Marked Back to marked.run

Privacy

Privacy, plainly stated.

Marked provides financial data, APIs and tools for AI agents. This policy explains what we collect, why we collect it, what we do with prompts and outputs, and how you can control your information.

Effective and last updated: September 12, 2026

1. Who we are

“Marked”, “we”, “us” and “our” mean the Marked service and its operator. Marked is based in India. Our privacy contact is [email protected]. We will update this policy if the operating entity or contact details change.

This policy applies to marked.run, app.marked.run, our API, MCP endpoint, dashboard, account and support interactions. A customer agreement or data-processing addendum controls if it conflicts with this policy.

We apply applicable Indian law, including the Digital Personal Data Protection Act, 2023 where it applies, and other applicable data-protection laws for people in other jurisdictions. The law applicable to a particular request depends on the person, service and processing involved.

2. What we collect

CategoryExamplesWhy
AccountEmail, name, profile, OAuth provider ID, sign-in and verification recordsCreate and secure your account
WorkspaceWorkspace name, plan, API-key hash, permissions and usage totalsProvide access, billing records and quotas
Request contentPrompts, questions, tool calls, arguments, retrieved context, files, outputs and feedback you submitProcessed to answer your request; raw content is not retained by default
TechnicalIP address, user agent, timestamps, URLs, status codes, request IDs, cookie identifiers and security eventsReliability, abuse prevention, diagnostics and security
SupportMessages, attachments and information you choose to provideAnswer and resolve your request

We collect information from you, your workspace administrator, your browser or client, authentication providers you choose, and service providers that help us operate the service. We do not buy personal information or use data brokers to build consumer profiles.

3. Prompts and AI content

When you call an API or MCP tool, we process the request in memory to return the requested result. By default, we do not retain prompt text, output text, request bodies, query values or uploaded files. We may retain limited metadata such as the endpoint or tool, dataset or query category, parameter names, response status, latency and date.

This metadata helps us deliver the service, detect abuse, protect security, troubleshoot failures, measure quality and prioritize improvements. It is not used to reconstruct your prompt, sold, used for cross-context behavioural advertising or used to train a general-purpose AI model. We do not disclose customer prompts or outputs to other customers.

Marked does not offer raw prompt or output capture for product improvement. Our product-improvement telemetry is limited to the metadata described above.

If you submit personal information about another person, you must have a lawful basis and any notices, permissions and instructions required by applicable law. Where Marked processes customer-submitted content on a customer’s instructions, the customer is generally the controller or business and Marked is generally its processor or service provider.

4. How we use information

  • To authenticate users, create workspaces, issue keys and provide the API, MCP server, dashboard and support.
  • To calculate quotas, prevent abuse, investigate incidents, maintain reliability and secure our systems.
  • To diagnose bugs, understand aggregate usage and improve documentation, data quality and product behavior.
  • To send essential account, security and service messages. We do not send promotional email unless you ask for it or applicable law permits it.
  • To comply with law, enforce agreements and establish, exercise or defend legal claims.

Depending on the law that applies, our legal bases may include contract, legitimate interests in operating and securing a business service, consent, and legal obligations. Our limited usage telemetry is used because it is necessary to operate and secure the service and, where permitted, because we have a legitimate interest in understanding aggregate product usage and improving reliability. We keep that interest proportionate by excluding raw prompt text and query values.

We do not make decisions about your eligibility, employment, credit or insurance using solely automated processing.

5. When we share information

We share the minimum information needed with service providers acting on our instructions. Current categories include:

  • Hosting and delivery: the VM or cloud provider hosting the application and database, Cloudflare for DNS, tunnel, proxy and security services, and Vercel for the marketing site.
  • Authentication and email: Google when you choose Google sign-in, and Resend when we send a magic-link or account email.
  • Legal and safety: authorities, advisers or other parties when required by law, to protect rights and safety, or during a merger, financing, acquisition or sale of assets.

We do not sell personal information. We do not share it for cross-context behavioural advertising. We do not disclose customer prompts or outputs to other customers.

These providers may process information in countries other than where you live. We use contractual, technical or other safeguards required by applicable law and limit providers to the purposes described here.

6. Cookies and similar technology

The app uses essential cookies for authentication, sessions, security and requested functionality. The marketing site does not use advertising pixels or analytics cookies. It loads fonts from Google Fonts, which may allow Google to receive technical connection information such as your IP address and browser details. Your browser may also store standard security and preference data.

7. Retention and deletion

We keep information only as long as needed for the purpose collected, to meet legal and accounting duties, resolve disputes, enforce agreements and protect the service. Our operating targets are:

  • Raw prompts, outputs and other request content: not retained.
  • Request and security metadata: up to 180 days, unless needed for an active incident or legal obligation.
  • Account and workspace records: while the account is active and generally up to 90 days after closure, subject to legal, security and financial-record requirements.
  • Backups: removed on the normal backup-rotation cycle, generally within 35 days after primary deletion.
  • Aggregated or irreversibly de-identified information: may be kept because it no longer identifies an individual.

Deletion from active systems may not immediately remove information in immutable backups or records we must keep. We restrict such information, do not use it for other purposes, and delete it when the applicable hold or retention period ends.

8. Your choices and rights

Depending on your location, you may have the right to access, correct, delete, restrict or object to processing, receive a portable copy, withdraw consent, opt out of certain uses, and complain to a data-protection authority. California residents may also have rights to know, correct, delete, limit certain sensitive-information uses and opt out of sale or sharing. Marked does not sell or share for cross-context behavioural advertising.

Send a request to [email protected] with the subject “Privacy request”. Tell us what you need and the email or workspace connected to the request. We may ask for reasonable information to verify your identity and protect another person’s data. We will respond within the time required by applicable law, explain any limitation or refusal, and provide an appeal or regulator route where required.

If you act for a customer or another person, include evidence that you are authorized. Workspace administrators may be able to access or delete content submitted through their workspace; contact the administrator first where appropriate.

9. Security, incidents and changes

We use measures appropriate to the risk, including encrypted connections, access controls, least-privilege administration, secret hashing, service isolation, logging and backups. No internet service is risk-free. Do not place secrets or highly sensitive information in prompts, URLs or support messages.

If we discover a personal-data incident, we will investigate, contain it and provide notices required by applicable law. To report a suspected issue, email [email protected].

We may update this policy when the service or law changes. The effective date above will change, and we will provide additional notice where required. If a change materially affects customer content or prompt use, we will give notice before applying it where the law requires.

10. Children

Marked is a business and developer service, not directed to children. Do not use it if you are under the age at which you can lawfully consent to data processing where you live. If you believe a child provided personal information, contact us so we can review and delete it where required.