01Who we are
This policy explains how Marv handles personal information when you use the website at meetmarv.org and the Marv app for Windows. Marv is the controller of that information, except where this policy says a provider acts on its own account.
“We” and “us” mean the people who publish Marv. You can reach us at hello@meetmarv.org, or by using Contact on the homepage and leaving a note with the email address concerned.
This policy is written for people in the United Kingdom. If you use Marv from somewhere else, your local law may give you extra rights. The way the product works does not change.
02The short version
The website saves the email address you submit for the waitlist, an optional note, and the date you joined. The first time an address joins, we email it once to confirm. The illustrations on the homepage do not record your microphone or capture your screen. The website does not use advertising trackers.
The app listens and looks only while you hold the talk hotkey, or for the single capture of a task you asked it to look at. Screenshots are held in memory, sent for that request, and then wiped. Microphone audio is not written to a file. Pause turns capture and the microphone off.
Settings, a privacy log, usage counts, and the text of recent turns stay on your PC. Optional provider keys and the account session are stored in Windows Credential Manager. Crash reports and product analytics stay off until you opt in, and they are not allowed to include what was on your screen.
03The website
If you join the waitlist, we store:
- your email address, in lower case;
- the date and time you first joined;
- a note, if you typed one. A later note replaces an earlier one. An empty submission does not wipe a note you already left.
We use that information to keep your place, to tell you when early access is ready, and to read and reply to a note. A repeat signup does not create a second row and does not send a second confirmation.
The form includes a hidden field meant to catch automated signups. If that field is filled in, we do not save the submission.
The confirmation email is sent so you know the address was received. It is one message per new address, not an ongoing marketing list. You are receiving it because you asked to join.
The page at /auth/callback only helps an email link open the app. It reads the code or token in that link and hands it to Marv on your computer. It does not create an account and it does not store the link.
Ordinary hosting records can include your IP address, the time of the request, the page you asked for, and the browser you used. We use those records to run the site and to investigate abuse. We do not use them to build an advertising profile.
04The Windows app
What stays on the PC
In the Marv folder under your Windows app data, the app can keep settings, a denylist of window titles, usage counts, and the text of recent turns. It also keeps a privacy log: the time, the name of the foreground app, whether a capture happened, and how many bytes were sent. The privacy log does not contain pixels and does not contain the transcript.
Windows Credential Manager holds optional API keys and the session for your account. Those values are not written into the privacy log.
If you ask an agent to draft something, the draft can be written under Documents/MARV. Those files stay there until you delete them. The app does not send, delete, or pay unless you confirm that action on screen.
What is used for a request, then dropped
While the talk hotkey is held, the app opens the microphone. Samples stay in memory so it can hear the start of a sentence. Audio is not written to a file on the PC.
When you ask Marv to look, it takes a screenshot, encodes it in memory, and sends it with the request. The buffer is wiped after the request is sent. Guide drawings are painted on the overlay from the reply. They are not saved.
A play or pause key is sent only when you ask to pause a video and that setting is on.
What we try to keep out of a capture
Before a capture is sent, windows that match the denylist are painted black. The denylist includes password managers, banking-like titles, private browser windows, and anything you add. The Marv buddy itself is left out of the capture so the model does not see it. The denylist can miss a window. Do not ask Marv to look at a screen you do not want included in that request.
The tray shows a listening state while the microphone is open. Pause turns capture and the microphone off.
What you can delete locally
Export and delete live under Settings, in Screen & Privacy. Delete removes turns, the privacy log, agent jobs, usage counts, and saved secrets on that PC. Uninstalling the app does not by itself remove drafts under Documents/MARV, and it may leave the app-data folder or a credential until you delete those too.
05Your account
If you create an account, we process your email address, your password in a form the account service stores, whether the email has been confirmed, a display name if you gave one, and the session that keeps you signed in. The app can also store a label for the device, such as “This PC”.
We use the account to recognise you, to send the confirmation and password-reset messages you ask for, and to keep the app signed in on that computer. A waitlist signup on the website is a separate list. Joining the waitlist does not create an app account.
If a paid plan is offered later, the payment provider processes the card. We would receive the status of the plan and the identifiers needed to match it to your account. We do not want your full card number in the app.
06Why we use it
Under UK data protection law, we rely on these reasons:
- Contract, or steps you asked for before a contract. Saving your waitlist signup, running your account, confirming your email, and carrying out the desktop request you started.
- Legitimate interests. Keeping the site and the app secure, blocking automated signups, understanding a fault you report, and keeping a short privacy log on your PC so you can see when capture happened. We do not use these interests for advertising.
- Consent, where we ask for it. Crash reports and product analytics stay off until you opt in. You can withdraw that opt-in in the app. Withdrawing it does not affect a request you already asked Marv to make.
- Legal duty. If we have to keep or disclose something because the law says so.
Holding the hotkey, turning pause off, or asking Marv to look is the instruction for that feature. You can stop it at any time by releasing the hotkey, pausing, or denying the Windows permission.
08How long it lasts
We keep a waitlist row until you ask us to remove it, or until we no longer need it to run early access and to handle a note you sent, whichever comes first. A confirmation email is a one-off. We do not keep sending because you joined.
We keep an app account while it is open. If you ask us to delete it, we delete or irreversibly anonymise the account information we hold, unless we have to keep a limited record to show that we dealt with the request or to meet a legal duty.
Screenshots and microphone audio are not stored by the app after the request. A provider that received them may keep them for a short period under its own abuse and reliability rules. Recent turn text on the PC stays until you delete it in Settings or it is replaced by later use.
Server logs are kept only as long as the host needs them for security and operations, and not as a profile of you.
09Where it is kept
The app’s local records stay on the Windows PC where you installed it. The waitlist, the account, email delivery, and model requests are handled by providers that can store or process information in the United Kingdom, the European Economic Area, and the United States.
Where information leaves the United Kingdom, we use a lawful transfer mechanism. That can include a country the UK treats as adequate, or the UK International Data Transfer Addendum to the EU standard contractual clauses, together with the provider’s security terms. You can ask us for a copy of the relevant safeguards.
10Your rights
If UK data protection law applies, you can ask us to:
- tell you whether we hold personal information about you, and for a copy of it;
- correct it;
- delete it;
- restrict how we use it, or object to use based on legitimate interests;
- provide information you gave us, where the law calls for portability, in a common format;
- withdraw a consent you gave, such as an opt-in to crash reports. Withdrawal does not undo processing that was already lawful.
Write to hello@meetmarv.org, or use Contact on the homepage from the same email address. We may need to confirm that the address is yours before we change or delete anything. We aim to reply within one month.
Local copies on your PC, including turns and the privacy log, are removed with the delete control in the app. Tell us if you also want the waitlist row or the account removed from our side.
You can complain to the Information Commissioner’s Office at ico.org.uk/make-a-complaint. We would like the chance to put a problem right first.
11Children
Marv is not directed at children under 16, and we do not knowingly collect their personal information. If you believe a child under 16 has given us an email address or opened an account, contact us and we will delete it.
13Security
We limit the waitlist so the public website cannot read or write it directly. Account passwords are handled by the account service, not stored in the waitlist. Provider keys in the app are kept in Credential Manager rather than in an ordinary settings file.
No method of transmission or storage is perfect. Do not put a password, a payment card, or another standalone secret into a waitlist note or into a question to Marv. Use the denylist and Pause when a sensitive window is open.
14Changes and contact
If we change this policy in a material way, we will post the new version on this page and change the date at the top. If you have an account and the change affects how we handle account or screen information, we will also email the address on the account.
The Terms of use explain the licence to use Marv. This policy explains the information. If you want a copy of what we hold, or you want it removed, email hello@meetmarv.org.
