Privacy policy

What we know about you.

We know your email, the Google account you sign in with, your plan, your devices and the settings you give them, and your Todoist token, which we keep encrypted. Not your assignments. Below is the long version, in plain language.

Last updated · 28 July 2026

01What we collect & what we don't

Everything on our side, by design.

The path your data takes is deliberately short. No Margin server ever stores or reads your academic data. Your assignments move from your school's class portal, to your browser plugin, to your Todoist, to your device, using your own credentials at every step. We do run a small control plane for sign-in and device sync. It holds your account and plan, your devices and their settings, your encrypted Todoist token, and the record of any license key you've redeemed — never your assignments. Here's the full accounting:

What we collect

  • Your email address, when you join the waitlist. Stored only until pre-orders ship and we email you about ordering. Never marketing.
  • Three optional fields on the same waitlist form, only if you choose to fill them in: your school's name, whether you're buying for yourself or someone in your family, and an open note. Each is blank by default. Used to prioritize which class portals we test first and to understand what objections to address. Never marketing, never shared.
  • When you sign in to sync, your Google account email and the account ID Google gives us, plus your plan status. Sign-in is Google OAuth, so we never see your Google password, and we never receive anything else from your Google account: no name, photo, contacts, Gmail, or Drive.
  • If you redeem a license key or buy a Margin Pass, the record linking that purchase to your account and your plan's status (which tier, and when a non-renewing pass lapses), so it can be honored across sign-ins. Paid checkout will run through a merchant-of-record, which handles the payment and passes us your name, email, and an opaque reference that links the purchase to your account — we never see or store a card number, and no academic data is part of a purchase.
  • For each device you set up: the device's number, its firmware version, and its registry timestamps (when it was set up, claimed, and last checked in), the nickname and settings you give it (theme, timezone, and — only if you turn on the optional weather widget, which is off by default — the city you pick for weather, with the map coordinates that city resolves to — an approximate location), and any remote command you've queued from the plugin (sync now, reboot) until the device picks it up.
  • Your Todoist access token and refresh token, kept encrypted (AES-GCM at rest). We decrypt the access token to hand your device a copy so it can read your Todoist, and the server also uses these tokens to identify your Todoist account and to refresh access when it expires, so your sync keeps working. We never use them to read your assignments — the tokens round-trip through us, the task titles never do — but since we decrypt them, that restraint is our policy, not a thing the architecture makes impossible.

That's the full list of what lives on a server we control. There's no academic data on our infrastructure: no assignment titles, no due dates, no grades. Your account, your plan, your device records and settings, and your encrypted Todoist token are there only to sign you in and keep your device in sync.

What we don't collect

  • Assignment titles or due dates (plugin → Todoist → device; we're not in the path)
  • Course names or codes (same)
  • Calendar events (your device reads iCal URLs directly)
  • Your LMS password. Ever.
  • Your Google password, or anything else from your Google account (name, photo, contacts, Gmail, Drive)
  • Grades, scores, or feedback on assignments
  • Submission contents, files, or attachments
  • Browsing history
  • Your location, beyond the city you typed for the optional weather widget (off by default; typed once, never tracked)
  • Contacts, or anything from other apps
  • Analytics, telemetry, or usage tracking on the device or in the plugin — apart from the redacted error diagnostics described below, which are on by default and switch off in Settings → Diagnostics

The browser plugin reads your already-signed-in session with your school's LMS, the same way you read it. We never see your university password and we never log you in. The plugin then writes those assignments to your Todoist using your Todoist OAuth token. The device reads from Todoist using the same token — and writes back one thing: when you mark an assignment done on the device, it completes that task in your Todoist. It writes nothing else. To save you from re-typing it on the device, our control plane relays that token, encrypted at rest, and only to a device you've claimed under your account. Your assignments never pass through us.

Two sign-ins are involved, and we handle them differently. Your Google sign-in just proves who you are: we verify the one-time token Google sends, store your email and the account ID Google provides, and throw the token away. Your Todoist token is the one we keep a copy of, encrypted, for the single purpose of handing it to a device you own so you don't have to type it in. Your LMS login is never a token we touch at all; the plugin just uses the session already open in your browser.

One exception: error reporting. We report application errors and health signals to ourselves so we can find and fix bugs. It's on by default, and it's yours to switch off. Two narrow streams, and nothing else:

No coursework, task contents, or personal data is ever part of this. It's on by default, used only for fixing bugs; you can turn it off any time in Settings → Diagnostics.

02What it's used for

One purpose, and that's the device.

What little data passes through anything we run is used for one thing: running your device and keeping it showing what's due. Your account signs you in and tracks your plan; your device settings and Todoist token get your dashboard set up and synced. That's the whole purpose. We don't use any of it for advertising, recommendations, training models, market research, or any other secondary purpose.

Specifically, we never:

These aren't aspirations. They're commitments. If we ever wanted to do any of these things, we'd have to update this policy and notify you first. We won't.

03Where it lives

Where each piece of data lives.

Your academic data lives in five places. None of them is a server we operate:

And on servers we do run:

Three outside services each handle one narrow thing:

That's the complete list of outside services that touch your account or your data. Two pieces of our own infrastructure sit underneath: Cloudflare hosts the site and routes the waitlist form, and a self-hosted error monitor catches crashes (the error reporting described earlier). Neither receives your coursework. No marketing pixels, no analytics scripts, no chat widgets, no data brokers.

The same accounting, integration by integration. The column that matters is the last one: where the data lives. Only one row points at a server we run, and that row holds a license check and a billing identity, never your coursework.

What each integration touches, and where it lives
Integration What it touches Where the data lives
Canvas (LMS) Your assignment list, read from the session already open in your browser. The plugin writes those items into your Todoist. We never see your LMS password. Your browser → your Todoist. Never a Margin server.
Todoist The assignments the plugin wrote, in one Margin list with a section per course. The device reads them on every refresh using your own token. Doist (EU). The encrypted token round-trips through us; the task titles never do.
iCal calendars The events in any iCal feed URL you add (Apple, Google, Outlook, your school's academic calendar). The device fetches them directly. Device ↔ the calendar provider. We're not in the path.
Syllabus parsing & change-tracking The syllabus you paste or upload, and what changed between captures over time. Read and stored on your own machine. Your machine. Never sent to us.
License & billing server A license check (is your plan current) plus, through the merchant-of-record at checkout, a name, email, and an opaque reference linking the purchase to your account. No syllabi, assignments, due dates, or grades. Our control plane (EU, Finland), and the merchant-of-record. The only server row.
04How long we keep it

Plain durations. The numbers got smaller.

Real numbers:

05Your rights

What you can ask us to do.

You can:

These rights apply to everyone, regardless of where you live. Not just people in California or the EU. We don't think basic data rights should depend on jurisdiction.

06Security

Practical measures, not promises.

The actual safeguards in place today:

What we don't claim: that we're impervious to breach. No company can honestly claim that. If a security incident affects your data, we'll tell you what happened, what we know, and what we're doing about it. Within seventy-two hours of confirming the breach. Not "as soon as practicable." Not "in due course." Within seventy-two hours.

07Children under 13

Margin is for readers 13 and older.

We don't knowingly collect data from anyone under 13. If you're a parent or guardian and you believe your child has registered for Margin, email us and we'll delete the account and all associated data, no questions asked.

This policy aligns with COPPA (the U.S. Children's Online Privacy Protection Act). Schools and districts that wish to provide Margin to students under 13 should contact us first. We don't currently support that use case.

08International readers

The world is bigger than the U.S.

Margin is operated from the United States, but the data we hold lives in the European Union. The waitlist record and the control plane that holds your account, device settings, and encrypted Todoist token all run on servers in the European Union (Finland). Your data is not stored in the United States. By joining the waitlist or signing in, you consent to the processing described here.

Your academic data is a different story. It flows from your browser to your Todoist to your device, and Doist is headquartered in the European Union. None of that data passes through any U.S. server we run.

For readers in the European Economic Area, the United Kingdom, or Switzerland: we process your waitlist email to perform the pre-order contract you entered into (you asked to be told when we ship), and we process your account and device data to provide the device you signed up for. Both rest on the legal basis of performing a contract with you. You have the rights described in section 05, plus the right to lodge a complaint with your local data protection authority.

For California residents: the rights in section 05 satisfy the requirements of the CCPA and CPRA (California's consumer privacy laws). We don't sell your data and we don't "share" it for cross-context behavioral advertising. There is no advertising on Margin.

09Changes to this policy

How you'll know we changed something.

If we update this policy in any meaningful way (adding a new third party, changing what we collect, changing how long we keep it), we'll email every active user at least seven days before the change takes effect. The email will say what changed, in plain language, and link to a diff of the old and new policies.

Cosmetic edits (typos, clarifications, link fixes) don't count and won't trigger an email. The "last updated" date at the top of this page reflects every change, cosmetic or otherwise.

Questions, requests, or concerns? Email us.

Privacy questions, data export requests, deletion requests, or "I think something's wrong." All go to the same address:

privacy@margin.computer

We aim to respond within three business days and to complete data export or deletion requests within seven days. A real human reads every email.