Marginota Privacy Policy
Effective date: September 8, 2026
Marginota is a language-learning reader operated by Paul Wright (“we,” “us,” or “our”), available at https://marginota.com. This policy explains how we collect, use, store, and share information when you use our website or installed progressive web app.
Information we collect
When you create an account, our authentication provider, Clerk, processes account information such as your email address, authentication credentials, and account identifier.
If you sign in with Google, Clerk receives basic Google account information, which may include your name, email address, profile picture, and Google account identifier. We use this information to create and authenticate your Marginota account. Marginota does not request access to your Gmail messages, Google Drive files, contacts, or calendar.
Marginota stores articles, language preferences, vocabulary lookups, translations, contextual sentences, and quiz progress in your browser. When you are signed in, vocabulary records—including contextual sentences and review progress—are also stored on our servers through our database provider to support synchronization across devices.
When you request a translation, we process the selected word, phrase, or sentence, its surrounding sentence, and the selected language. When you import an article by URL, our server retrieves and processes that page.
Our hosting and authentication providers may process technical information such as IP addresses, browser and device information, request timestamps, and security logs. We also record usage counts associated with your account to enforce service limits.
How we use information
We use information to create accounts and authenticate users; import articles and provide contextual translations; save vocabulary and schedule reviews; synchronize vocabulary and progress across devices; enforce usage limits, prevent abuse, and maintain the service; and respond to support and privacy requests.
We do not sell personal information or use Google account information for advertising.
Service providers and sharing
We use Clerk for account management, authentication, and sign-in communications; Vercel for website hosting and server-side request processing; Upstash for synchronized vocabulary, usage counters, and cached translation results; and Anthropic for translations and language explanations.
For translations that require AI processing, we send the requested text and language context to Anthropic. Our translation requests do not include your Google account profile or email address. Text you choose to translate may itself contain personal information.
Translation results may be cached and reused for identical requests. Cached results are not keyed to your account.
When you import a URL, the source website receives a request from our server. External websites have their own privacy practices.
We may also disclose information when required by law or reasonably necessary to protect users, investigate abuse, or secure the service.
Google user data
We use Google account information only to provide account and authentication functionality described in this policy.
Marginota’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements.
We do not use Google account information to train AI models or send it to our translation provider.
Cookies and local storage
Marginota and its authentication provider use cookies and similar technologies to maintain sign-in sessions and support security.
We use browser storage to save articles, vocabulary, review progress, and preferences. The installed app also caches resources to support loading and offline functionality.
Clearing browser or app storage removes locally stored information and may sign you out. It does not delete server-side account information or synchronized vocabulary, which may be downloaded again when you sign in.
Retention
Locally stored information remains until you remove it through the app, clear your browser’s site data, or otherwise delete the relevant device storage.
Synchronized vocabulary does not currently have an automatic expiration period. Contact us to request deletion of your account and associated server-side learning data.
Daily usage counters expire approximately two days after their last update. Monthly counters expire approximately 40 days after their last update. Cached translation results expire after 30 days without reuse; reuse restarts that period.
Service providers may retain operational logs or backups under their own retention practices. Some information may be retained where needed for security, resolving disputes, or legal obligations.
Your choices and requests
You can choose whether to sign in with Google. You can revoke Marginota’s Google connection through your Google Account’s third-party connections settings. Revoking access does not automatically delete information already stored by Marginota.
To request access, correction, or deletion of your personal information, contact me@paulwright.dev. We may need to verify your identity before acting on a request.
Depending on where you live, you may have additional rights, including rights to object to processing, request restrictions or portability, or complain to a relevant privacy authority.
Security and international processing
We use HTTPS and authenticated access controls to help protect information. No method of storage or transmission is completely secure.
Our service providers may process information in countries other than your own, where data protection laws may differ.
Changes and contact
We may update this policy as the service changes. We will post updates here and revise the effective date. Where required, we will provide additional notice of material changes.
For privacy questions or requests, contact Paul Wright, Marginota, at me@paulwright.dev.