Privacy policy
Last updated October 3, 2026 · Operated by MarginMeter
This policy explains what data MarginMeter collects, why, how long we keep it and the choices you have.
Data we collect
- Account data: your name, email address, password hash (never the password), sign-in provider identifiers, and session records including a truncated IP address and browser family.
- Workspace data: workspace names, members, roles, settings, alert rules and manual costs you create.
- Connected data: revenue, subscription, customer and cost records that MarginMeter reads from the providers you connect (for example Stripe, AWS, OpenAI and Anthropic), and the raw payloads those providers return.
- Credentials: provider keys you supply, stored encrypted with AWS KMS. AWS connections store only a role ARN and external ID.
- Billing data: your subscription status. Card details are handled by Stripe and never reach our servers.
We do not use advertising trackers or third-party analytics on our website or app.
How we use data
- To provide the service: calculate revenue, costs, margins and alerts, and show them to members of your workspace.
- To send service emails: verification, security notices, alerts and the weekly digest (which you can turn off).
- To secure the service: prevent abuse, enforce rate limits and investigate incidents.
We do not sell personal data and we do not use your connected data to train AI models.
Where data is stored
Data is stored in AWS and Supabase in the Asia Pacific (Singapore) region and encrypted in transit and at rest. See our subprocessors.
Retention
- Normalized financial data is kept while your workspace exists, limited to your plan's history window.
- Raw provider payloads are deleted automatically after 90 or 400 days depending on your plan.
- Deleted workspaces and accounts are removed in stages after a short grace period; backups expire within 35 days.
Your rights
You can access, export, correct and delete your data from the app at any time. Depending on where you live you may have additional rights, such as objecting to processing or lodging a complaint with a supervisory authority. Contact us through the contact page to exercise them.
Changes
We will post changes on this page and update the date above; significant changes are announced by email.