/ privacy

What we do with what you say

Margin talks to real people mid-session, inside a product they didn’t sign up to be interviewed by. So the rule is simple: we collect the smallest amount of data needed to ask one question, keep it for the shortest reasonable time, never re-identify anyone, and honor one click of “no thanks” forever. Here’s how that actually works.

If you just got asked a question

You’re seeing Margin because a product you use installed it. Here’s what we promise you, in plain English:

  1. We ask sparingly — only when your behavior suggests something's worth asking about, never on a loop. The same question won't come back for about two weeks, and across all of Margin you'll see at most one ask every couple of days.
  2. You can dismiss with Esc or a click. Nothing happens, and nothing changes.
  3. You can opt out forever in one click — no email, no account. We remember it for this site.
  4. We won't ask for your email, name, role, or company. If you put one in a reply anyway, we store the reply but never surface it without flagging it first.
  5. A real person reads your reply. We use AI to group answers — never to identify you.
  6. We don't track you across sites. Your session here has nothing to do with your session anywhere else.
  7. We don't record your IP, your screen, your scroll, your mouse, or the pages you visit. Margin isn't a session-replay product.
  8. Your replies aren't sold, shared, or used to train models. Full stop.

How long we keep things

A daily job does the deleting, so this isn’t a someday-TODO — it’s enforced:

  • Raw replies — 90 days, then deleted.
  • “A question was shown here” records (anonymous, no reply text) — 90 days.
  • End-user session tokens — 30 days.

And the override: opt out, and we delete your session and your raw replies — right then, not in 90 days. A reply already grouped into a Finding keeps its quote there, de-identified: the session that tied it to you is gone, so it’s no longer linked to you.

Feedback you paste or upload yourself — reviews, support notes, a churn export — runs through the same pipeline as a widget reply, and we keep it under the same retention. By pasting it you confirm you’re allowed to share it with us.

What we can and can’t catch

Before a reply is stored, it runs through a screen that redacts the personal details it can recognize by shape — an email address, a card number (checked so “I clicked 4 times then 4 more” doesn’t trip it), a phone number, an SSN, an IBAN, an IP address. They’re replaced with [redacted] before they ever land in the database.

We won’t oversell it: this is best-effort, not a guarantee. A pattern-matcher can’t catch a name, a postal address, or every phone format on earth. So we say best-effort, and we never surface a reply we flagged without marking it as flagged.

Who else touches the data

A handful of services do specific jobs. Here’s each one — what we send, and why:

  • Anthropic (Claude) reply text and grouping context — no session tokens, no identifiers. grouping your replies into a Finding and writing it in a human voice.
  • Voyage AI reply text. turning replies into vectors so we can group them by meaning.
  • Neon everything above, stored. our Postgres database.
  • Vercel ordinary web-request data. hosting the app and the widget.
  • Resend your email address, plus the Finding we email you, which includes verbatim quotes from your users. sign-in links, the 'your Finding is ready' note, and the weekly digest.
  • Linear a Finding's title, its suggested direction, and the verbatim quotes. Only to the team you connect, and only when you send one there.
  • Stripe billing details, and only when an account owner pays. taking payment.
  • Sentry error traces and the user-agent string. catching our own bugs before they bite you.

What never leaves to anyone: your session token, your IP, your opt-out record, and any account credentials.

Margin’s own pages

Our marketing site and the workstation where a product team reads its Findings use a product-analytics tool (Pendo) so we can see what’s confusing and fix it. The widget we ship onto someone else’s product carries none of it — we check that on every release. Pendo never rides along to watch your users for us.

If your team needs a DPA

We don’t have a signable data-processing agreement yet. We’re pre-revenue, and a real one needs a lawyer rather than a generated template we’d be bluffing with. If your team needs one before you can install Margin, email hello@askmargin.com and we’ll work it out with you.

Questions about any of this? Same address — hello@askmargin.com. A real person reads those too.