/ privacy
What we do with what you say
Margin talks to real people mid-session, inside a product they didn’t sign up to be interviewed by. So the rule is simple: we collect the smallest amount of data needed to ask one question, keep it for the shortest reasonable time, never re-identify anyone, and honor one click of “no thanks” forever. Here’s how that actually works.
If you just got asked a question
You’re seeing Margin because a product you use installed it. Here’s what we promise you, in plain English:
- We ask sparingly — only when your behavior suggests something's worth asking about, never on a loop. The same question won't come back for about two weeks, and across all of Margin you'll see at most one ask every couple of days.
- You can dismiss with Esc or a click. Nothing happens, and nothing changes.
- You can opt out forever in one click — no email, no account. We remember it for this site.
- We won't ask for your email, name, role, or company. If you put one in a reply anyway, we store the reply but never surface it without flagging it first.
- A real person reads your reply. We use AI to group answers — never to identify you.
- We don't track you across sites. Your session here has nothing to do with your session anywhere else.
- We don't record your IP, your screen, your scroll, your mouse, or the pages you visit. Margin isn't a session-replay product.
- Your replies aren't sold, shared, or used to train models. Full stop.
How long we keep things
A daily job does the deleting, so this isn’t a someday-TODO — it’s enforced:
- Raw replies — 90 days, then deleted.
- “A question was shown here” records (anonymous, no reply text) — 90 days.
- End-user session tokens — 30 days.
And the override: opt out, and we delete your session and your raw replies — right then, not in 90 days. A reply already grouped into a Finding keeps its quote there, de-identified: the session that tied it to you is gone, so it’s no longer linked to you.
Feedback you paste or upload yourself — reviews, support notes, a churn export — runs through the same pipeline as a widget reply, and we keep it under the same retention. By pasting it you confirm you’re allowed to share it with us.
What we can and can’t catch
Before a reply is stored, it runs through a screen that redacts the personal details it can recognize by shape — an email address, a card number (checked so “I clicked 4 times then 4 more” doesn’t trip it), a phone number, an SSN, an IBAN, an IP address. They’re replaced with [redacted] before they ever land in the database.
We won’t oversell it: this is best-effort, not a guarantee. A pattern-matcher can’t catch a name, a postal address, or every phone format on earth. So we say best-effort, and we never surface a reply we flagged without marking it as flagged.
Who else touches the data
A handful of services do specific jobs. Here’s each one — what we send, and why:
- Anthropic (Claude) — reply text and grouping context — no session tokens, no identifiers. grouping your replies into a Finding and writing it in a human voice.
- Voyage AI — reply text. turning replies into vectors so we can group them by meaning.
- Neon — everything above, stored. our Postgres database.
- Vercel — ordinary web-request data. hosting the app and the widget.
- Resend — your email address, plus the Finding we email you, which includes verbatim quotes from your users. sign-in links, the 'your Finding is ready' note, and the weekly digest.
- Linear — a Finding's title, its suggested direction, and the verbatim quotes. Only to the team you connect, and only when you send one there.
- Stripe — billing details, and only when an account owner pays. taking payment.
- Sentry — error traces and the user-agent string. catching our own bugs before they bite you.
What never leaves to anyone: your session token, your IP, your opt-out record, and any account credentials.
Margin’s own pages
Our marketing site and the workstation where a product team reads its Findings use a product-analytics tool (Pendo) so we can see what’s confusing and fix it. The widget we ship onto someone else’s product carries none of it — we check that on every release. Pendo never rides along to watch your users for us.
If your team needs a DPA
We don’t have a signable data-processing agreement yet. We’re pre-revenue, and a real one needs a lawyer rather than a generated template we’d be bluffing with. If your team needs one before you can install Margin, email hello@askmargin.com and we’ll work it out with you.
Questions about any of this? Same address — hello@askmargin.com. A real person reads those too.