Privacy Policy
Effective date: 10. April 2026
margin ("we", "our", "us") is a communication and organization platform operated from Denmark. This Privacy Policy explains what personal data we collect, why we collect it, how we process it, and your rights under the General Data Protection Regulation (GDPR).
By creating an account or using margin, you agree to the practices described in this policy.
1. Data Controller
The data controller is:
margin
Contact: hello@margin.chat
2. What Data We Collect
2.1 Account Information
When you create an account, we collect your email address, display name, and a hashed version of your password. We never store your password in plain text.
2.2 Messages and Content
margin handles messages differently depending on the context:
- Secret chats and secret groups are end-to-end encrypted. We cannot read their content. Encrypted message data is stored on our servers solely for delivery and synchronization.
- Channel messages and standard group messages are not end-to-end encrypted. They are transmitted over encrypted connections (TLS) and stored encrypted at rest on our servers, but are readable by the server for delivery purposes.
2.3 Usage and Connection Data
We collect basic technical data necessary for the service to function: IP addresses during active connections, login timestamps, and online/offline status. This data is used for session management, presence features, and security purposes.
2.4 Call Data
Voice and video calls use peer-to-peer (WebRTC) connections where possible, meaning audio and video streams flow directly between participants. For group calls, media is routed through our SFU (Selective Forwarding Unit) server for distribution but is not recorded or stored. We store basic call metadata (participants, timestamps, duration) for call history.
3. Why We Process Your Data (Legal Basis)
We process your personal data on the following legal bases under the GDPR:
- Contract performance (Art. 6(1)(b)): Processing necessary to provide the margin service to you — account management, message delivery, call functionality.
- Legitimate interest (Art. 6(1)(f)): Security measures, abuse prevention, and service improvements. Our legitimate interest does not override your fundamental rights.
- Legal obligation (Art. 6(1)(c)): Where we are required to retain data by applicable law.
- Consent (Art. 6(1)(a)): Where applicable, such as optional communications. You may withdraw consent at any time.
4. Data Storage and Security
All data is stored on servers located in the European Union, hosted by Hetzner Online GmbH in Germany. Data is encrypted in transit (TLS) and at rest. Secret chats and secret groups are additionally protected by end-to-end encryption, meaning only the participants can read them.
We implement appropriate technical and organizational measures to protect your data against unauthorized access, alteration, disclosure, or destruction.
5. Sub-processors
We use the following third-party service providers who may process personal data on our behalf:
| Provider | Purpose | Data Processed | Location |
|---|---|---|---|
| Hetzner Online GmbH | Server hosting and object storage | All service data | Germany (EU) |
| Scaleway (Iliad Group) | Transactional email delivery | Email addresses | France (EU) |
| Mollie B.V. | Payment processing and subscription management | Name, email address, billing and transaction data | Netherlands (EU) |
All sub-processors are located within the EU. No personal data is transferred outside the European Economic Area. Mollie acts as an independent data controller for payment data they collect directly; their privacy policy is available at mollie.com/privacy.
6. Data Retention
We retain your data for as long as your account is active. Messages and content remain stored until you or your organization's administrator deletes them, or until you delete your account. Upon account deletion, your personal data will be removed within 30 days, except where retention is required by law.
7. Your Rights
Under the GDPR, you have the following rights:
- Access: Request a copy of the personal data we hold about you.
- Rectification: Request correction of inaccurate data.
- Erasure: Request deletion of your data ("right to be forgotten").
- Restriction: Request that we limit how we process your data.
- Portability: Request your data in a structured, machine-readable format.
- Objection: Object to processing based on legitimate interest.
To exercise any of these rights, contact us at hello@margin.chat. We will respond within 30 days. You also have the right to lodge a complaint with the Danish Data Protection Agency (Datatilsynet) at datatilsynet.dk.
8. Cookies and Local Storage
margin uses session storage to maintain your authentication state. We do not use tracking cookies, advertising cookies, or any third-party analytics tools. No data is shared with advertisers.
9. Age Requirement
You must be at least 16 years old to use margin. We do not knowingly collect personal data from anyone under 16. If we become aware that a user is under 16, we will delete their account and data promptly.
10. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you through the margin application or by email. The effective date at the top of this document indicates when it was last updated.
11. Contact
If you have questions about this Privacy Policy or your personal data, contact us at:
hello@margin.chat