Privacy Policy
marginal.sh (“we”, “us”, “our”) provides an email marketing MCP server for AI agents at marginal.sh. This policy explains what information we collect, how we use it, and the choices you have when you create an account or connect an MCP client.
Information we collect
- Account information — Email address, password (stored hashed), and session data used to sign you in and operate your dashboard.
- API keys — Keys you create to authenticate MCP and API requests. We store a hashed form and display prefixes; full keys are shown only once at creation.
- Campaign and experiment data — Subject lines, campaign briefs, variant metadata, recipient email addresses and optional names, destination URLs, and experiment configuration you submit through the dashboard, MCP tools, or CLI.
- Engagement data — Open and click events, tracking tokens, timestamps, and related attribution data generated when messages are sent through the service.
- Usage data — Plan limits, experiment counts, send volumes, and technical logs (IP address, request timestamps, error diagnostics) for security, billing, and reliability.
- AI processing — When you use variant generation, campaign content may be sent to our AI provider to produce subject line suggestions. We do not use your content to train third-party models beyond what that provider’s API terms allow.
How we use information
- Provide hosted MCP tools, sending, tracking, and experiment results
- Authenticate accounts, API keys, and MCP connections
- Enforce plan limits and prevent abuse
- Improve reliability and comply with legal obligations
Recipient email addresses
When you run campaigns, you provide recipient email addresses. You are responsible for having a lawful basis to contact those recipients (for example consent or a legitimate interest where permitted). We process recipient data only to deliver your campaigns, measure engagement, and operate the service on your instructions.
Recipients who wish to stop receiving messages from a marginal customer should contact that sender directly. If you believe a message was sent in error through marginal, contact us at [email protected].
How we share information
We do not sell personal information. We share data only with:
- Service providers — Infrastructure we use to host the service, store data, deliver email, run AI features, and operate tracking endpoints
- Legal requirements — When required by law or to protect rights, safety, and security
Data retention
We retain account and experiment data while your account is active and as needed to provide the service, meet legal obligations, and resolve disputes. You may request deletion of your account data by contacting us.
Your choices
- Revoke or rotate API keys at any time from your dashboard
- Sign out to end your browser session
- Request access to or deletion of your account data by emailing [email protected]
Security
We use HTTPS, access controls, and industry-standard practices to protect your data. No method of transmission or storage is completely secure.
Children
marginal.sh is not intended for users under 13 (or the minimum age required in your country). We do not knowingly collect data from children.
Changes
We may update this policy from time to time. We will post the revised version on this page and update the effective date above.
Contact
Questions about this policy or your data: [email protected]