Privacy notice

Written from what this website and this app actually do, rather than from a template. Four different things are involved, and they are kept apart on purpose.

Version 1.6Updated 2026-09-28Approved

The four things, kept separate

Most privacy policies blur these together. They are genuinely different, and which one you are asking about changes the answer completely.

  1. This website. Marketing pages, the download, sign-up and your account page. Very little data, all of it listed below.
  2. Your Margo Account, held by Margo’s account service. Your email address, name, age, whether the Margo team has approved you to use Margo (and a beta application, if you sent one earlier in the beta), your sign-in methods, the devices signed in to it, and the records synced between your Mac and your iPhone so the iPhone can show them and add to them. Your billing status too, once there is one. Deleting the account deletes these.
  3. The Margo app on your Mac. This is where your actual life is: goals, journal, observations, commitments. It is in files in your home directory. The part your iPhone needs is synced through your Margo Account (item 2); the rest stays on the Mac.
  4. Margo’s AI service and Anthropic. To reason, the app sends the relevant parts of your records to Margo’s hosted AI service, which passes them to Anthropic’s Claude and returns the answer. Margo pays for this during the beta; you do not use an AI account of your own.
“Local-first” does not mean “nothing leaves your device”. Your records live on your Mac, the part your iPhone needs is synced through your Margo Account, and the reasoning about them happens at Anthropic, through Margo’s AI service. All three are true, and printing only the first would be misleading.

Who we are

Margo LLC, c/o Northwest Registered Agent LLC, 8401 Mayland Dr Ste A, Richmond, VA 23294-4648, USA. Postal address (letters): c/o Northwest Registered Agent LLC, 8401 Mayland Dr Ste A, Richmond, VA 23294-4648, USA. Phone: +1 434 291 4342. Privacy contact: help@margo.global.

What this website collects

No analytics, no advertising pixels, no session replay, no chat widget, no social buttons, no third-party fonts. That is a decision, not an accident. What remains:

Data this website processes
WhatWhyWho else sees itKept for
margo_privacyRemembers your privacy choices and the version of the notice they were made against, so we do not ask again on every visit.Margo (us)6 months, or until you clear it from the privacy-choices panel.
margo-themeRemembers whether you chose the light or dark appearance.Margo (us)Until you clear your browser storage. It never reaches our server.
margo_formA one-time value for your visit. It lets us tell the difference between a form you submitted yourself and one another website submitted in your name.Margo (us)Cleared when you close the browser.
Cloudflare TurnstileProtects the beta application form, Margo Account sign-up and the password-reset request from automated abuse, when it is switched on.Cloudflare, Inc.The token is discarded after verification; Cloudflare service retention applies to its own processing.
margo_langRemembers which language you chose, so a neutral URL answers in it and you are not asked again on every visit.Margo (us)6 months, or until you choose the other language.
Cloudflare Workers — request handling and logsServing the site. Every page is rendered on demand by a Cloudflare Worker, so every request reaches Cloudflare. Logs are also how an outage or an attack is diagnosed at all.Cloudflare, Inc.Cloudflare keeps its own logs under its terms. We have request tracing switched on for our account, and a sample of those traces is kept there. We keep them for a few days, Cloudflare’s short default.
Cloudflare Workers Rate LimitingLimiting how often the same visitor can submit a form or start a checkout. It counts requests at each Cloudflare location separately, so it is not one worldwide limit.Cloudflare, Inc.Counters expire within the limiter window — 60 seconds.
help@margo.globalAnswering support questions, privacy requests and security reports. One shared mailbox.Google Workspace (Google LLC)12 months after the conversation ends; privacy requests and our answers, 3 years.
margo_sessionKeeps you signed in to your Margo account on this website. Only set when you sign in; never readable by page script.Margo (us)Up to 30 days, or until you sign out, sign out everywhere, or change your password.
margo_deviceLets your account’s device list show this browser once, so you can sign it out from any device. Only set when you sign in.Margo (us)About 13 months, or until you clear your cookies.
margo_oauth, margo_pendingCarries one “Continue with Google / Apple” attempt across the hop to Google or Apple and back, and — for someone new — the sign-in they returned, until the account is created.Margo (us)margo_oauth: 10 minutes at most. margo_pending: 30 minutes at most, while you finish creating the account.
margo_mac_pairRemembers which Margo for Mac is waiting to be connected, from the moment it opens this website until you click Connect. Only set when Margo for Mac opens the connect page.Margo (us)14 days at most; removed as soon as the Mac is connected.
Margo account serviceSigning in, creating an account and managing it. This website forwards what you submit to Margo’s account service and shows you the answer.Margo (us)Held by the account service for as long as your account exists.
Sign in with GoogleSigning in with your Google account instead of a password. Only when you choose “Continue with Google”.GoogleGoogle’s own terms apply to its processing.
Sign in with AppleSigning in with your Apple Account instead of a password. Only when you choose “Continue with Apple”.AppleApple’s own terms apply to its processing.
Stripe Checkout and Customer PortalTaking a subscription payment and letting you manage or cancel it. Loaded only when you start a purchase — never on an ordinary page.StripeHeld by Stripe under Stripe’s terms; our copy of the subscription record lasts as long as the subscription plus the period we are required to keep billing records.
Beta applicationTo review the application and, if it is approved, email you that you can create your Margo Account.Margo’s account service holds it; the approval email is sent from help@margo.global through Google Workspace (Google LLC). No marketing recipient.Until the beta ends, or earlier if you ask us to delete it at help@margo.global.
Waitlist addressTo send you one message when Margo is available.Nobody. It is not shared or sold.Until we send it, or until you ask us to remove it.
Support messagesTo answer you.Nobody outside the people answering.As long as the conversation is live, plus our own records period.
Subscription recordTo take payment, prove entitlement, and issue receipts.Stripe, as our payment processor.For the subscription, plus the period billing records must legally be kept.

“No analytics” is not the same as “no personal data”. Serving a web page means our host sees your IP address and what you asked for, and that is personal data even though we never use it to recognise you. It is in the table above for that reason.

  • Performing a contract (Art. 6(1)(b) GDPR). Running your Margo Account, syncing your devices, answering the AI requests you make in the app, taking payment, giving you the app, and answering support about it.
  • Legitimate interests (Art. 6(1)(f) GDPR). Deciding by hand who may use Margo during the beta, contacting testers about taking part, keeping the site up, and defending it from abuse through rate limiting and security controls.
  • Consent (Art. 6(1)(a) GDPR). Optional marketing email, connecting Gmail and Photos in the app, and — when they are available — location, Screen Time and Apple Health, and any optional technology — of which there are currently none. Consent is separate, unchecked, specific, versioned, timestamped, and withdrawable if it is introduced. The beta form does not enroll applicants in marketing.
  • Explicit consent for health data (Art. 9(2)(a) GDPR). Health data is a special category of personal data. When Apple Health is available, Margo will read it only after you give explicit consent — Margo’s own explanation, then Apple’s permission screen for each data type — and only for the purposes described above. You can withdraw it at any time in Health → Sharing → Apps → Margo; what was already read is then no longer used, and you can delete it with the account.
  • Legal obligation (Art. 6(1)(c) GDPR). Keeping billing records as long as tax law requires.

Where a record of your acknowledgment is kept (an earlier beta application, a sign-up), it holds the version of this notice and the time; it is not a marketing consent.

Access to the beta

Anyone can download Margo and create a Margo Account. Before Margo works for you, the Margo team approves you by hand in its own admin tool; until then the app waits. To decide, the team sees your account’s name and email address and the name of the Mac you signed in on. Approval is used only to let you use Margo and, if we write to you about it, that email is sent from help@margo.global through Google Workspace. Approving you does not start a subscription or sign you up for marketing.

Earlier in the beta, testers applied through a form on this website (first name, last name, email address and an optional answer about why they wanted to test Margo). The form is no longer offered. Applications already received are kept by Margo’s account service until the beta ends, or deleted earlier if you ask at help@margo.global.

Recipients and processors

  • Cloudflare. Cloudflare Workers/OpenNext serves the website; Cloudflare rate limiting, and Turnstile when it is switched on, help protect the form. Cloudflare also receives request metadata needed to deliver and secure the site.
  • Google Workspace (Google LLC). Margo’s email provider. It sends Margo’s automated account and beta emails from help@margo.global — email verification, welcome, password reset and password-changed notices, new-device alerts, the reminder to finish setup on your Mac, account-deletion confirmations, subscription and integration notices, and beta approval emails — and it hosts the help@margo.global mailbox for support, privacy requests and security reports. It receives your email address and the content of those messages. It is kept separate from marketing tools, and it is separate from connecting your own Google account in the app. Google processes this data under the Google Workspace data processing terms Margo has accepted.
  • Margo’s account service. Operated by Margo at account.margo.global, on a server run by the operator in the United States. It holds your Margo Account, whether you are approved to use Margo, any earlier beta application, and the records synced for your iPhone.
  • Anthropic. Receives the text of AI requests from Margo’s AI service and returns the answer, as Margo’s AI provider.
  • ElevenLabs (Eleven Labs, Inc., USA), or OpenAI (OpenAI, L.L.C., USA). When Margo speaks an answer aloud, the text of that answer is sent to Margo’s text-to-speech provider — currently ElevenLabs; Margo’s account service can instead use OpenAI’s text-to-speech — which returns the audio. The audio is streamed to your device and not stored by Margo. What you say is not sent to them.
  • Apple. Turns your speech into text when you talk to Margo on the Mac and the language cannot be recognised on the Mac itself (see above).
  • Google and analytics providers. The website does not use Google Analytics, Google advertising, or another analytics provider. Apart from Google Workspace sending and receiving Margo’s email (above), the only Google processing is signing in with Google and the Google sources you choose to connect in the app — Calendar, Tasks and Gmail — whose data goes from Google to your device.

What the apps do on your Mac and iPhone

Margo reads what you tell it and the sources you connect. Every source is optional and off until you connect it, and each can be disconnected in Settings.

  • Calendar and tasks. Google Calendar and Google Tasks with read-only access, or the calendars and reminders on your Mac.
  • Gmail (Mac and iPhone). If you connect Gmail, Margo reads the headers and Gmail’s short preview of your recent mail — never the full body — on your device, to find what needs a reply, what you are waiting on and deadlines that are mentioned. It stores these on your device. When you ask about your mail, a short summary of relevant threads is part of the request to Margo’s AI service (below). Margo can also write an email for you, but it is sent only when you press Send on that draft. Gmail access is granted by you on Google’s own consent screen and can be revoked there at any time.
  • Places (iPhone) — when this is available. It is not in the current app, which contains no location code at all. When it is, it will be off until you allow location: Margo will take one location fix while the app is open (at most every ten minutes, and when you save a place), match it to the places you named, and then discard it. It will never track location in the background, and will store only which named place you arrived at or left. To disconnect: iOS Settings → Privacy & Security → Location Services → Margo.
  • Screen Time (iPhone) — when this is available. It is not in the current app, which carries no Family Controls entitlement. When it is, it will be off until you allow it: your usage will be shown in Apple’s Screen Time report inside the app. That report runs in a sealed Apple extension that cannot send data anywhere; Margo does not read it back.
  • Photos (iPhone). If you take or pick a photo in Margo — of handwritten notes, say — Margo keeps it in its own folder on your iPhone and reads the text in it on the device, with Apple’s Vision. You confirm or edit that text; only the confirmed text is saved as a capture, synced through your Margo Account and, like your other records, can be part of a request to Margo’s AI service. The photo itself never leaves your iPhone: no image pixels are uploaded, synced or sent to any AI. When reading your photo library becomes available, it will be off until you allow photo access, and Margo will read only each item’s date, time and location, and its kind (photo or video) — never the image — to help reconstruct your days and the places you went. What it derives will stay on your iPhone, the part your Mac needs will be synced through your Margo Account, and a short summary can be part of an AI request when it is relevant. To disconnect: iOS Settings → Privacy & Security → Photos (and Camera) → Margo.
  • Apple Health (iPhone) — when this is available. It is not in the current app. When it is, it will be off until you connect it: Margo will read only the Health data types you allow on Apple’s own permission screen — for example workouts, steps, sleep, heart rate and body measurements — when the app opens and refreshes, and use them for your goals, its readings and its recommendations. It will never write to Health. What it reads will be stored on your iPhone; the summaries your Mac needs (a day’s total, say) will be synced through your Margo Account; and when it is relevant to what you ask, a short summary of those readings can be part of a request to Margo’s AI service and Anthropic. As Apple’s HealthKit rules require, Health data is never used for advertising or marketing, never sold, and not shared with third parties except as needed to provide the feature — the AI request described below. To disconnect: Health app → Sharing → Apps → Margo (or iOS Settings → Health → Data Access & Devices → Margo), and turn every category off.
  • Voice (Mac). When you talk to Margo, speech is turned into text by Apple’s speech recognition — on your Mac where the language supports it, otherwise by Apple’s service. Margo’s spoken answers are produced from the text of the answer by a text-to-speech provider (below).

The App Store privacy label. The iPhone app’s label lists every category of data Margo may collect, including optional sources — some of them not available yet — so that it stays true as they arrive. Each optional source is off until you turn it on, and none of it is used for tracking or advertising.

What Margo derives from those — its readings, your goals, your commitments, its own record of being wrong — is written to a database and a journal in your home directory. The part your iPhone needs is synced through your Margo Account; the rest stays on the Mac.

Margo also forms views about your habits and your follow-through, and uses them to make recommendations. That is automated processing about you, done on your own machine, with the evidence shown and every conclusion correctable. It does not make any decision with a legal or similarly significant effect on you.

What goes to Margo’s AI service and Anthropic

To reason, Margo assembles the relevant parts of your records into a request and sends it to Margo’s hosted AI service, which passes it to Anthropic’s Claude (Haiku) under Margo’s agreement with Anthropic and returns the answer. The AI service keeps a usage record — model, token counts, cost, app version and a digest of the request — so each tester stays within the beta budget; it does not keep the text. What Anthropic retains, and for how long, is set by its commercial terms with Margo.

When they are relevant to what you ask, a request can include the text you confirmed from a photo and — once those sources are available and you have connected them — a short summary of your Apple Health readings and of your photos’ dates and places. Image pixels are never part of a request.

We do not claim zero retention and we do not claim no model training. We are not in a position to know either way.

International transfers

Margo is operated from the United States, and Margo’s account service runs there. The providers that receive your data — Cloudflare, Google (Google Workspace, and the Google sources you connect), Anthropic, and ElevenLabs or OpenAI for spoken answers — are U.S. companies, and Margo has accepted each one’s data processing terms. Transfers from the EU/EEA rely on the EU-U.S. Data Privacy Framework where the recipient is certified under it, and otherwise on the EU standard contractual clauses in that provider’s data processing terms.

How long we keep it

  • Your Margo Account and the records synced for your iPhone: until you delete the account (Account → Delete account), when the account service removes them.
  • Whether you were approved, and any earlier beta application: as long as your account exists, and applications without an account until the beta ends — or earlier if you ask.
  • Support conversations in help@margo.global: 12 months after the conversation ends.
  • Privacy requests and our answers: 3 years, so we can show a request was handled.
  • AI usage records (model, token counts, cost, app version, a digest of the request — not its text): 12 months, to keep each tester within the beta budget and to spot abuse.
  • The log of emails the account service sent (to whom, which kind, when, whether it was delivered): 90 days.
  • Spoken answers: the audio is streamed to your device and not stored by Margo.
  • Website request logs: Cloudflare’s short-lived logs, kept for a few days.
  • Billing records, once there are any: as long as tax law requires.
  • Photos you take or pick in Margo: in Margo’s folder on your iPhone until you delete the capture or the app. The text you confirmed from them is kept like your other records.
  • Apple Health readings and photo-library details, once available: on your iPhone until you delete them, disconnect the source or delete the app; the part synced through your Margo Account until you delete the account.
  • What is on your Mac and iPhone: until you delete it or the app; it is on your device, not with us.

Your rights

Depending on where you live, you may be able to ask us to:

  • tell you what we hold about you, and give you a copy;
  • correct it;
  • delete it;
  • restrict or object to what we do with it;
  • receive it in a portable form;
  • opt out of any sale or sharing, or of targeted advertising — we do none of these anyway;
  • withdraw consent, at any time, as easily as you gave it.

Use the data requests page. For access, correction and deletion we will email you to confirm the address is yours before acting, because otherwise anyone could ask for your data by typing your address. For an opt-out we simply act, and we will not make you create an account to say no.

A request we have received is a request we have received. It is not a completed deletion, and we will tell you when it is actually done, along with anything we are legally required to keep.

Complaints

Please come to us first. You can also complain to your national data protection authority.

Children

Margo is only for people aged 18 and over — the beta application and the Margo Account alike. Sign-up is refused below that age, and an application or sign-up that fails the age check is not stored. If you believe someone under 18 has given us data, write to help@margo.global and we will delete it.

Security

We use HTTPS, security headers including a restrictive content security policy, server-side validation, same-origin and CSRF protections, rate limiting, Turnstile when beta collection is enabled, parameterized D1 queries, secrets kept on the server, restricted operator review, deletion tooling, and errors that do not repeat back what you typed. We do not put applicant PII in application logs and are not certified against any standard. How to report something.

Changes

This notice is versioned. We publish the current version and effective date on this page. If we materially change what we do with your data, we will update the page and, where the legal basis is consent, ask again before the changed optional processing starts. For a material change affecting an existing beta applicant, we will use the contact details we hold where appropriate and legally permitted.

Questions about this page: contact us. To exercise a right over your data: data requests.