1. Who we are
“Marked”, “we”, “us” and “our” mean the Marked service and its operator. Marked is based in India. Our privacy contact is [email protected]. We will update this policy if the operating entity or contact details change.
This policy applies to marked.run, app.marked.run, our API, MCP endpoint, dashboard, account and support interactions. A customer agreement or data-processing addendum controls if it conflicts with this policy.
We apply applicable Indian law, including the Digital Personal Data Protection Act, 2023 where it applies, and other applicable data-protection laws for people in other jurisdictions. The law applicable to a particular request depends on the person, service and processing involved.
2. What we collect
| Category | Examples | Why |
|---|---|---|
| Account | Email, name, profile, OAuth provider ID, sign-in and verification records | Create and secure your account |
| Workspace | Workspace name, plan, API-key hash, permissions and usage totals | Provide access, billing records and quotas |
| Request content | Prompts, questions, tool calls, arguments, retrieved context, files, outputs and feedback you submit | Processed to answer your request; raw content is not retained by default |
| Technical | IP address, user agent, timestamps, URLs, status codes, request IDs, cookie identifiers and security events | Reliability, abuse prevention, diagnostics and security |
| Support | Messages, attachments and information you choose to provide | Answer and resolve your request |
We collect information from you, your workspace administrator, your browser or client, authentication providers you choose, and service providers that help us operate the service. We do not buy personal information or use data brokers to build consumer profiles.
3. Prompts and AI content
When you call an API or MCP tool, we process the request in memory to return the requested result. By default, we do not retain prompt text, output text, request bodies, query values or uploaded files. We may retain limited metadata such as the endpoint or tool, dataset or query category, parameter names, response status, latency and date.
This metadata helps us deliver the service, detect abuse, protect security, troubleshoot failures, measure quality and prioritize improvements. It is not used to reconstruct your prompt, sold, used for cross-context behavioural advertising or used to train a general-purpose AI model. We do not disclose customer prompts or outputs to other customers.
Marked does not offer raw prompt or output capture for product improvement. Our product-improvement telemetry is limited to the metadata described above.
If you submit personal information about another person, you must have a lawful basis and any notices, permissions and instructions required by applicable law. Where Marked processes customer-submitted content on a customer’s instructions, the customer is generally the controller or business and Marked is generally its processor or service provider.
4. How we use information
- To authenticate users, create workspaces, issue keys and provide the API, MCP server, dashboard and support.
- To calculate quotas, prevent abuse, investigate incidents, maintain reliability and secure our systems.
- To diagnose bugs, understand aggregate usage and improve documentation, data quality and product behavior.
- To send essential account, security and service messages. We do not send promotional email unless you ask for it or applicable law permits it.
- To comply with law, enforce agreements and establish, exercise or defend legal claims.
Depending on the law that applies, our legal bases may include contract, legitimate interests in operating and securing a business service, consent, and legal obligations. Our limited usage telemetry is used because it is necessary to operate and secure the service and, where permitted, because we have a legitimate interest in understanding aggregate product usage and improving reliability. We keep that interest proportionate by excluding raw prompt text and query values.
We do not make decisions about your eligibility, employment, credit or insurance using solely automated processing.
7. Retention and deletion
We keep information only as long as needed for the purpose collected, to meet legal and accounting duties, resolve disputes, enforce agreements and protect the service. Our operating targets are:
- Raw prompts, outputs and other request content: not retained.
- Request and security metadata: up to 180 days, unless needed for an active incident or legal obligation.
- Account and workspace records: while the account is active and generally up to 90 days after closure, subject to legal, security and financial-record requirements.
- Backups: removed on the normal backup-rotation cycle, generally within 35 days after primary deletion.
- Aggregated or irreversibly de-identified information: may be kept because it no longer identifies an individual.
Deletion from active systems may not immediately remove information in immutable backups or records we must keep. We restrict such information, do not use it for other purposes, and delete it when the applicable hold or retention period ends.
8. Your choices and rights
Depending on your location, you may have the right to access, correct, delete, restrict or object to processing, receive a portable copy, withdraw consent, opt out of certain uses, and complain to a data-protection authority. California residents may also have rights to know, correct, delete, limit certain sensitive-information uses and opt out of sale or sharing. Marked does not sell or share for cross-context behavioural advertising.
Send a request to [email protected] with the subject “Privacy request”. Tell us what you need and the email or workspace connected to the request. We may ask for reasonable information to verify your identity and protect another person’s data. We will respond within the time required by applicable law, explain any limitation or refusal, and provide an appeal or regulator route where required.
If you act for a customer or another person, include evidence that you are authorized. Workspace administrators may be able to access or delete content submitted through their workspace; contact the administrator first where appropriate.
9. Security, incidents and changes
We use measures appropriate to the risk, including encrypted connections, access controls, least-privilege administration, secret hashing, service isolation, logging and backups. No internet service is risk-free. Do not place secrets or highly sensitive information in prompts, URLs or support messages.
If we discover a personal-data incident, we will investigate, contain it and provide notices required by applicable law. To report a suspected issue, email [email protected].
We may update this policy when the service or law changes. The effective date above will change, and we will provide additional notice where required. If a change materially affects customer content or prompt use, we will give notice before applying it where the law requires.
10. Children
Marked is a business and developer service, not directed to children. Do not use it if you are under the age at which you can lawfully consent to data processing where you live. If you believe a child provided personal information, contact us so we can review and delete it where required.