Privacy Policy
Last updated: July 9, 2026
Marvin (“we”, “us”) operates marvinsci.com. This policy explains what personal information we collect and how we use it.
Information we collect
- Account information: When you create an account or sign in with Google or GitHub, we receive your name, email address, and a stable identifier from the sign-in provider. We do not receive or store your sign-in provider password.
- Content you provide: Research questions, prompts, files, and datasets you upload or reference within Marvin.
- Usage information: Basic log, device, and usage data when you use the service.
Sign in with Google and your Google data
- Data we access: When you sign in with Google, we access your name, email address, and Google account identifier (via the standard OpenID Connect
openid,email, andprofilescopes). We do not request access to your Gmail, Google Calendar, Google Contacts, or YouTube data. If you choose to connect Google Drive, we request read-only access to your Google Drive (including the contents of your files) so you can reference your files within Marvin. - How we use it: Your Google sign-in data is used to create and authenticate your account and to display your identity in the product. Google Drive data is used only within research sessions that you initiate, and never for advertising.
- Sharing: We do not sell your personal information. Your sign-in identifiers are shared only with the infrastructure providers listed below. When you use Google Drive files or other content within a Marvin session, that content may be processed by AI model provider(s) — either providers we configure, or a provider whose API key you supply, depending on your setup.
- Storage and protection: Your name, email, and account identifier are stored in our PostgreSQL database hosted on Fly.io, protected by access controls. We do not store your Google OAuth access or refresh tokens — only your stable account identifier. When you connect an integration such as Google Drive, the connection credentials are stored encrypted.
- Retention and deletion: Your sign-in data is retained for as long as your account is active. A Google Drive connection is retained until you disconnect it (revocable at any time from your settings). To request deletion of your account and associated personal data, email [email protected]; we process such requests within 30 days.
How we use information
To provide, maintain, and improve Marvin; to authenticate you; to process the research sessions and content you initiate; and to communicate with you about your account. We do not sell your personal information.
Data storage and security
We use reasonable administrative, technical, and physical safeguards to protect your information. Data is stored on infrastructure hosted by Fly.io, including Fly Postgres. No method of transmission or storage is completely secure.
Third-party services
We rely on the following categories of third parties to operate Marvin:
- Authentication providers (Google, GitHub) — to verify your identity at sign-in.
- Cloud hosting and database (Fly.io, Fly Postgres) — to run the application and store account data.
- Object storage (Tigris) — to store files and datasets you upload.
- Payments (Stripe) — to process billing if you purchase a plan.
- Email (AWS SES) — to send transactional and account-related email.
- AI model provider(s) — to process the research sessions and content you initiate; this may include a provider whose API key you supply.
- Optional integrations you connect (for example, Google Drive, Notion) — accessed only when you choose to connect them.
Data retention
We retain your account information for as long as your account is active. Project content and logs are retained for the life of the relevant project unless deleted. You may request deletion at any time.
Your rights and deletion
You may request access to, correction of, or deletion of your personal data by emailing [email protected]. We process deletion requests within 30 days. We may retain certain information as required by law or to resolve disputes.
Changes
We may update this policy from time to time. Material changes will be reflected by updating the “Last updated” date above.
Contact
Questions? Email [email protected].