com is encrypted with TLS (HTTPS). Browsers are also told never to fall back to plain HTTP with us, on any subdomain, for a year at a time.
  • Encrypted before they are stored. Two-factor secrets and Canva connection tokens are encrypted with AES-256-GCM, using a key that is not kept in the database. Two-factor recovery codes are stored only as keyed hashes, so the database alone cannot produce one.
  • The Vault. The Vault is a part of your workspace you lock with your own passphrase. The Mind's copy of anything in it is encrypted with AES-256-GCM under a key made from that passphrase, and we store neither. The items themselves still sync to the devices of everyone in the workspace and are only hidden on screen while the Vault is locked. So the Vault keeps things out of sight and away from the assistant; it is not a lock against the people you share a workspace with. Something truly private belongs in your personal workspace. This is not end-to-end encryption, and we do not claim it is.
  • What we do not encrypt ourselves. The database disks and the backup files are not encrypted by us at the disk or file level.

How we know: The header our server sends (Strict-Transport-Security: max-age=31536000; includeSubDomains; preload), and the encryption code for two-factor secrets, Canva tokens and the Vault.

Backups

  • Nightly. At 02:30 UTC every night the whole database is copied and uploaded to Cloudflare R2. Each copy is kept for 30 days, on the server and in R2, so something you delete is gone from every backup within 30 days.
  • Tested every week. Every Sunday at 03:30 UTC the newest backup is restored into a fresh, throwaway database and compared with production: its tables, its security rules and its row counts.
  • Watched. If a night's backup goes missing or fails, or the weekly restore fails, our monitoring sends us an alert.

How we know: The scheduled jobs that run the backup and the restore test, and the alert rules in our monitoring.

How access is enforced

  • Your devices get only what is yours. Sync sends a device the workspaces its person belongs to and the boards they were added to. Nothing else reaches it.
  • The database checks too. Every change a device sends is written under row-level security, rules inside the database that refuse a write into a workspace the writer is not part of. That is a second check, behind the one in our server code.
  • People. Nobody at The Margin reads your content unless you share it with us for support, or security or the law requires it. It is not used to train AI models and it is not sold.

How we know: Our sync rules and the database's row-level security rules, both of which ship with the code.

What Team admins can and cannot see

A team workspace is a shared room. Everyone in it sees its notes, whiteboards, checklists, habits and expenses, apart from the private items listed below. Boards are the exception: each board has its own members, and only they see it in the app.

Owners and admins can

  • See every member, their role, every guest and who can open which board.
  • See how many AI actions (requests to Margin Intelligence) each member has used, and set a monthly cap per person.
  • Read and export the security log.
  • Export everything in the team workspace, including boards they are not a member of. So an admin can read every board in the team workspace that way, even one they cannot open in the app.

Owners and admins cannot

  • Open a member's personal workspace, or any workspace they do not belong to. Each workspace is separate, and its data only goes to its own members.
  • Read a member's conversations with Margin Intelligence. Those are shown only to the person who had them.
  • See expenses or income a member marks private. Those sync only to the person who recorded them.
  • See the focus sessions of a member who turned off sharing their focus status.

How we know: Our sync rules for workspaces, private money and focus sessions, and the way conversations with Margin Intelligence are looked up, always for the person asking.

Signing in

  • No passwords. You sign in with a link we email you, with Google or with Apple. There is no Margin password to steal or reuse.
  • Two-factor sign-in. Anyone can add an authenticator app and get one-time recovery codes. Once it is on, every sign-in stops for a code, whichever way you signed in.
  • Team rules. Owners and admins can require two-factor for every member. A member without it keeps their seat but cannot open the workspace until they turn it on. A Team can also require members to sign in with Google on the team's own domain.

How we know: The sign-in options in our code, and the database changes that added two-factor and the team domain rule.

The Team security log

  • What it records. Sign-ins and two-factor changes; role, seat, invitation, removal, guest and board-access changes; the sign-in rule, AI caps, shares and exports.
  • Tamper-evident. The database stamps every entry with a fingerprint (a hash) of the entry before it, so editing, deleting or reordering a past entry breaks the chain at that point. Every export carries the latest fingerprint, so an owner can keep it and check later.
  • Append-only. The database refuses to change or delete an entry, for everyone, the owner included.
  • Addresses are cut short. An entry keeps only the first part of a network address: enough to notice a sign-in from somewhere new, not enough to locate a person.
  • Who sees it. Owners and admins can view it and export it as CSV or JSON. It is kept for the life of the workspace and deleted with it.

How we know: The database rules that build the chain and refuse changes, deletions and wipes.

Companies that handle your data

These are the outside companies that receive some of your data, what each does for us and what it receives. We do not sell your data, and no advertising or analytics company receives any of it.

Hetzner
Rents us the server that runs the database, the app, sync and Margin Intelligence, in Ashburn, Virginia.
Receives Everything stored on our server: your account and your workspaces.
Cloudflare
Sits in front of themarginapp.com, stores attachments and the nightly backups in R2, and receives mail sent to our two addresses.
Receives Your traffic to the site as it passes through, the files you attach, the database backups, and any email you send us.
AI model providers reached through OpenRouter
Run Margin Intelligence, voice transcription and the Mind's background reading. OpenRouter is the one gateway, and every request carries two routing rules, so it only goes to hosts whose terms forbid training on it and that keep none of it.
Receives The content a request needs to be answered, at the moment you use an AI feature. The privacy policy names every model and host.
Tavily
Web search for Margin Intelligence.
Receives The search words, when the assistant searches the web for you. Not your workspace content.
Stripe
Takes payments for paid plans.
Receives Your name, email and payment details. Card numbers go to Stripe and never reach us.
Resend
Sends our email: sign-in links, invitations and notices.
Receives Your email address and the email we are sending you.
Sentry
Collects crash reports.
Receives The error, the page it happened on and your account identifier. On the web a short replay of the clicks is included, with all text masked and all media blocked.
Google
Sign in with Google, Google Calendar and Sheets if you connect them, Android notifications, and the mailbox our two addresses deliver to.
Receives Your Google profile and email when you sign in with Google, the calendar events and spreadsheets you choose to sync, your phone's push address, and any email you send us.
Apple
Sign in with Apple and iPhone notifications.
Receives The name and email Apple shares when you sign in with Apple, and your phone's push address.
Canva
The design hub, only if you connect a Canva account.
Receives The requests needed to list and import your designs. Your Canva tokens are stored encrypted.
Discord
Our community server, only if you link a Discord account to join it.
Receives Your Discord user id, to confirm you joined.

How we know: The services in our live configuration. A test fails if a provider's key appears there that this list does not name.

What we do not offer yet

  • SAML single sign-on. It is not part of Team. It is planned for a later enterprise plan. Today a Team controls sign-in with Google on its own domain plus required two-factor.
  • A choice of data location. Everything is stored as described above, in the United States.
  • Certifications. We do not hold SOC 2 or ISO 27001 certification.
  • An uptime guarantee or a recovery-time target. The status page shows how we are doing right now, but there is no uptime commitment with service credits.

How we know: What the product and our configuration do today.

Getting your data out

  • Any member, any plan. Settings, Data exports a whole workspace as one JSON file, on every plan including Free. It is built in your browser from the copy on your device, so no server can refuse it.
  • Pieces. A note exports as Markdown, expenses as CSV, the Mind as JSON or Markdown, and a whiteboard as an image or a file that imports back.
  • The whole team. Owners and admins can export everything in the team workspace.
  • Leaving. An owner can delete a workspace, and anyone can delete their account from Settings, Data. The privacy policy says what that removes and when.

How we know: The export in Settings, Data, and the Your data page in our docs.

Getting help

  • Email. [email protected] for anything about the app, your account or billing. A person reads every message.
  • In the app. Report a problem, from the menu under your picture or from Settings, Help and reports. You can follow what happened to each report there.
  • Status. themarginapp.com/status shows whether anything is down right now, and it opens even when you cannot sign in.
  • Community. Our Discord is for talking with other people who use The Margin. It is not a support line.

How fast we reply

  • Team: a person replies within one business day.
  • Every other plan: we aim to reply within two business days.

Business days are Monday to Friday. These are targets we hold ourselves to, not a contract: there are no service credits, no phone line and no 24/7 cover.

How we know: The two addresses our mail service accepts, and the report form in Settings, Help and reports.

Reporting a security problem

If you think you have found a vulnerability, or that your data was exposed, write to [email protected] and include a way to reach you. It reaches a person who can act on it. We will not take action against anyone reporting in good faith. Anything that affects the service is posted on the status page.

How we know: The two addresses our mail service accepts.