Last updated: September 2, 2026
Marklet Privacy Policy
1. General provisions
This policy explains what data the Marklet service processes on marklet.so, why it is needed, and how users can manage it. The service administrator can be reached at[email protected].
Before the public commercial launch, this section must additionally state the full name or business name and address of the personal data operator.
2. Data we process
- email, profile name, identifiers, and technical account data; when Google sign-in is used, the Google account email and profile name;
- prompts, page and revision content, text, contact details, photos, attachments, and other materials submitted to the service;
- voice-input audio submitted for transcription and the resulting transcript;
- essential authentication, guest-draft, page-view, and attribution cookies, together with technical identifiers stored in the browser's local storage;
- Marklet stores the parameters of the visit through which a user arrived: UTM parameters, a referral code, advertising click identifiers, the referring site's host, and the landing page path — separately for the first visit and the visit in which the account was created;
- the aggregated number of views of published pages, without storing IP addresses in page statistics;
- product-usage events, technical browser and device data, and diagnostic information about errors and requests;
- email messages, support inquiries, complaints, and related materials.
3. Purposes of processing
Data is used to create and edit pages and generate images, store drafts and revisions, transcribe voice input, provide account access, publish short links and QR codes, count views and usage events, send transactional and product email, measure where registrations come from, evaluate advertising channels, prevent abuse, diagnose errors, moderate content, and respond to inquiries.
4. Service providers and data transfers
AI providers
- Google Gemini API — generating and editing pages and images from the prompt, page content, and required attachments;
- OpenAI — a backup model for page generation and editing;
- OpenRouter and model hosts selected through it — backup routing of model requests.
To perform a request, the prompt, page content, and required attachments are transmitted to the selected AI provider. If the service switches to a backup model, one request may be sent sequentially to more than one provider. How those providers retain and use the data, including for model improvement or training, is governed by each provider's current terms and policies; Marklet does not make promises on their behalf. Do not submit data that is unnecessary to create the page.
Voice input
Deepgram receives the voice-input audio and technical request parameters needed to return a transcript.
Resend processes the recipient address and content of transactional messages, including sign-in and confirmation email. Loops receives the email address, a name when available, and the applicable service identifier for product mailings and contact management.
Analytics and errors
PostHog and Google Analytics, loaded through Google Tag Manager, process usage events and technical browser information. The TikTok Pixel, also loaded through Google Tag Manager, receives usage events and technical browser information for advertising measurement. The Meta Pixel, the LinkedIn Insight Tag, and the ChatGPT Ads Measurement Pixel receive usage events and technical browser information for advertising measurement. Marklet does not send server-side conversion events to Meta through the Conversions API. OpenAI also receives registration events and available advertising identifiers through its Conversions API under the same measurement consent policy; shared event identifiers prevent duplicate counting. Sentry receives server-error diagnostics; it is configured without default personal information and removes request bodies, cookies, email addresses, and IP addresses from its events. GitHub Issues is used for operational error reports and may receive a diagnostic description and attachments that an administrator adds to such a report.
Infrastructure
Cloudflare handles all network traffic, DNS, and incoming email forwarding for support and abuse addresses, and may therefore process network data and email metadata and content. Supabase provides accounts, authentication, and the database; Railway hosts the application and its technical logs; Bunny.net stores and delivers uploaded and generated images and QR codes.
Google sign-in
If a user chooses Google OAuth, Google provides the authentication system with the account email, profile name, and technical sign-in data.
When the Google sign-in button is loaded in a sign-in dialog, or a Google sign-in prompt is requested on an eligible returning visit to the homepage or in the editor, Google receives the visitor's IP address, browser details, and the marklet.so origin through the script request. This can happen before the visitor chooses Google sign-in and is not controlled by the analytics consent setting.
Providers may process data outside the user's country. Their own retention periods and processing practices are governed by their current terms, policies, and service settings.
5. Public pages and other people's data
A published page is available to anyone who knows its link or scans its QR code. The "link only" setting prevents search indexing, but it is not a password. Users must have a lawful basis for publishing photographs, phone numbers, and other information about third parties. For children's pages, we recommend providing adults' contact details and only the minimum information necessary.
6. Retention and deletion
The current code does not apply one automatic deletion period to account data, pages, prompts in generation logs, or revision history. Revision history is not automatically truncated and remains with the page until the page is deleted or a user request is processed. Security, accounting, or legal requirements may require individual records to be kept longer.
Retention by external analytics systems follows their settings and terms.
Attribution data for the first visit and the account-creation visit is stored for as long as the account exists and is deleted with it.
Individual pages can be deleted in the account. To request account deletion or access to, correction of, or deletion of other associated data, email[email protected]. Retention of copies by external providers is governed by their terms and mandatory requirements, not by one period in Marklet's code.
7. Cookies, analytics, and security
Marklet uses essential cookies for sessions, guest drafts, abuse prevention, and deduplicating aggregate page views. The analytics choice is stored in the browser's local storage. For visitors in the European Economic Area, the United Kingdom, or Switzerland, the banner asks for prior consent: PostHog, Google Tag Manager/Google Analytics, the TikTok Pixel, the Meta Pixel, the LinkedIn Insight Tag, and the ChatGPT Ads Measurement Pixel remain disabled until an explicit Accept, while Decline keeps them disabled. Everywhere else, those analytics services are on when the visitor arrives, and no consent banner or notice is rendered. The ChatGPT Ads Measurement Pixel follows the same analytics-consent preference. The Analytics preference control below switches analytics off, saves the decision in this browser, and prevents the loaders from running on later page loads. If analytics tags are already active, the page reloads once after they are switched off so their third-party runtimes stop. A stored Accept or Decline always takes priority over a later country result.
Analytics preference
Cloudflare's request country is used only to select the applicable consent regime for that request; Marklet does not store, log, or persist it for this purpose. If the country is missing or unrecognized, Marklet uses the safer prior-consent regime. The first-party aggregate page-view counter can still operate and does not store IP addresses in page statistics. Google's advertising storage and personalization consent signals are set to denied.
Marklet also classifies the attribution cookie as essential: it holds UTM parameters, a referral code, advertising click identifiers, the referring site's host, and the landing page path, and it lasts for one year.
The essential metka_seen_auth cookie remembers that this browser has already used an account so the right sign-in or sign-up form opens; it contains only the value 1 and lasts for one year.
The essential metka_locale cookie stores the interface language and whether it was selected by the user or detected automatically. It lasts for one year; an explicit choice always takes priority over automatic detection.
Access to data is restricted, connections are protected with HTTPS, and uploaded materials are checked for type and size. No internet service can guarantee absolute security.
8. Changes to this policy
A new version will be published on this page with an updated date. Material changes affecting registered users will be communicated in the interface or by email when necessary.