← Marginalia

Marginalia · Legal & help

Privacy policy

Where your information goes, and what deletion does.

Effective 9 October 2026 · Version 1.3

Marginalia is operated by LUFF LLC, a Massachusetts limited liability company. This policy covers Marginalia, optional LUFF-operated services and Marginalia-related website forms. Contact us at support@luff.works or through the contact form. Information flows depend on the features you use; availability varies by release and device.

Your local library

Articles, imported files and emails, podcasts, recordings, highlights, notes, generated results and reading or listening progress are stored in your local library, along with operation history, settings and downloaded files. Selected connection credentials use the device's Keychain. Companion features can copy relevant information to widgets or paired Apple devices.

Local use needs no Marginalia account. The connections below explain when information leaves your device. Exports and device backups can create additional copies under your own or Apple's settings.

Publishers and podcast sources

Saving a link or loading, refreshing and downloading a podcast can contact its publisher, feed host or content network. These recipients receive the requested address and ordinary network information, including IP address and request time. Podcast directory searches send your search term and relevant region or lookup information to Apple's directory service.

Saved pages can contain resources from other hosts. Each recipient controls its own network records and retention.

Camera, microphone and local processing

Scanning text and recording audio use the camera or microphone when you choose the feature and grant system permission. Recordings and results can be saved to your library.

On-device reading assistance, speech processing, handwriting recognition and translation use Apple's system features where available. Apple may download model or language assets. This is separate from hosted processing; microphone permission does not itself enable hosted transcription.

Optional iCloud and nearby sync

Enabling iCloud sync sends library operations and selected assets to the private CloudKit database associated with your Apple Account. Audio uploads depend on your setting. This uses Apple's storage and account protections, rather than Marginalia Relay's sealed channel.

Nearby pairing exchanges library operations and assets with paired devices over an encrypted Marginalia connection. Stopping sync does not remove copies already received.

Optional home servers and audio processing

A home server you connect receives library operations, assets, library and device identifiers and authentication information over HTTPS. Its operator can read the records; HTTPS protects transport, rather than hiding records from the server.

Enabled server workflows can send episode progress or notes. Hosted transcription sends selected audio and job information, including language and recording identity, to the server you enroll. Its operator controls records, backups and additional processors. Cancelling a job or disconnecting does not erase every server copy.

Optional iCloud Mail import

Your device uses your iCloud address and app-specific password to connect to Apple's mail service over TLS and list recent inbox messages for you to select. The address is saved in app settings and the password in Keychain. Listing and importing do not mark messages read, move them or delete them from the mailbox.

Removing the connection removes the saved address and credential. Imported messages remain in your library until separately removed. Apple's rules govern the mailbox.

Optional Gmail newsletter reading

When you choose to connect Gmail, Marginalia requests Google’s Gmail read-only permission. This permission can view email messages and settings. Marginalia uses it to show labels, list recent message information within a label and open an issue you select. Browsing and saving do not mark mail read, change labels, archive, send or delete messages. Marginalia does not scan your whole mailbox in the background.

Sign-in is handled by Google in a system browser. The shared Google access and refresh tokens, verified account identity and granted feature permissions are held in this device’s Keychain. Gmail and YouTube use the same Google connection when you enable both. Listing results and previews remain temporary and are cleared when the app enters the background or the connection changes; these previews are not automatically added to your library.

Choosing Save retains the selected issue’s original MIME data, extracted reader text and available message metadata in your library. The original message can include attachments and header information. Saved issues can enter enabled iCloud sync, nearby pairing or a home-server connection, and can appear in exports and device backups as described above. Only save issues you want to retain through these features. Disconnecting Google does not remove separately saved issues or copies already received elsewhere; remove library records separately and review the retention and deletion section below.

Agents you approve can read saved issues within the permissions you grant, which can cover more than one library item. Depending on the connection, content can pass through Marginalia Relay and the agent’s provider, or be sent to a hosted AI service for a feature you enable. Google tokens and temporary Gmail browsing lists are not automatically sent to agents or AI. Review an agent’s permissions and the processing terms of its provider before enabling that connection; revoke access in Connected agents when it is no longer wanted. LUFF does not use Google Workspace data to train general-purpose AI models.

Marginalia’s use of information received from Google Workspace APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google Workspace data may be used or transferred only for the permitted user-facing purposes described here, not for advertising, sale to data brokers or general-purpose model training. This policy also governs LUFF’s agents and processors; it is not a claim that Marginalia technically controls every third-party service a person connects.

Disconnect Google removes the shared credential on this device and requests revocation from Google for both Gmail and YouTube. If revocation cannot be confirmed, Marginalia directs you to review access in your Google Account. Google’s handling of sign-in and Gmail data is described in Google’s Privacy Policy.

Optional YouTube account browsing

Marginalia uses YouTube API Services. Connecting YouTube is optional and requests read-only access to browse your channel, subscriptions, playlists and video metadata, including identifiers, titles and descriptions where returned. YouTube browsing uses its YouTube read-only permission; Gmail read-only access is requested only if you explicitly enable Gmail. When both features are enabled, they use the same Google connection. Neither connection changes your YouTube subscriptions, playlists or videos. Availability depends on your release and device.

You sign in with Google in the system browser. Your device communicates directly with Google to exchange and refresh authorization tokens and request account information. Tokens use this device's Keychain; this connection does not send them through Marginalia Relay. Google controls its sign-in session and cookies. The account browser displays API results from temporary memory, rather than automatically copying its lists, titles or descriptions into library history.

When you save a video selected through the API, its identifier, title, channel and connected-account identity are kept in a separate, revocable provider cache. Library history retains an opaque reference rather than those API fields. Each cached observation expires within seven days unless renewed through the same connected Google account. Receiving a synchronized copy does not extend that deadline. Expiry and revocation are checked before display, playback and foreground use; unavailable provider data requires reconnection. Your own notes remain available.

Provider cache files are excluded from Apple device backups before they are written. Their raw contents do not enter Marginalia's ordinary operation history, immutable asset store, portable exports or full-library backups. Restoring a library without the cache can leave a reference that needs reconnection, while preserving personal notes. We cannot remove copies in earlier operating-system snapshots or promise immediate physical erasure on a suspended or offline device.

Enabled sync can exchange these attachments separately with compatible devices: through a dedicated private CloudKit zone, an encrypted nearby transfer, or an authenticated home-server connection that supports provider attachments. This mutable channel carries API metadata and opaque grant, expiry and revision information; it does not carry Google credentials. A home-server operator can read metadata it receives. On Linux or other operator-managed servers, the operator must exclude the provider cache from backups and snapshots; the app cannot enforce that server backup policy. Older connections omit provider attachments. Revocation takes priority over older copies when devices reconnect, and expiry prevents continued use while offline.

Disconnect Google removes the shared credential on this device, clears its account lists, revokes the connected account's local provider grant and requests revocation from Google for enabled Gmail and YouTube access. The app reports when Google's revocation cannot be confirmed. Local grant revocation prevents an older synced copy from restoring access and propagates through supported sync. It does not revoke unrelated Google accounts. You can also revoke access through Google's security settings. Contact Support about privacy questions or deletion requests.

Links and titles you supply independently, your personal notes and caption files you deliberately import remain ordinary library content. They can appear in enabled sync, exports and backups and are not removed merely because you disconnect YouTube. Deleting Marginalia records does not delete data held by YouTube.

The account connection does not automatically send Google tokens or browsing lists to agents or AI. Personal library records can be read within the permissions you grant to agents; provider metadata follows the cache and access limits above. LUFF does not use your library content to train models. Google's handling of sign-in and YouTube information is described in Google's Privacy Policy.

YouTube playback and supplied captions

Before the video eligibility check, Marginalia asks you to agree to this Privacy policy and the applicable YouTube terms. Before each in-app playback, supported releases send the video identifier to Google's YouTube Data API. Embedding requires a current response explicitly identifying the video as not Made for Kids. Made for Kids videos, an unknown status or a failed check use external playback instead.

On supported iOS devices, this request uses your connected account's read-only authorization. Supported Mac releases can use an optional API key you configure on the device. A configured key is stored in this device's Keychain, separate from library sync and backups. The check result is held temporarily rather than saved to your library. Feature availability depends on the release and device.

Opening the embedded player contacts YouTube even without an account connection. Google and YouTube receive information needed to provide playback, including the requested video and ordinary network and device information, and can collect player activity, serve advertisements or use cookies and similar technologies. Marginalia uses a nonpersistent web-data store for the player; this does not determine Google's own records or retention. Google's Privacy Policy applies to this processing.

You can deliberately import an SRT or VTT caption file for a saved video reference. Marginalia retains the supplied file and its transcript version; cue notes can retain your chosen quotation and video time. Source information you supply yourself remains ordinary library content; a source selected through the API uses the separate provider reference described above. Viewer sign-in does not provide automatic caption downloading. Imported captions and notes can be synced or read by agents within the permissions you grant. Disconnecting YouTube does not delete these separately supplied files or notes.

Agents and sealed relay traffic

An agent you approve can read or write information within its permissions, such as sources, notes and results. Access can cover more than one item. Review the permission you grant.

For the sealed bridge, request content is encrypted to your library's key. The relay forwards opaque content but handles connection information: library or tunnel identifiers, device information, a secret hash, public keys, push delivery details, usage counts and encrypted queued requests. Network infrastructure can receive IP addresses and request times.

The sealed queue holds up to 200 requests. Delivered entries are removed; entries older than seven days are discarded during later queue activity. This is logical expiry with activity-driven cleanup, rather than physical erasure at an exact seven-day deadline.

Chat connections with readable forwarding

OAuth chat connections send requests and library results through Marginalia Relay. The relay can read this traffic while forwarding it using the agent permission approved on your device. The chat provider receives information returned within that permission. A reachable library device is needed for live requests.

The relay stores client registrations, authorization and grant records, token records, device keys and routing identifiers. Access tokens expire after one hour and refresh tokens after thirty days. Revocation invalidates the relevant grant. Expiry and revocation end access; they do not remove every associated record, log, backup or copy held by the chat provider. That provider's privacy rules also apply.

Optional Marginalia Hosted Agent

Hosted Agent is off unless you enable it. For an answer or summary, the relay processes your instruction, the selected item's title and up to 40,000 characters of its text through Cloudflare Workers AI, currently using Llama 3.3. This scoped workflow does not give the model access to the rest of your library. The answer returns to your device and can be saved in the library.

The relay application handles readable chat and hosted-answer content during the request; it does not save those request bodies, prompts or answers in durable storage. It retains connection configuration, scoped credentials and usage counts. Disabling Hosted Agent removes its hosted credentials; monthly usage records remain.

Cloudflare's Workers AI data terms state that Customer Content is not used to train models or improve services unless explicit consent is given. LUFF does not use your library content to train models. This is not a zero-retention promise for network, security or provider records. Read the feature notice and approve sharing before sending personal information to hosted AI or a chat provider.

Website forms and support

Launch forms save your email and consent, with separately chosen feedback, research consent, TestFlight invitation requests and ambassador applications. Contact and feature forms save what you submit. Responses are kept in a private Cloudflare database. Your private removal link removes the corresponding active response; anyone holding it can use it, so keep it private.

Launch consent permits one LUFF launch-and-pricing email, with no newsletter or follow-ups. TestFlight invitations need separate permission and share your email with Apple. Removing a website request does not remove accepted TestFlight membership; use Stop Testing in TestFlight. Unconverted launch responses are kept for up to twelve months after the 1.0 launch, then removed. Closed feature requests are removed within twelve months of closure unless you remove them earlier.

Form abuse controls use hourly rotating IP hashes that expire after two hours, with cleanup on subsequent writes. Infrastructure records are separate. Fonts are served locally. LUFF does not integrate advertising or session-replay SDKs into the app or site. YouTube's embedded player can serve advertisements and collect information as described above. LUFF does not sell your personal information or use it for cross-context advertising.

Support receives the contact details, message and diagnostics you choose to send. The public email address uses Apple's iCloud Mail infrastructure; the contact form uses Cloudflare. Send only what is needed, without passwords, tokens, private connection addresses or a full library.

Purposes, providers and international processing

We process information to perform the actions you choose: retrieving content, browsing connected YouTube lists and opening video playback, syncing, connecting approved agents, generating requested results, sending the single launch message or optional invitation, responding to support and protecting services against abuse. Apple, Google/YouTube, Cloudflare, publishers and the devices, servers, agents or chat providers you choose receive information as described above. Relevant records may be disclosed when legally required or needed to address security incidents or protect rights.

Where European or UK data-protection law applies, LUFF's processing bases are performance of the service you request, consent for optional launch email and research, legitimate interests in responding to inquiries and keeping services secure, and legal obligations where applicable. Optional information is not required for local use. Declining a connection or consent prevents that optional feature or message.

LUFF is based in the United States. Providers can process information in the United States and other countries where they operate. Cloudflare's Data Processing Addendum describes applicable transfer safeguards, including standard contractual clauses for restricted transfers. Contact us about the arrangements relevant to your request. Apple and independently chosen providers have their own transfer arrangements.

See Apple's Privacy Policy, Google's Privacy Policy, Cloudflare's Privacy Policy and your chosen provider's policy. These do not replace LUFF's responsibility for its own processing.

Retention, deletion and withdrawing permission

Local records remain in your library and its copies until removed through the relevant controls. Item deletion hides the current entry and records deletion in library history. Full backups can contain history and deleted content. Deleting an item, uninstalling, stopping sync, disconnecting and deleting a backup are separate actions.

Turning off connections, revoking agent permissions and removing a mail connection stop associated future access. They do not retract information already received elsewhere. iCloud copies, Apple backups, paired-device copies, exports and provider records need separate handling through their operator's controls.

Relay connection metadata, client registrations, grants and monthly usage records have no automatic age-based purge. Some records are removed through the specific revocation or disable paths above. Other records remain in service storage until removed through service maintenance or an applicable deletion request. The sealed queue rule and token-access expiry are separate from storage retention.

Support and contact records are kept as needed to answer inquiries, follow up and address security or legal obligations. There is no fixed automatic expiry. Use your private website removal link or contact Support to request removal of LUFF-held information. We assess requests against relevant records and applicable law, including any lawful need to retain limited information.

Provider backups can preserve earlier copies after active deletion. Cloudflare D1 recovery history lasts seven or thirty days depending on the plan. Other infrastructure and provider records follow their applicable retention rules. Active removal is not immediate erasure of all backups; no universal deletion deadline is promised.

Privacy requests and regional rights

Contact Support to request access, correction or deletion of LUFF-held information, withdraw consent or ask about retention. Where applicable law provides them, you can request portability or restriction, object to processing and complain to your local data-protection authority. Withdrawal does not change the lawfulness of earlier processing. We may request proportionate verification before acting.

LUFF does not use this information to make automated decisions with legal or similarly significant effects. Independently controlled records may require a request to Apple, a publisher, your own server or a chat provider. Parents or guardians can contact us about a child's information without sending private library content or credentials.

Updates and contact

This page shows its version and effective date. Material changes will be explained where notice is required. A policy update does not itself authorize new sharing that requires permission.

Contact LUFF LLC through Support, support@luff.works or the contact form. The Terms & conditions describe the App Store license and optional services.