Legal
Privacy policy
Last updated September 27, 2026
This policy explains what Marlow collects, why we collect it, and the choices you have. We only collect what we need to run the platform, and we never sell customer data.
What we collect
- Account data from Auth0 — your email address and a unique identifier so we can recognize you.
- Project configuration you create in the console — project names, environment variable keys, workflow settings, integration metadata.
- Run data — ticket payloads, agent logs, and pull request URLs produced by each run.
- Operational telemetry — application logs, error reports and request metrics, retained no longer than 90 days.
What we don't collect
- We do not sell customer data to third parties.
- We do not train models on your private code or ticket contents.
- We do not run third-party advertising trackers on the console.
Where data lives
Operational data — organizations, projects, runs and the audit ledger — sits in a PostgreSQL database. Run logs and artifacts sit in S3-compatible object storage.
Agent code runs in isolated sandbox containers that are torn down at the end of each run unless you have explicitly enabled snapshotting.
Retention
- Run logs: 90 days.
- Composed agent prompts: 14 days.
- Sandbox snapshots (when enabled): newest 3 per project, 30 days max.
- Audit log: lifetime of the organization.
- Deleted organizations: purged within 30 days of deletion.
- Usage and billing records (identifiers, token counts and costs; no ticket or code content): kept after deletion, for accounting.
Your rights
Email privacy@getmarlowai.com for data access, deletion, or export. We respond within 30 days.