Privacy Policy
This policy explains what data Margo collects, what we do with it, and the control you keep over it. It applies to the Margo service operated by Fyndability Labs, Inc.
We collect what we need to run your marketing department: your account details, the brand content you create, tokens for the platforms you connect, and usage data. We use your content to draft marketing on your behalf — never to train shared AI models across customers, and we never sell your data. Delete your organization and your data goes with it.
What we collect
Account data. Your name, email address, and organization details when you sign up or accept an invitation.
Content you create. Brand information, marketing briefs, drafts, approvals, and anything else you or Margo produce inside your workspace.
Connection data. When you connect an external platform (an ad account, email service, or social channel), we store the OAuth tokens needed to act on your behalf. Tokens are encrypted at rest.
Usage data. Metrics about how the service is used and audit logs of significant actions — who approved what, and when. Audit logs exist to protect you.
How we use it
We use your data to provide the service: running your marketing roles, drafting content, syncing metrics from connected platforms, and sending you transactional email about your account.
Your marketing content is processed by AI to draft on your behalf. That processing is scoped to your workspace. We do not use your content to train shared models across customers, and we do not sell your data — to anyone, for any purpose.
Subprocessors
We rely on a small set of infrastructure providers to run Margo. Each one processes data only as needed for its role:
- VercelApplication hosting and content delivery
- NeonManaged Postgres database where your data lives
- AnthropicAI processing of your marketing content to generate drafts
- InngestBackground job scheduling (the department clock)
- ResendTransactional email (invites, notifications)
- UpstashRate limiting infrastructure
- SentryError monitoring and diagnostics
If we add or replace a subprocessor, we will update this list before the change takes effect.
Retention
We keep your data for as long as your account is active. If you delete your organization from the product, deletion cascades: your brands, content, connections, and related records are removed. Copies in encrypted backups age out on a rolling schedule thereafter.
Your rights
You can request access to, an export of, correction of, or deletion of your personal data at any time. Organization deletion is self-serve inside the product; for anything else, email us at sales@citepulse.io and we will respond promptly. Depending on where you live, these rights may also be guaranteed to you by law (for example under GDPR or CCPA); we honor them for everyone.
Security
Data is encrypted in transit (TLS) and at rest. OAuth tokens for connected platforms are additionally encrypted at the application level. Access inside your workspace is governed by role-based access control, and significant actions are recorded in audit logs. No system is perfectly secure, but we treat your marketing data — and the keys to your channels — as the sensitive material it is.
Children
Margo is a business tool and is not directed at children. We do not knowingly collect data from anyone under 16. If you believe a child has provided us data, contact us and we will delete it.
Changes
If we make material changes to this policy, we will update the effective date above and notify account owners by email before the changes take effect. Continued use of the service after that date means you accept the updated policy.
Contact
Fyndability Labs, Inc. · sales@citepulse.io
This document is provided for transparency and is not legal advice to you. Questions: sales@citepulse.io