LEGAL

Privacy Policy

LAUNCH VERSION · LAST UPDATED AUGUST 2026

Plain-language launch version. It describes what the product actually does today; a counsel-reviewed policy will replace it as the product matures, and account holders will be notified before material changes. We do not claim certifications or regulatory compliance frameworks we have not completed.

1. The core position

MarginFuse never sees prompts or responses - identifiers, usage metadata, costs, and revenue only.

This is enforced by architecture, not by a setting: the SDK has no field for prompt or response content, so there is nothing to accidentally enable.

2. What we collect

  • Your account: name, email address, hashed password, and workspace membership.
  • Revenue data you connect: customers, plans, subscriptions, invoices, refunds and credits from your Stripe account, read with a restricted read-only credential you provide and can revoke at any time.
  • AI usage metadata you send: customer identifier, feature name, provider, model, token/usage counts, costs, timestamps, and policy decision context.
  • Operational records: activity history of consequential configuration changes, policy decisions and their explanations, and internal product analytics about how the MarginFuse dashboard itself is used. We do not send your financial data to third-party analytics vendors.

3. What we never collect

  • Prompts, model responses, or any of your customers’ content.
  • Your Stripe secret key with write access - the connection is read-only by instruction and scope.
  • More personal data about your end customers than the identifier you choose to send us.

4. How we use it

Solely to provide the product: attributing cost to customers, plans and features; computing profitability; evaluating and explaining policies; alerting you; and billing your MarginFuse subscription. We do not sell your data or use your financial data for advertising.

5. Isolation, secrets and retention

Workspace and project data are isolated from other customers. API keys are stored hashed and displayed only once at creation; connected credentials are stored encrypted and are never shown back in full. Detailed history is retained according to your plan’s retention policy, and we warn you before a downgrade makes data inaccessible. Decision explanations are preserved without preserving unnecessary customer content.

6. Deletion and revocation

You can disconnect Stripe, revoke API keys, and delete projects or your whole workspace from settings. Deletion is confirmed with an explicit statement of what is removed and is permanent, except for the minimal billing and legal records we are required to keep about our own subscription relationship with you.

7. Subprocessors and email

We run on cloud infrastructure and use Stripe for our own billing and an email delivery provider for transactional email (verification, password reset, alerts you enable). Alert emails avoid including sensitive customer information. Questions or requests: see the contact section of the Terms.