Privacy Policy
Last updated: July 30, 2026
1. Who we are
Margot LLC (“Margot,” “we,” “us”) provides a platform that helps creators manage brand partnerships, affiliate links, discount codes, and related deadlines. This Privacy Policy explains what personal information we collect, how we use it, and the choices you have. It applies to our website, waitlist, and the Margot application.
2. Information we collect
Information you give us.When you join our waitlist you provide your email address. When you create an account and use the app, you provide your email address, a name or display name, and optionally your time zone and follower range. You also provide the brands, deals, deliverables, terms, notes, affiliate links, discount codes, payments, and promotional windows you choose to store. Free-text notes may contain whatever you put in them. If you send us feedback, we collect your message, the page you were on, and your browser’s user-agent string.
Information from a connected email account. Connecting a mailbox is optional and Margot works without it. If you connect one, we store message metadata — sender name and address, reply-to address, subject line, date, message and thread identifiers, and email authentication results. We do not retain the body of your emails and we do not store attachments; bodies are fetched into memory for processing and discarded. We do store the structured results of that analysis: the brand involved, compensation terms, deliverables, deadlines, links, and discount codes. Those records can include short verbatim fragments from a message, limited to roughly 140 characters, where one is needed to show you why something was flagged. Section 3 covers Google data specifically.
Information about other people. Because Margot reads brand-partnership email, we necessarily process personal information about people who are not Margot users — most often brand representatives and agency contacts who write to you. This includes their names, email addresses, the domains they write from, and the subject lines they wrote. We keep an index linking senders to brands so we can recognize the same counterpart next time. We use this only to provide the service to you, the account holder. We do not sell it, use it for advertising, or build cross-user profiles from it, and it is erased on the schedule in section 8.
Information collected automatically. When you visit our site or use the app, we and our analytics and monitoring providers collect usage data such as pages viewed, actions taken (for example, copying a link), device and browser type, and approximate location derived from your IP address. When the service encounters an error, we also collect diagnostic data such as error messages, stack traces, and the device and app state at the time — which may include a recording of your interactions with the app — to help us diagnose and fix it. Section 7 covers what loads before you consent.
Push notification tokens. If you enable notifications, we store the subscription token needed to deliver them.
3. Google user data
This section describes our use of data from Google APIs and takes precedence over any general statement elsewhere in this policy.
What we request. At sign-in, your basic profile and email address. If you connect a mailbox, read-only access to Gmail.
Read-only. We only read. Margot never sends, drafts into, deletes, or modifies anything in your Gmail account. Where Margot helps you reply, it prepares text and opens your own mail client — you send it yourself.
How we use it. Solely to provide features you can see in the app: detecting brand offers, extracting deal terms and deadlines, capturing affiliate links and discount codes, and tracking where a negotiation stands. We retain metadata and the derived structured records described in section 2 — not message bodies, not attachments — and erase them on the schedule in section 8.
Limited Use.Margot’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
No AI training. We do not use Google user data to develop, improve, or train generalized artificial intelligence or machine learning models. Where we use AI to process your email (section 5), it is solely to produce features you can see, and we instruct our providers not to retain the data or train on it.
Disconnecting. You can disconnect a mailbox at any time from your settings, which withdraws our access at Google and stops further processing. Deleting your account does the same.
4. How we use your information
- To operate, maintain, and improve the Margot service.
- To detect brand partnership activity in connected mail and turn it into records you can act on, and to flag contract terms worth a second look.
- To manage the waitlist and tell you when your spot opens or your account is ready.
- Service emails. To send you messages needed to run your account or your waitlist entry, such as sign-in links, security notices, receipts, and changes to our terms. These are part of the service, so you cannot opt out of them while you have an account or a waitlist entry.
- Marketing emails. To tell you about Margot itself: product news, new features, launch announcements, and occasional tips on getting more from the service. We measure how these perform: our email provider records when you open one and which links you click, which also reveals your IP address, approximate location, and the app you read mail in. We use this to judge what is worth sending and to stop sending what is not. We do not use it to build a profile of you or to target advertising. The service emails above carry no such measurement. You can opt out of marketing emails at any time without losing access to anything, using the route in section 9.
- To send push notifications, where you have enabled them, for the categories you have turned on.
- To understand how the service is used so we can improve it, measure performance, and prioritize features.
- To keep the service secure and available: detecting and preventing abuse, fraud, and automated sign-up attempts, and diagnosing technical problems.
- To comply with our legal obligations.
5. How we use AI
Margot uses AI models to read brand-partnership email and turn it into structured records. This section explains exactly how.
What is processed. The prepared text of relevant messages, with formatting stripped and length capped, along with the sender, subject, and date. If you paste a list of brands or deals during onboarding or a bulk import, that text is processed the same way.
Which providers. Model calls are routed through Vercel AI Gateway to Google, Anthropic, and OpenAI. Different models handle classification, extraction, and quality checks.
Retention and training. We enable zero data retention on every model call, which instructs providers not to keep the content after generating a response, and we do not permit its use for training. We monitor quality, cost, and speed through an observability provider that is configured not to record message content.
Accuracy.AI output can be wrong or incomplete. Margot’s extractions, term flags, and suggestions are informational aids, not professional advice, and you should verify anything that matters. See our Terms of Service.
6. Service providers
We share personal information only with vendors that process it on our behalf to provide the service, under contractual obligations to protect it. These include:
- Vercel — application hosting, scheduled jobs, routing of AI model calls, and request rate limiting to protect the service from abuse.
- Supabase — database, authentication, and file storage.
- Google — sign-in, and the Gmail APIs we use to read the messages you authorize us to process.
- Anthropic, OpenAI, and Google — AI processing used to extract deal, deadline, link, and discount-code details from connected email content.
- Langfuse — AI observability. Configured not to record message content; it receives operational measurements such as cost, speed, and quality scores.
- PostHog — product analytics and feature management.
- Sentry — error and performance monitoring.
- Resend — delivering account and product emails, including sign-in emails, and storing the email address of anyone who joins our waitlist or asks for product news, which is the record we send those emails from. In marketing emails only, Resend also measures opens and link clicks for us, using a tracking image and links routed through their domain. That reveals your IP address and email app to them. Sign-in and other service emails contain neither.
- Linear — triaging the feedback you submit.
- Cloudflare — the bot check on our sign-up and sign-in pages, and on the waitlist form on our home page, which establishes that a request came from a person rather than a script. Your browser contacts Cloudflare directly, which reveals your IP address and basic browser information to them. It runs only on those pages, and we receive only a pass or fail result.
- Logo providers — supplying brand logos. Your browser requests these directly, which reveals your IP address and which brands you track to that provider.
- Browser push services — operated by Google, Apple, and Mozilla, to deliver notifications you have enabled.
We may also disclose information if required by law, to protect our rights or the safety of others, or in connection with a merger or acquisition. We do not sell your personal information, and we do not share it for cross-context behavioral advertising.
7. Cookies and analytics
We use cookies and similar technologies to keep you signed in, remember your preferences, and understand how the service is used. Essential cookies — the ones that keep you signed in — are always active because the service cannot work without them.
On our public pages, analytics and diagnostics are not loaded until you consent. You can change your choice at any time using . You can also control cookies through your browser settings; disabling essential cookies may affect how the service works.
The bot check described in section 6 is an exception, and loads on our sign-up and sign-in pages whichever choice you make. It is a security measure rather than analytics: without it we cannot tell a person from a script, and those two pages are the ones worth attacking.
8. Data retention and deletion
We keep personal information for as long as your account is active or as needed to provide the service, and afterward only as required to comply with our legal obligations, resolve disputes, and enforce our agreements.
When you delete something in the app. Deleting a brand, deal, or other record removes it from the app immediately and schedules it for permanent deletion. Most records are erased from our database 30 days later. That window exists so we can help you recover something you deleted by mistake.
Information from a connected email account. Processed messages and the sender details we derive from them are erased 7 days after you delete them, rather than 30. Disconnecting an email account also erases the messages we had already processed from it, on the same 7 day schedule.
When you delete your account. Everything we hold in our own systems is deleted straight away, with no waiting period. We withdraw the access we were granted to any connected email account, remove you from our waitlist and marketing list, and cancel work queued on your behalf.
Records held by our providers.The providers in section 6 hold records that reference you — analytics events, email delivery logs, error diagnostics. We do not currently instruct them to delete those records when you close your account; they are kept and removed according to each provider’s own retention practices, which in some cases means they are kept indefinitely. We do not use them to identify or contact you, and the identifiers in them are not usable to reconstruct your account.
Waitlist emails are retained until you ask us to remove them, or until you delete your account.
9. Your rights and choices
You can do the following yourself, at any time, from your settings: export your data as a machine-readable archive, delete your account permanently, disconnect a connected email account, and manage your notification preferences.
Depending on where you live, you may also have the right to access, correct, delete, or export your personal information, to object to or restrict certain processing, and to withdraw consent. Some places also give you the right not to be treated differently for exercising these rights. To exercise a right that is not available in the app, or to withdraw from the waitlist, email us at the address below.
Marketing emails. To stop receiving them, email us at the address below and we will take you off the list. Opting out does not affect your account or your place on the waitlist, and we will still send the service emails described in section 4. Opting out also ends the open and click measurement described in section 4, because it happens only in marketing emails. If you would rather keep receiving them without the open measurement, most email apps can be set to block remote images, which prevents it.
You can manage push notifications from within the app or your device settings.
10. Security
We use technical and organizational measures designed to protect your information, including encryption in transit and at rest, database-level access controls that isolate each account’s data, and encryption of the access tokens for any email account you connect. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
11. Children
Margot is not directed to children. You must be at least 16 years old to use it, and we do not knowingly collect personal information from anyone younger. If you believe a child has provided us information, please contact us so we can delete it.
12. International users
We are based in the United States and process information there, including with the providers listed in section 6. If you access Margot from outside the United States, you understand your information may be transferred to and processed in the United States, which may have different data-protection rules than your country.
13. Features we are building
We would rather tell you where this is going than surprise you later. None of the following is active today, and where a new use needs it, we will update this policy and ask you to agree before it begins.
- Contract handling — reading partnership agreements you receive as attachments or links, to pull out terms and flag unfavorable ones. This would mean storing document content, which we do not do today.
- Invoicing and payments — generating invoices from your deal terms and tracking what has been collected, which would involve a payment processor.
- Deal value estimates— estimating what a partnership is worth to you, using your own history and any platform statistics you provide. A later phase may use anonymized aggregates across creators to improve benchmarks; this would never expose any individual creator’s rates.
- Affiliate network connections — importing earnings automatically from affiliate platforms.
- Referrals — inviting other creators to Margot.
14. Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date above. When a change is material, we will ask you to agree to the updated policy the next time you use Margot, before you carry on. We keep a record of which version you agreed to and when, and you can see it in your data export.
15. Contact us
Questions about this policy or your information? Email us at hello@hellomargot.ai.