marshal Privacy Policy
Operated by emefa LLC
Last updated: August 8, 2026
1. Introduction
marshal is a group communication and coordination application operated by emefa LLC ("marshal," "we," "us," or "our"). This Privacy Policy explains what personal information we collect, how we use and share it, and the choices and rights you have. It applies to the marshal mobile and web applications and to the website at marshalapp.us.
marshal is designed for community groups — such as homeowners associations, fraternities and sororities, religious organizations, and civic clubs. When you use marshal as a member of a group, the group — or the organization that owns it — generally acts as the controller of member data (acting through its administrators and officers), and marshal acts as a processor providing the service on its behalf. For your own account information, emefa LLC acts as the controller.
2. Information We Collect
Information you provide:
- Account and identity: email address, password (stored by our authentication provider, never in plain text), display name, and — if you choose to provide them — profile photo, phone number, and city.
- Group activity: the groups you belong to, your role(s) in each group (member, an officer role such as treasurer, secretary, or events coordinator, president/chair, or owner), messages and announcements you post, direct messages you send (kept in a separate, participant-only store), event RSVPs, attendance records (an officer can record attendance for an event; for group video meetings, attendance may also be recorded automatically from who was present in the call when the meeting ends), poll responses (your individual vote is private — recorded only to enforce one vote per person and to honor deletion, and never shown to other members or administrators; results are counts only), and photos you upload (including any caption you add to a photo).
- Group dues / payments: if your group collects dues, we store payment records (the amount, currency, method label such as "Venmo," status, an optional note, and who recorded it), the group's own payment-method handles that the group's owner or a member with the treasurer (payment-collection) role configures, and the group's dues settings. marshal is non-custodial: we do not process, route, or hold any money, and we store no card, bank-account, or other payment-instrument details. You pay your group directly through the external app it lists (for example Venmo, Zelle, Cash App, PayPal, or Sendwave); marshal only records the payment you report. Where a payment provider offers a public payment page, marshal shows a link built from your group's configured handle (or a reusable payment link your group stored) — the payment itself happens entirely on the provider's site or app, and marshal cannot see or confirm whether a payment occurred; payment records in marshal are member-reported and treasurer-reconciled. Every change to a group's payment handles is logged, and the group's owner and president are notified in-app. See the "Group payments / dues" subsection below for who can see this information.
- Consent records: your privacy preferences, age attestation, and the date and policy version at the time you consented.
Information collected automatically:
- Device and technical data: device push-notification tokens, app version, and basic usage metadata needed to operate the service.
- Service-usage measurements (for billing and plan limits): to apply your plan's allowances and bill correctly, we record aggregate usage measurements — such as the number of meeting/call minutes used, AI meeting-notes minutes generated, participant counts in calls, the number of groups you own, and storage used. These are counts and durations associated with your billing account and group; they are not the content of your meetings, messages, or files. If you buy a consumable "minute pack," we record the purchase and how much of it has been used.
- IP address: when you sign up on the web, your IP address is processed on marshal's own servers to confirm the service is available in your location and to help prevent abuse; it is not shared with third parties for that purpose and is not retained afterward. Separately, limited security-audit records may include the IP address associated with a sensitive action (see Data Retention).
Communications and meetings:
- Audio/video: if you join a marshal call, real-time audio and video are routed through our calling provider (LiveKit). If a meeting is recorded, the recording is stored within marshal's own infrastructure (see Security). AI meeting minutes are available on certain plans: when an administrator chooses to generate minutes for a recording, that recording's audio is sent to our transcription provider (Deepgram) and the resulting transcript to our summarization provider (Anthropic). As part of generating minutes, Deepgram also performs automated speaker separation — labeling which participant is speaking — so the minutes can attribute what was said. You are shown an in-app notice identifying these third-party AI services before this processing runs.
- Live captions: if a participant turns on live captions during a call, the call's audio is streamed to our transcription provider (Deepgram) in real time to generate on-screen captions. Any participant can turn captions on, and while they are on, all speakers' audio is transcribed to produce them. Captions are shown live to the participant viewing them and are not stored as a saved transcript.
Biometric authentication: if you enable Face ID or Touch ID to sign in, this uses your device's built-in authentication. No biometric identifier is collected by or transmitted to marshal.
3. Sensitive Information
Some information marshal holds can imply sensitive characteristics even though we do not ask for them directly. For example, membership in a religious group can imply religious belief, and membership in some clubs can imply other affiliations. We treat membership and group data with heightened care: a group's records are restricted to that group's members through our access controls. Group files and recorded meetings can be retrieved only by that group's members, through short-lived, membership-checked links in the app. Gallery photos, announcement images, and chat images are moving to the same short-lived, membership-checked links — the app already retrieves them that way — but until that migration completes, older image links remain long-lived; they are unguessable and shared only within your group.
4. How We Use Information
We use personal information to:
- provide, operate, and maintain the marshal service;
- create and manage your account and group memberships;
- deliver messages, announcements, events, polls, calls, and notifications;
- maintain the dues ledger and self-reported payment records where a group or organization uses that feature (marshal never processes the payments themselves);
- measure usage against your plan's allowances and administer your subscription, plan changes, minute packs, and any overage;
- provide optional AI-assisted features (announcement drafting, and AI meeting minutes generated from recordings) when you or your group's administrators choose to use them;
- maintain security, prevent abuse, and keep audit logs of sensitive actions;
- comply with legal obligations.
5. Legal Bases (EU/EEA and UK users)
Where the GDPR or UK GDPR applies, we rely on:
- Contract — processing necessary to provide the service you signed up for;
- Consent — for AI processing of your content and any optional features that ask for it;
- Legitimate interests — for security, abuse prevention, and basic service operation, balanced against your rights.
6. How We Share Information
We share information only as described here:
- With your group: content you post to a group and your profile are visible to other members and administrators of that group. Direct messages are different — they are visible only to you and the recipient. An administrator or moderator can access a direct message only when you report it for abuse; that access is logged.
- Service providers (sub-processors): we use trusted third parties to operate marshal. Each processes data only as needed to provide its service:
- Google Firebase — core infrastructure (database, storage, authentication, hosting, functions).
- Google Cloud SQL (PostgreSQL) — database infrastructure, hosted in the United States, that stores durable operational records such as security-audit, payment, and access-control records.
- Stripe — payment processing for marshal's own paid-plan subscriptions (web checkout). This is not used for group member dues, which are non-custodial (see "Group payments / dues" below).
- RevenueCat — in-app-purchase subscription management (Apple in-app purchases for international individual subscribers).
- LiveKit — real-time voice and video calling.
- Deepgram — real-time and recorded transcription for AI minutes and live captions. A recording's audio is sent when an administrator generates minutes, and a call's live audio is streamed while captions are turned on; in both cases this audio is not used to train Deepgram's models — marshal sets Deepgram's model-training opt-out on every individual request and enforces this in code, with an automated check that fails our build if any request path ever omits it.
- Anthropic — AI assistance, including announcement drafting and AI-minutes summarization that you or your administrators invoke, and automated support and operational assistance (for example, drafting responses to support requests you submit).
- Expo — push-notification delivery.
- Postmark — email delivery. When marshal sends you email (for example, account or support messages, or a copy of your data you request), Postmark processes the recipient email address and the contents of that message.
- Sentry (diagnostics) — crash/error diagnostics. This is configured but not currently active; if enabled, only privacy-reduced diagnostic data (no account identifiers) would be processed.
- Google Maps / Google Places (independent third party): when you type an address (for example, an event location or a profile city) or view a map, that address or the approximate coordinates are sent to Google Maps Platform to provide address autocomplete and mapping. Google acts as an independent controller for this data under its own privacy policy, not as a marshal sub-processor.
- Legal and safety: we may disclose information if required by law or to protect the rights, safety, or property of users, the public, or emefa LLC.
We do not sell your personal information, and we do not share it for cross-context behavioral advertising.
Group payments / dues. If your group collects dues, the way we share that information is specific and limited:
- What we hold: the payment records members report, the group's own external payment-method handles, and the group's dues settings (amount, cycle, due day). marshal does not process or hold money and stores no card details — we are a directory of your group's payment handles plus a ledger of self-reported payments.
- Paying through an external app is a separate relationship. When you pay your group, you do so directly inside a third-party payment app the group lists — for example Venmo, Zelle, Cash App, PayPal, Sendwave, or a mobile-money service. Those apps are independent third parties, not marshal sub-processors: marshal sends them no information about you and handles none of the funds. Your use of them is governed by those companies' own privacy policies and terms, not this one.
- Who can see your dues information: you can always see your own records. Your group's treasurer or administrators (those with payment-collection permission) can see the dues roster to reconcile it. If — and only if — the group owner turns on the optional dues transparency board (it is OFF by default), other members can see a paid/unpaid status only view; amounts are never shown on that board.
- Notifications: dues reminders and payment notifications never put a payment amount on a lock-screen notification.
7. Data Retention
We keep personal information only as long as needed for the purposes described above. Several categories are deleted automatically by the system once their retention window passes:
- Account data: for the lifetime of your account, plus 30 days after you ask us to delete it — so you can recover from an accidental deletion. When you delete your own account from your profile settings, your account is scheduled for permanent erasure 30 days later; you stay signed in and can cancel any time before then. If a deletion is instead carried out by our support team on your behalf, your account is first disabled and then permanently erased after a 30-day restore window, during which support can reverse the deletion at your request. What happens to what you contributed:
- Media you uploaded — the photos, files, and post and message images we can identify as yours — is deleted, unless it is being preserved under a legal hold or has been quarantined by a group moderator (reporting content does not by itself preserve it). Images that identify a group or organization rather than a person, such as a group's cover photo or an organization's logo, stay with that group or organization. If we cannot locate a file in order to delete it, we keep the item and its link to you so it can be found and removed later, and we record that the erasure was incomplete.
- Posts you wrote — announcements, polls, and messages, including direct messages — are kept with your name removed. Your individual poll votes and event RSVPs are deleted, so any tally that included them changes accordingly. Removing your name is pseudonymization, not anonymization: an internal account identifier may remain on some records.
- Your group's governance and financial records — such as meeting minutes, recordings, attendance and dues — are kept as they are, including where they name you or contain your recorded voice, because a group's record of its own meetings and money must survive a member leaving (see “Meeting recordings” and “AI meeting minutes” below for how long those are kept).
- Chat messages: retained for up to two years (about 730 days), then deleted automatically.
- Notifications: approximately 90 days, then deleted automatically.
- Meeting recordings: the recorded audio is retained per your group's plan tier (approximately 30 days, 1 year, or up to 7 years depending on tier), then deleted automatically at the end of that window; earlier deletion can be requested through marshal support.
- Verbatim transcripts: when AI minutes are generated, the underlying word-for-word transcript is currently stored together with those minutes and retained on the same basis as the minutes; if the minutes are deleted, the transcript is deleted with them.
- AI meeting minutes (the summary): the AI-generated minutes serve as your group's official record of the meeting and are not deleted automatically; they are kept as the group's governance record, and a group can request deletion by contacting us (see Contact Us).
- Security and audit logs: routine operational copies are kept approximately 90 days; a durable security-audit record (which may include the acting account and IP address) is retained longer for security and legal-compliance purposes.
- Financial records: retained as required by applicable tax and accounting law even after account deletion.
Some records that a group needs for its governance (such as attendance) and financial records are retained under the group's or our legitimate interest or legal obligation. Where your account has been deleted, these records are kept as they stand — which in some cases still includes your name, for example on a dues record or in minutes that record what you said or decided.
8. Your Rights
Depending on where you live, you may have the right to access, correct, delete, or export your personal information, to object to or restrict certain processing, and to withdraw consent. marshal provides built-in tools to export your data (a machine-readable copy) and to delete your account from your profile settings. To exercise other rights, contact us at privacy@emefa.us.
If you are in the EU/EEA or the UK, you also have the right to lodge a complaint with your local data protection supervisory authority (for example, the Information Commissioner's Office (ICO) in the UK, or the Data Protection Commission in Ireland).
California (CCPA/CPRA): you have the right to know, delete, and correct your personal information, and to opt out of "sale" or "sharing." marshal does not sell or share personal information or engage in cross-context behavioral advertising, so there is nothing to opt out of.
9. Children
marshal is not directed to children under 13, and we do not knowingly collect personal information from children under 13. We require an age attestation at sign-up. If you believe a child under 13 has provided us personal information, contact privacy@emefa.us and we will delete it.
10. International Transfers
marshal's infrastructure is hosted in the United States. If you access marshal from outside the U.S., your information will be transferred to and processed in the U.S. Where required, we are putting appropriate transfer safeguards (such as Standard Contractual Clauses) in place with our processors for these transfers.
11. Security
We use industry-standard measures to protect your information, including access controls that restrict group records to group members; group files and recordings served only through short-lived, membership-checked links in the app (gallery, announcement, and chat images are being migrated to the same links); encrypted transport; append-only audit logging of sensitive actions; least-privilege service accounts; and secrets management for credentials. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
12. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date and, where appropriate, notify you in the app. Continued use of marshal after changes take effect constitutes acceptance of the revised policy.
13. Contact Us
For privacy questions or to exercise your rights:
emefa LLC, 10601 Clarence Dr., Suite 250, Frisco, TX 75033 — privacy@emefa.us