Trust & Transparency
Here is what marshal holds, how long it keeps each kind of data, the providers it relies on, and the controls you have. The Privacy Policy is the binding version.
Last updated: July 25, 2026
What we collect & how long we keep it
marshal keeps only what a group needs to run, and most of it is deleted automatically on a schedule:
| Data | Kept for |
|---|---|
| Profile & account (name, email, phone) | While your account is active |
| Chat messages | ~2 years, then auto-deleted |
| Meeting recordings (audio only) | 30 days to 7 years by your group's plan — in a group meeting, recorded only with every participant's consent |
| Poll votes | Private — only you can see your vote, not even group admins; results are counts only (stored against your account to enforce one-vote-per-person and honor deletion, but never shown to anyone else) |
| Attendance & meeting minutes | Kept as your group's governance record until the group deletes them or the group is closed |
| Dues & payment records | Kept as a financial record for as long as your group maintains it (and any period the law requires) — marshal never stores your card details |
| Notifications | 90 days |
| Feature-usage measurements (call minutes, AI-notes minutes, storage totals) | Counts and durations only — never the content of meetings, messages, or files; kept with your billing account to apply your plan’s allowances |
| Deleted accounts | Deleting your account yourself removes it from the live service promptly; if you ask support to delete it, it is held 30 days first. Residual copies in encrypted backups and any legally-required security-audit records are purged on their normal cycle. |
How we protect it
- The server enforces access, not the client app. Database security rules and backend permission checks decide who can read or change what, so a modified app can't bypass them.
- In a group meeting, recording starts only after every participant present has agreed to it — and consent is asked fresh for each recording, including for people who join late. Anyone can decline; if the host chooses to proceed with consenting participants only, each declining participant gets a clear choice to consent or leave before recording continues, and is never recorded without having been asked. An on-screen indicator stays visible the whole time recording is active. In a livestream broadcast, only the host's own audio is captured, with the host's consent.
- Poll votes are private: only the voter can see an individual vote, not even admins, and results are reported as counts. Votes are stored against your account to enforce one-vote-per-person and to honor deletion, but are never shown to anyone else.
- Dues are non-custodial. marshal never touches your money and stores no card numbers; you pay your group directly through the app it lists (Venmo, Zelle, Cash App, PayPal, a mobile-money service, and the like), under that app's terms.
- Lock-screen notifications show the group and the notification type. They never include the sender's name or message content.
- Recordings and folder files are served through access-checked, time-limited links rather than public URLs. Gallery photos, announcement images, and chat images are moving to the same time-limited links — the app already retrieves them that way — and until that migration completes, older image links remain long-lived, unguessable, and shared only within your group.
- Backend functions run with least-privilege permissions and rate limits to reduce abuse. No system is completely secure, and we don't claim otherwise — but the design keeps the blast radius of any one action small.
- Turning on live captions streams the call's audio to our transcription provider (Deepgram) to generate on-screen captions; any participant can turn captions on. Content sent to our transcription and AI providers is not used to train their models — for transcription, the opt-out is set on every individual request and enforced in code; for AI summaries, our provider's commercial API terms do not use customer content for training — and it is retained only transiently to perform the task.
- Data is encrypted in transit between your device and marshal, and encrypted at rest by our infrastructure providers. Because AI and transcription features require the service to process your content, marshal is not end-to-end encrypted.
If something goes wrong
If a security incident affects your personal data, we will investigate promptly and notify affected users and, where required, regulators without undue delay, as the law requires. Security researchers can report an issue any time via our Vulnerability Disclosure Policy.
Providers we work with
marshal uses a small set of specialized providers (sub-processors) to operate. We keep the list short and purpose-limited:
| Provider | What it does | Location |
|---|---|---|
| Google Firebase | Core infrastructure — database, file storage, sign-in, hosting, functions | United States |
| Google Cloud SQL (PostgreSQL) | Database for durable operational records (security-audit, payment, and access-control records) | United States |
| LiveKit | Real-time voice & video calling | United States |
| Deepgram | Transcription — for AI meeting minutes (when an admin generates them) and for live on-screen captions (call audio streamed in real time whenever any member turns captions on during a call) | United States |
| Anthropic (Claude) | AI features — announcement drafting, minutes summarization, and automated support and operations assistance | United States |
| Stripe | Billing for marshal's own paid plans (not member dues) | United States |
| RevenueCat | Manages Apple/Google in-app-purchase subscription entitlements (an independent company, not Apple) | United States |
| Expo | Push-notification delivery | United States |
| Postmark | Transactional email — invites, data exports, notifications | United States |
| Sentry | Crash/error diagnostics — configured to strip/minimize personal data; activated only if enabled | United States |
marshal also integrates Google Maps Platform (Maps and Places) to display maps and to autocomplete addresses you type. Google receives the addresses you enter and approximate (city-level) coordinates, and acts as an independent controller, not a marshal sub-processor.
External payment apps used for dues (Venmo, Zelle, Cash App, PayPal, Sendwave, mobile money, and similar) are not marshal sub-processors — those payments happen directly between you and the app. For data originating in the EU/EEA or UK, we are putting appropriate cross-border transfer safeguards (such as Standard Contractual Clauses) in place; the EU/EEA and UK are not part of our current launch regions until those are executed.
Ages
marshal is for people aged 13 and over; it is not directed to children under 13. Where a group meeting is recorded, all-participant consent and an on-screen recording indicator apply to every participant, including minors.
Intimate images shared without consent: marshal maintains a dedicated report-and-removal process, available to anyone — with or without a marshal account. How to report is set out in our Terms of Use (Acceptable Use) and in the app's profile menu. We remove verified reports within 48 hours and make reasonable efforts to remove identical copies.
Your rights & controls
- See what we hold — the "Your Data" view in Account & Security summarizes the data categories and how long each is kept.
- Export — get a portable, machine-readable copy of your data at any time.
- Delete — remove your account. Deleting it yourself from Account & Security removes it from the live service promptly; if you ask our support team to delete it, we hold it 30 days first. Residual copies in encrypted backups and any legally-required audit records are purged on their normal cycle.
- Protect sign-in — optional two-factor authentication and biometric app-lock.
- Location is private by default — your location is not shared with or shown to your group.
To exercise a right, use the in-app controls under Account & Security, or contact us at privacy@emefa.us.