Privacy policy

What we know about you.

We know your email, the assignments your school publishes to its LMS, and which device is yours. That's it. Below is the long version, in plain language.

Last updated · 13 May 2026

01What we collect & what we don't

Almost nothing on our side, by design.

The data pipeline is deliberately tiny. Margin runs no server that handles your academic data. Your assignments move from your school's class portal, to your browser plugin, to your Todoist, to your device, using your own credentials at every step. We're never in the middle. Here's the full accounting:

What we collect

  • Your email address, when you join the waitlist. Stored only until pre-orders ship and we email you about ordering. Never marketing.
  • Three optional fields on the same waitlist form, only if you choose to fill them in: your school's name, whether you're buying for yourself or someone in your family, and an open note. Each is blank by default. Used to prioritize which class portals we test first and to understand what objections to address. Never marketing, never shared.

That's the full list of what lives on a server we control. There's no Margin user account, no profile, no academic data on our infrastructure.

What we don't collect

  • Assignment titles or due dates (extension → Todoist → device; we're not in the path)
  • Course names or codes (same)
  • Calendar events (your device reads iCal URLs directly)
  • Your LMS password. Ever.
  • Grades, scores, or feedback on assignments
  • Submission contents, files, or attachments
  • Browsing history
  • Location, contacts, or anything from other apps
  • Analytics, telemetry, or usage tracking on the device or in the extension

The browser plugin reads your already-authenticated session with your school's LMS, the same way you read it. We never see your university password and we never log you in. The plugin then writes those assignments to your Todoist using your Todoist OAuth token, stored locally in the extension. The device reads from Todoist using the same token, cached on the device.

Those OAuth tokens are yours, not ours. They live in your browser's encrypted local storage and on your device's flash storage. We don't hold copies, and we couldn't act on them if we wanted to.

02What it's used for

One purpose, and that's the device.

What little data passes through anything we run is used for one thing: making the device show you what's due. That's the whole purpose. We don't use any of it for advertising, recommendations, training models, market research, or any other secondary purpose. With the new pipeline, there's barely anything to misuse even if we wanted to.

Specifically, we never:

These aren't aspirations. They're commitments. If we ever wanted to do any of these things, we would need to update this policy and notify you first, and we never will.

03Where it lives

Five places, none of them a Margin server.

Your academic data lives in five places. None of them is a server we operate:

And one small thing on a server we do run:

The device also reaches one more public service for the weather widget:

That's the complete list. There are no other third parties. No marketing pixels, no analytics scripts, no chat widgets, no data brokers.

04How long we keep it

Plain durations. The numbers got smaller.

Real numbers:

05Your rights

What you can ask us to do.

You can:

These rights apply to everyone, regardless of where you live. Not just users in California or the EU. We don't think basic data rights should depend on jurisdiction.

06Security

Practical measures, not promises.

The actual safeguards in place today:

What we don't claim: that we're impervious to breach. No company can honestly claim that. If a security incident affects your data, we'll tell you what happened, what we know, and what we're doing about it. Within seventy-two hours of confirming the breach. Not "as soon as practicable." Not "in due course." Within seventy-two hours.

07Children under 13

Margin is for users 13 and older.

We don't knowingly collect data from anyone under 13. If you're a parent or guardian and you believe your child has registered for Margin, email us and we'll delete the account and all associated data, no questions asked.

This policy aligns with COPPA (the U.S. Children's Online Privacy Protection Act). Schools and districts that wish to provide Margin to students under 13 should contact us first. We don't currently support that use case.

08International users

The world is bigger than the U.S.

Margin is operated from the United States. The waitlist database is hosted on Supabase, which stores it on U.S.-region servers. If you use Margin from outside the U.S., joining the waitlist means your email and any optional fields you fill in are transferred to and stored in the United States. By joining, you consent to this transfer.

Your academic data is a different story. It flows from your browser to your Todoist to your device, and Doist is headquartered in the European Union. None of that data passes through any U.S. server we run.

For users in the European Economic Area, the United Kingdom, or Switzerland: we process your waitlist email on the legal basis of performing the pre-order contract you've entered into with us (you asked to be told when we ship). You have the rights described in section 05, plus the right to lodge a complaint with your local data protection authority.

For California residents: the rights in section 05 satisfy the requirements of the CCPA and CPRA (California's consumer privacy laws). We don't sell your data and we don't "share" it for cross-context behavioral advertising. There is no advertising on Margin.

09Changes to this policy

How you'll know we changed something.

If we update this policy in any meaningful way (adding a new third party, changing what we collect, changing how long we keep it), we'll email every active user at least thirty days before the change takes effect. The email will say what changed, in plain language, and link to a diff of the old and new policies.

Cosmetic edits (typos, clarifications, link fixes) don't count and won't trigger an email. The "last updated" date at the top of this page reflects every change, cosmetic or otherwise.

Questions, requests, or concerns? Email us.

Privacy questions, data export requests, deletion requests, or "I think something's wrong." All go to the same address:

privacy@margin.computer

We aim to respond within three business days and to complete data export or deletion requests within seven days. A real human reads every email.