Privacy Policy

Last updated: August 21, 2026

Marginal is operated by Jithin Lal K, trading as Marginal, who is the data controller for the personal data described here. Contact: jithin@marginalhq.com.

What we collect#

Account data. When you sign up we collect your email address, a password (stored only as a secure hash by our authentication provider), and your company and project names. If teammates are added to a project, we store their email addresses.

Usage events you send. Marginal's job is to receive AI usage metadata from your applications: model and provider names, token counts, costs, timestamps, and short custom fields you define (capped at 256 characters each). The ingestion API has no field for prompts or completions — we never receive or store the content of your AI conversations, by design. What arrives in the events you send is under your control; don't put personal data in custom fields unless you're prepared to manage it.

Billing data. Payments are processed by our Merchant of Record, Paddle, who collects your payment details directly — card numbers never touch our servers. We store your subscription status, plan, and Paddle customer reference.

Technical data. Standard server logs, and an ingestion request log used for debugging that is automatically deleted after 7 days.

How we use it#

To provide and improve the service, bill subscriptions, and respond to support requests. We don't sell your data, and we don't use it for advertising.

Where it lives#

Your data is stored in a managed PostgreSQL database (Supabase) running on Amazon Web Services infrastructure in the Mumbai region (ap-south-1), and is encrypted in transit (TLS).

Who we share it with#

Only the subprocessors that run the service: Supabase (database and authentication), Vercel (application hosting), and Paddle (payments, as Merchant of Record). We disclose data beyond that only if required by law.

Retention and deletion#

Usage events are retained while your account is active (your plan controls how far back the dashboard reads, but data isn't deleted on downgrade). Ingestion request logs are deleted after 7 days. When you delete your account — or ask us to — we delete your data. Email jithin@marginalhq.com for deletion, export, access, or correction requests, and we'll act on them promptly.

Changes#

We'll update this page as the service evolves; the "Last updated" date reflects the current version. Material changes will be notified by email or in-app notice.