Marker
  • Product
  • Deployment
  • Pricing
  • Docs Guides and API reference Blog Writing on agent verification Team The people building Marker
Sign in Book Demo
  • Product
  • Deployment
  • Pricing
  • Docs
  • Blog
  • Team
Sign in Book Demo

Legal

Privacy Policy

Effective: July 24, 2026

This Privacy Policy explains how Marker AI, Inc., a Delaware corporation (“Marker,” “we,” “us,” or “our”), collects, uses, shares, and retains personal information when you visit our websites or use our hosted platform. It also explains the difference between the information we handle for our own purposes and the information we process on behalf of our business customers, which is governed by our agreement with that customer rather than by this policy. Section 2 describes that distinction and Section 14 describes how to make a request about your information.

Contents

  1. 1. Scope of This Policy
  2. 2. Customer Content: Information We Process for Our Customers
  3. 3. Personal Information We Collect
  4. 4. Where That Information Comes From
  5. 5. How We Use Personal Information
  6. 6. How We Share Personal Information
  7. 7. Service Providers We Use
  8. 8. Cookies and Similar Technologies
  9. 9. Communications and Marketing
  10. 10. Data Security
  11. 11. Data Retention
  12. 12. Where Data Is Processed and Stored
  13. 13. Marker Personnel Access
  14. 14. Your Choices and How to Make a Request
  15. 15. U.S. State Privacy Laws
  16. 16. Children’s Privacy
  17. 17. Self-Managed, On-Premises, and Air-Gapped Deployments
  18. 18. Changes to This Policy
  19. 19. How to Contact Us

1. Scope of This Policy

1.1 What this policy covers. This policy applies to the Marker websites at usemarker.ai and docs.usemarker.ai (the “Sites”), and to the hosted Marker platform at app.usemarker.ai and its application programming interface at api.usemarker.ai (the “Service”). Where this policy says “the Service and the Sites” it means both; where it says only one, it means only that one. Our Terms of Service draw the same distinction and state which of their provisions apply to a person who merely reads the Sites.

1.2 Who we are. Marker is an agent-verification platform. Our business customers connect their own artificial-intelligence voice and chat agents, run simulated conversations against them or ingest their real production conversations, and evaluate the resulting transcripts. Marker is a business-to-business service; it is not directed to consumers or to personal use.

1.3 Two distinct roles. We handle two different kinds of information, and the distinction matters. The first is information about site visitors, prospective customers, account holders, and their authorized users, which we collect and use for our own business purposes — running, securing, billing for, and supporting the Service. That information is the subject of this policy. The second is Customer Content: the conversation data our business customers put into their Marker organizations, which we process only under their instructions and under our agreement with them. Section 2 explains how Customer Content is handled and where to direct questions about it.

1.4 What this policy does not cover. This policy does not cover self-managed, on-premises, or air-gapped deployments of Marker software, which run inside the customer’s own environment and are licensed exclusively under a separately executed written agreement (see Section 17). It also does not cover third-party websites, models, carriers, or services that we link to or that a customer connects to the Service; those are governed by their own privacy policies.

1.5 Related documents. Your use of the Service is also governed by our Terms of Service. Details of what the Service does are described in our product documentation at docs.usemarker.ai, access to which is gated as described in Section 3.7, and the deployment options that run the software inside your own environment — including the air-gapped profile, which is the configuration designed to make no outbound network calls at all — are described in Section 17 and at usemarker.ai/deployment.

2. Customer Content: Information We Process for Our Customers

2.1 What Customer Content is. When a business customer uses the Service, it submits and generates data within its own organization: conversation transcripts ingested from its production systems, audio recordings and call audio, audio-derived measurements, telemetry and traces, personas, scenarios, scenario sets, templates, marker definitions, machine-generated Marks, human-entered Labels, and Notes. That data is “Customer Content.” It may contain personal information about individuals — for example, the voice, speech, and statements of a person recorded in a production call the customer chose to ingest.

2.2 The customer decides, not Marker. Our business customer decides what Customer Content to submit, whom to record, which agents and telephone numbers to test, what retention settings to apply, and for how long to keep the results. Marker processes Customer Content only to provide the Service to that customer, at that customer’s direction, and as described in our agreement with them. We do not decide the purposes for which Customer Content is collected. We use Customer Content only to provide, secure, and support the Service for that customer, to generate Service Results at its direction, to enforce our Terms of Service, and to comply with law. We do not use it to train models, we do not sell or license it, and we do not use it to build a profile of any individual for our own commercial purposes. Sections 6.4, 6.5, and 13 describe the limited circumstances in which Customer Content may be disclosed or accessed.

2.3 This policy does not govern Customer Content. The handling of Customer Content is governed by our agreement with the business customer — our Terms of Service, together with any data processing addendum or other written instrument the parties execute under Section 18.2 of those Terms — and by that customer’s own privacy policy and practices, rather than by this policy. Sections 3 through 6 of this policy describe information we collect for our own purposes and do not describe Customer Content.

2.4 If you are an individual whose data is in a customer’s Marker organization. If you believe a Marker business customer holds information about you — for example, because you were a party to a call that the customer recorded and analyzed — please contact that business directly. They control that data, they can identify you within it, and they decide whether to access, correct, or delete it. We cannot lawfully or practically act on such a request without their instruction. If you contact us at [email protected], we will use commercially reasonable efforts to forward your request to the relevant customer where we can identify them, and to tell you that we have done so.

2.5 Customer obligations. Our business customers are contractually responsible for obtaining every consent, authorization, and notice required before submitting Customer Content, including the call-recording, wiretap, two-party and all-party consent, telemarketing, and do-not-call obligations set out in our Terms of Service. Marker is a technical facilitator; it does not determine whom a customer calls or records.

2.6 No training on Customer Content. We do not use Customer Content to train, fine-tune, or otherwise improve generally available artificial-intelligence or machine-learning models, and we do not license or sell Customer Content to any third party for that purpose.

3. Personal Information We Collect

This section describes information we collect and use for our own business purposes. It does not describe Customer Content, which Section 2 covers.

3.1 Account and profile information. When you create an account, we collect your name, your email address, the identifiers our identity provider issues for your login, and your organization name, membership, and role. Authentication is delegated to our identity provider: you sign in with Google or with an email address and password held by that provider. Marker does not store your password. We also record which organization each account belongs to, because every read and write in the Service is scoped to that organization.

3.2 Billing and payment information. When you subscribe, our payment processor collects and processes your payment details. It returns to us the information we need to bill and service your subscription — your billing contact and email address, customer and subscription identifiers, plan, invoice and payment status, amounts, and the last digits and brand of the card on file. We do not receive or store full payment card numbers. We keep a journal of the billing events our payment processor sends us so that we have an auditable record of charges and subscription changes.

3.3 Credentials and session information. We store a hash of each API key you create, never the key itself; the key is displayed once at creation and cannot be recovered afterward. Your browser session is carried by a cookie that is HttpOnly, Secure, SameSite, and scoped to the single hostname that issued it; no session token is ever placed in browser storage.

3.4 Usage, metering, and diagnostic information. As you use the Service, we automatically collect operational data about how it runs: metered quantities such as simulated voice minutes, ingested audio minutes, and evaluation counts; credit balances, grants, reservations, and ledger entries; job, batch, and run statuses; latencies, error rates, and exception reports; model, carrier, and provider utilization; and feature-usage statistics. These records are tied to your organization and, where relevant, to the account that performed the action, so they can be linked back to you.

3.5 Device and log information. Our infrastructure and our edge and hosting providers generate ordinary server logs when you visit our websites or call our API. These include your IP address, the request time, path, and method, response status, referring page, user-agent string, and approximate location inferred from the IP address. We use them for delivery, performance, security, abuse prevention, and debugging.

3.6 Support and communications information. When you email us, ask a question, report a problem, or make an enterprise or sales inquiry, we collect your email address, the content of your message, and any attachments or logs you send, together with our correspondence with you.

3.7 Documentation access. Our documentation site at docs.usemarker.ai is not public. Access is gated by our edge provider, which asks a visitor for an email address, sends a one-time code to it, and admits the visitor only if the address is on our allow-list. That provider therefore collects and verifies the email address of every documentation visitor and keeps a short-lived log of those access events; we use it to control who can read the documentation. Section 7.2 identifies the provider. The marketing site at usemarker.ai is public and requires no email address.

3.8 Information we do not collect. We do not knowingly collect government-issued identification numbers, financial account numbers, precise geolocation, biometric identifiers used to identify you, or information about your race, ethnicity, religion, health, sexual orientation, or political opinions. Our Terms of Service prohibit customers from submitting protected health information, cardholder data, and other regulated categories to the Service without a separate written agreement.

4. Where That Information Comes From

4.1 From you. Account, profile, billing-contact, support, and inquiry information comes from you or from the colleague who invited you or set up your organization.

4.2 Automatically. Usage, metering, diagnostic, device, and log information is generated automatically as you use the Service.

4.3 From our providers. Our identity provider supplies the authentication identifiers and the verified email address associated with your login. Our payment processor supplies billing, subscription, and payment-status information. Our observability providers supply error and performance telemetry generated by our own systems.

5. How We Use Personal Information

We use each category described in Section 3 for the purposes stated below, and not for unrelated purposes.

5.1 To provide the Service. We use account, profile, credential, and session information to authenticate you, to place you in the right organization, to enforce what you are permitted to see and do, and to make the Service function.

5.2 To bill you. We use billing information and metered usage to charge your subscription, apply your included credit allotment, calculate any overage you have opted into, enforce your spend cap, issue invoices and receipts, collect payment, handle failed payments and disputes, and maintain accounting records.

5.3 To support you. We use support and communications information, together with diagnostic data, to answer your questions, reproduce and fix problems, and follow up on issues you report.

5.4 To secure the Service. We use log, device, session, credential, and usage information to detect and investigate unauthorized access, credential abuse, fraud, and abusive or unlawful use; to enforce our Terms of Service; to apply rate limits and spend caps; and to protect our customers, our providers, and the public.

5.5 To operate and improve the Service. We use aggregated and de-identified usage, metering, and diagnostic data to monitor reliability and cost, to plan capacity, to prioritize work, and to improve features. We do not publish or disclose such data in a form that identifies you, your organization, or the agents you test.

5.6 To communicate with you. We use your email address to send service, security, billing, and legal notices, and — where you have not opted out — occasional product announcements. Section 9 explains your choices.

5.7 To meet legal obligations. We use the information described above as necessary to comply with applicable law, to respond to lawful requests, to maintain tax and accounting records, and to establish, exercise, or defend legal claims.

5.8 What we do not do. We do not sell personal information. We do not share personal information for cross-context behavioral advertising or targeted advertising. We do not use personal information to train generally available artificial-intelligence models. We use Customer Content only for the purposes stated in Section 2.2, and never to build a profile of an individual for our own commercial purposes.

6. How We Share Personal Information

6.1 With service providers. We share personal information with the vendors that host, secure, meter, bill, and support the Service, strictly to perform those functions on our behalf. Section 7 identifies them.

6.2 Within your organization. The Service is a collaborative product, and visibility inside it follows the organization’s teams. Your name and email address are part of your organization’s member directory and are visible to other members of that organization. The resources you create, and the Marks, Labels, and Notes recorded against them, are visible to the members of the teams that own them — not to every member of the organization. Visibility of audit records is tiered by role: an organization owner or an administrator can read the organization-wide audit trail, while a member or viewer can read only the record of their own actions. Your organization’s owner controls its subscription and spend settings, and can see across all of its teams.

6.3 To destinations you configure. If you configure the Service to send alerts or data to a destination you control — such as a chat webhook, an incident tool, or any other HTTPS endpoint you allow-list — we transmit the configured content to that destination at your direction. You choose those destinations, you are responsible for them, and their operators are not our service providers.

6.4 For legal reasons. We may disclose information if we reasonably believe disclosure is required by law, regulation, legal process, or governmental or carrier request; or is necessary to enforce our Terms of Service, to investigate suspected fraud or abuse, or to protect the rights, property, or safety of Marker, our customers, or the public. Where we are legally permitted to do so, we will notify the affected customer before responding to a demand for their data.

6.5 In a corporate transaction. If Marker is involved in a merger, acquisition, financing, reorganization, or sale of all or substantially all of its assets, personal information may be transferred as part of that transaction, subject to the receiving party continuing to handle it under terms no less protective than this policy. We will post notice of any such transfer here.

6.6 With your direction. We share information with third parties in any other case only at your direction or with your consent.

7. Service Providers We Use

The providers below process personal information or Customer Content on our behalf in order to deliver the hosted Service. This list is current as of the effective date of this policy and is representative rather than perpetual: we may add, replace, or remove providers as the Service evolves, and we update this section when we do.

7.1 Amazon Web Services. Cloud infrastructure for the hosted Service: compute, the managed PostgreSQL database, object storage for audio and other artifacts, secrets management, key management, load balancing, and edge protection. The Service data Marker itself controls — Customer Content, account records, and operational data — is stored at rest here. Copies held by the providers described in Sections 3 and 7 reside with those providers under their own terms: visitor and documentation-access logs with the provider in Section 7.2, login identities and credentials with the provider in Section 7.3, and payment details with the processor in Section 7.4.

7.2 Cloudflare. Domain registration and domain name service for usemarker.ai, and hosting and content delivery for our marketing and documentation sites. This provider also operates the access gate on our documentation site described in Section 3.7, and in that role it receives and verifies a documentation visitor’s email address. It does not proxy traffic to the hosted platform or its API: those hostnames resolve through this provider’s domain name service directly to our cloud edge, and the edge protection for them is provided by the cloud infrastructure in Section 7.1.

7.3 WorkOS. Identity and authentication for the hosted Service, including Google sign-in and email-and-password sign-in. Your credentials are held by this provider, not by Marker.

7.4 Stripe. Payment processing, subscriptions, invoicing, and billing webhooks. Your payment card details are collected and stored by Stripe under its own terms and privacy policy.

7.5 OpenAI. Large-language-model inference used to drive simulated personas and to run judge-based evaluation of transcripts. Conversation text is transmitted to this provider to generate those Service Results.

7.6 Anthropic. Large-language-model inference used to drive simulated personas and to run judge-based evaluation of transcripts, on the same basis as Section 7.5.

7.7 Deepgram. Speech-to-text transcription — both batch transcription of ingested audio and live transcription during simulated voice calls — and text-to-speech synthesis for the default synthetic persona voice. Call audio is transmitted to this provider to produce transcripts, and persona speech text is transmitted to it to produce audio.

7.8 Google Cloud. Text-to-speech synthesis for the synthetic voice used by simulated personas, as a selectable alternative to the default voice described in Section 7.7. Where a persona uses this provider’s voice, the persona speech text is transmitted to it to produce audio.

7.9 Telephony carriage. A simulated voice call placed over the public telephone network is carried by a telephony provider, which handles call setup and the media stream and therefore receives the call audio and the telephone numbers involved. As of the effective date of this policy no telephony carrier is enabled for the hosted Service. We will name the carrier in this section, and give the notice described in Section 18.1, before enabling one.

7.10 Sentry. Error and exception monitoring for our own systems. Diagnostic context, which can include identifiers associated with a request, is sent to this provider when something fails.

7.11 Grafana Cloud. Metrics, traces, and logs from our own systems, used for reliability and performance monitoring.

7.12 Email. Marker sends service and billing email — invitations, account and security notices, and billing notifications — to the contact addresses on an account. As of the effective date of this policy this section names no email-delivery vendor. If we engage one that receives recipient addresses and message content, we will name it here.

7.13 Professional advisers. Our accountants, auditors, insurers, and legal counsel may receive personal information where necessary for them to advise us, subject to professional duties of confidentiality.

7.14 Additional voice and speech providers. The Service supports additional telephony carriers, speech-synthesis providers, and real-time voice transports beyond those named above, which we may enable for particular features or customers. Where we enable one for the hosted Service, we update this section.

7.15 Our commitments about providers. We give each provider only the information it needs to perform its function, we require each to protect that information and to use it only to provide services to us, and we do not authorize any of them to sell it or to use it for their own advertising. We are not responsible for the independent practices of a destination you configure under Section 6.3.

8. Cookies and Similar Technologies

8.1 What we use. The hosted application sets a single strictly necessary session cookie after you sign in. That cookie is HttpOnly, Secure, SameSite, and scoped to the hostname that issued it; it exists to keep you signed in and to protect your session. The application also stores a small amount of non-identifying interface preference data in your browser, such as layout and display choices.

8.2 What we do not use. As of the effective date of this policy, our marketing and documentation sites use no third-party analytics, advertising, retargeting, or cross-site tracking technologies, and we place no advertising cookies anywhere on the Service. If that changes, we will update this section before the change takes effect.

8.3 Your controls. You can block or delete cookies in your browser settings. Blocking the session cookie will prevent you from signing in to the hosted application. Because we do not track you across sites or serve targeted advertising, there is nothing for a Do Not Track or Global Privacy Control signal to opt you out of; we do not sell or share personal information for advertising in any case.

9. Communications and Marketing

9.1 Service messages. We send transactional messages that are part of the Service — account and security notices, invitations, billing and payment notices, notices of changes to our Terms of Service or this policy, and responses to your support requests. You cannot opt out of these while you hold an account, because they are necessary to operate it.

9.2 Product and marketing messages. We may send occasional product announcements and other marketing messages to a business email address you gave us. Every such message includes an unsubscribe link and our business postal address, and you can also opt out at any time by emailing [email protected]. Opting out of marketing does not stop the service messages described in Section 9.1.

10. Data Security

10.1 Measures we take. We maintain administrative, technical, and organizational measures designed to protect personal information and Customer Content against unauthorized access, disclosure, alteration, and destruction. These include encryption of data in transit; encryption of stored data using managed cloud key services; authorization scoped to your organization and enforced in the application layer on every read and write; role-based access control and scoped, hashed API keys; delegated authentication with no password storage by Marker; session cookies that are not readable by browser scripts; restricted and logged administrative access; restricted network egress from our production environment; and cryptographically signed container images for the software we build and distribute.

10.2 No certifications claimed. We do not hold, and this policy does not claim, any third-party security certification or attestation, including SOC 2 or ISO 27001. We do not represent that the Service is HIPAA-compliant, and this policy is not a business associate agreement, a data processing agreement, or a set of standard contractual clauses. Any additional data-protection commitment must be set out in a separately executed written agreement.

10.3 No absolute guarantee. No method of transmission over the internet and no method of electronic storage is completely secure. We cannot and do not guarantee that the Service or the information in it will never be subject to unauthorized access. You are responsible for protecting your own credentials and API keys, and for telling us promptly at [email protected] if you suspect they have been compromised.

10.4 If an incident happens. If we confirm a security incident that has resulted in unauthorized access to, acquisition of, or disclosure of Customer Content or of personal information associated with an account, we will notify the affected customers as required by applicable law, by email to the account email address. We may delay notice where a law-enforcement authority directs us to. This is a notification obligation measured by law; it is not a commitment to a fixed deadline, to provide forensic reports, or to bear a customer’s remediation or notification costs. Section 18.5 of our Terms of Service states the same obligation in contract.

11. Data Retention

11.1 Product data in your organization. Each organization has a retention policy with separate windows for transcripts, audio, traces, and the Marks and Labels recorded against them. Every organization starts at 365 days for all four windows. Where a window is set, it must be at least 30 days; a window may also be left unset, in which case that data is kept until it is deleted. Where the Service exposes this control, an organization owner can change these windows, and is responsible for choosing settings appropriate to its own legal obligations.

11.2 Stored audio and other objects. The stored bytes behind audio and ingest artifacts expire on infrastructure lifecycle rules that, in our hosted environment, default to 365 days for audio and ingest inputs, 30 days for intermediate result artifacts, and 7 days for worker scratch data.

11.3 Account and organization records. We keep account, profile, and organization records for as long as the account exists, and for a reasonable period afterward to complete billing, resolve disputes, maintain security records, and meet legal, tax, accounting, and audit obligations.

11.4 Billing records. We keep invoices, payment records, and our journal of billing events for as long as required for accounting, tax, audit, and fraud-prevention purposes. After a configured window that defaults to 730 days, we purge the personal information contained in each stored billing event — the verbatim event our payment processor sent us — and retain only a non-identifying record that the event occurred, such as its type, its processor identifier, and its timestamps.

11.5 Logs and diagnostics. Server logs, error reports, and operational telemetry are retained on the rolling schedules of the systems that hold them and are used only for the purposes in Sections 5.4 and 5.5.

11.6 After you cancel. For 30 days after termination, we will make Customer Content reasonably available for export where the account remains in good standing and export is technically feasible. After that window we have no obligation to retain Customer Content, and we may delete or de-identify it in the ordinary course. We do not commit to deleting it on any particular schedule, and residual copies may persist as described in Section 11.7 and in records we are required to retain by law. The 30-day export window does not apply where we terminate or suspend an account for cause under Section 8.3 of our Terms of Service; in that case we are not obliged to retain Customer Content at all.

11.7 Backups and residual copies. Deleting data in the Service removes it from the live system, but not immediately from every copy. Automated backups of our hosted database are retained for a limited period — 14 days as our production infrastructure is configured on the effective date of this policy — and data deleted from the live system remains recoverable from those backups until they age out of that window. If we decommission a piece of that infrastructure, a final snapshot of the database may be retained beyond that window. Other systems that hold copies, such as object storage and our observability providers, expire them on their own schedules. Copies also persist in records we are required to retain for legal, tax, audit, or fraud-prevention reasons.

12. Where Data Is Processed and Stored

12.1 United States. The hosted Service stores and processes data in Marker-operated cloud infrastructure in the United States, in the us-east-2 region of our cloud provider. Marker is a United States company and operates from the United States.

12.2 Our providers. Some of the providers listed in Section 7 operate globally and may process data outside the United States in the course of delivering their services to us. We have not certified to any cross-border transfer framework and do not represent that we have; if you require data residency outside the United States, run the software yourself under Section 17, and if you require that no data leave your own network, run the air-gapped profile described in Section 17.2. Deployment options are described at usemarker.ai/deployment.

12.3 If you are outside the United States. If you access the Service from outside the United States, you are sending information to the United States, where privacy laws differ from those of your country. Use the Service only if that is acceptable to you and to your organization.

13. Marker Personnel Access

13.1 No in-product staff access to Customer Content. The Service provides no in-product mechanism by which Marker personnel can browse, search, or read a customer’s Customer Content. There is no support console, no impersonation feature, and no cross-organization view: every read and write in the application is scoped to a single organization and is authorized against the caller’s membership in it.

13.2 Infrastructure-level access. Marker personnel who operate the hosted infrastructure necessarily hold infrastructure-level access to the systems that store and process data — databases, object storage, logs, and the deployment environment itself. That access is limited to operating, securing, and supporting the Service, and is used for those purposes only. It is not a product feature, and it is not offered as a way to answer questions about the contents of an account.

13.3 Not applicable to self-managed deployments. Neither form of access reaches a self-managed, on-premises, or air-gapped installation. That software runs on infrastructure the customer operates, and Marker holds no access to it.

14. Your Choices and How to Make a Request

14.1 In the application. You can view and update your account profile. The remaining controls are gated by the role you hold, because the Service authorizes every action against your membership rather than granting each member the same powers. Membership is managed per team by that team’s owners and administrators, and an administrator cannot grant a role above their own. API keys belong to the organization rather than to the person who created them: an organization owner can create an organization-wide key, while a member of an agent’s team can create a key locked to that agent and limited to what their own role already permits. Subscription and billing management is limited to the organization owner and its administrators, and starting a subscription or changing usage-based settings is limited to the organization owner.

14.2 By email. To ask what personal information we hold about you, to request a copy of it, to correct it, or to ask us to delete it, email [email protected]. Describe what you are asking for and the account or organization it relates to. We will honor the request where applicable law requires us to, and otherwise where doing so is operationally feasible, and we will respond as promptly as we reasonably can. Before acting we will take commercially reasonable steps to verify your identity or your relationship to the account, and we will not act on a request we cannot verify. We may decline a request where doing so would break the law, compromise security, defeat a legal hold, or affect another person’s rights, and we will tell you if that is why.

14.3 Requests about Customer Content. If your request concerns Customer Content in a business customer’s Marker organization, Section 2.4 applies: contact that business, because they control the data and we act only on their instructions.

14.4 Marketing. Section 9.2 describes how to stop marketing messages.

14.5 No retaliation. We will not deny you the Service, charge you a different price, or provide you a lesser quality of service because you made a privacy request.

15. U.S. State Privacy Laws

15.1 Where we stand today. Many U.S. states, including California, have enacted consumer privacy statutes. They apply to businesses meeting statute-specific thresholds, and those thresholds vary considerably from state to state: some turn on annual revenue, some on the number of consumers whose personal information the business handles, some on the share of revenue derived from selling personal information, and some on none of those. We have assessed our current scale against those statutes and do not believe most of their obligations apply to us today, but we do not publish that as a legal conclusion and we do not rely on it as a reason to ignore a request. Whether or not a particular statute reaches us, we honor the requests described in Section 14.2, and we do not sell or share personal information. We state this plainly rather than reciting a compliance program we do not operate.

15.2 What we do anyway. Independent of whether a statute requires it, we will honor a request to access, correct, or delete personal information we hold about you where doing so is operationally feasible, on the terms described in Section 14.2. We do not sell personal information, we do not share it for cross-context behavioral advertising, we do not use it for targeted advertising, and we do not profile individuals to make decisions that produce legal or similarly significant effects about them.

15.3 What we do not claim. We do not claim certification under, or full operational compliance with, the California Consumer Privacy Act, the General Data Protection Regulation, or any other privacy statute or framework, and nothing in this policy should be read as such a claim. We do not offer a formal statutory verification workflow, a fixed statutory response deadline, or an appeal mechanism. If our business grows past a statutory threshold, we will build what the statute requires and update this section before it applies to us.

15.4 Business-to-business context. Most personal information we hold about identifiable individuals is work-contact information about the employees and contractors of our business customers — a name, a work email address, an organization, a role, and the actions taken under that account. We describe this to be accurate about what we hold, not to suggest that work-contact information falls outside any statute: it does not, and it is subject to Section 15.2 and to the requests described in Section 14.2 on the same terms as any other personal information we hold.

16. Children’s Privacy

16.1 The Service is a business product intended solely for use by organizations and by individuals acting on their behalf. It is not directed to children, and our Terms of Service require every user to be at least 18 years old, or the age of majority in their jurisdiction if greater. We do not knowingly collect personal information from children. If we learn that we have collected personal information from a child, we will delete it. If you believe a child has provided us personal information, contact us at [email protected].

17. Self-Managed, On-Premises, and Air-Gapped Deployments

17.1 Your infrastructure, your data. Marker also offers deployments that run entirely inside the customer’s own cloud account, data center, or isolated network. In those deployments, transcripts, audio, traces, Marks and Labels, and all other Customer Content are stored in the customer’s own database and object storage. Marker’s hosted infrastructure does not receive Customer Content from a self-managed installation, and Marker does not host that data.

17.2 Air-gapped installations. The air-gapped profile is the configuration designed to make no outbound network calls at all: no telemetry, no usage relay, and no license check over the network. It runs against an offline signed license file, and is the profile to choose where the requirement is that no data leave the customer’s network.

17.3 Connected self-managed installations. A self-managed installation that the customer chooses to run connected is a different posture. It makes only the outbound calls the customer approves, but those calls may carry conversation data — including personal information contained in it — to the model, speech, and telephony providers the customer has configured. Those transmissions go from the customer’s environment to the customer’s chosen providers, not to Marker. A customer running the connected profile is responsible for deciding which outbound endpoints to approve and on what terms.

17.4 The customer chooses the providers. In a self-managed deployment the customer supplies its own identity provider, its own model, speech, and telephony providers where it uses them, and its own storage and secret backends. The provider list in Section 7 describes our hosted environment and does not describe a customer’s self-managed installation.

17.5 Governed by a separate agreement. Self-managed, on-premises, and air-gapped deployments are licensed exclusively under a separately executed written agreement, which governs data handling for that offering. This policy describes only our hosted Service and our websites. Deployment options are described at usemarker.ai/deployment.

18. Changes to This Policy

18.1 We may update this policy from time to time. When we do, we will change the effective date at the top of this page. For material changes — for example, a new category of information, a materially new purpose, or a new provider that receives Customer Content — we will give notice in advance where practicable, by email to the address on your account or by in-product notice, before the change takes effect.

18.2 Changes apply prospectively. Continued use of the Service after a change takes effect means you accept the updated policy. If you do not accept it, your remedy is to stop using the Service and cancel your subscription.

19. How to Contact Us

19.1 Marker AI, Inc. is the company responsible for the personal information described in this policy.

19.2 Send privacy questions, requests to access, correct, or delete personal information, and any other privacy or legal notice by email to [email protected]. Email is our preferred channel and the address of record for notices to Marker, because it is the channel we monitor and the one that lets us respond fastest. It is not the only channel: Section 19.3 describes how to reach us by post.

19.3 We will provide our current business mailing address for legal and privacy notices on request at [email protected], and a notice delivered to that address is effective on delivery. Section 28.1 of our Terms of Service states the same for contractual notices.

19.4 If you are an individual whose information sits in a Marker customer’s organization, contact that business first — see Section 2.4.

Marker AI, Inc. · Effective July 24, 2026 · [email protected]

Home · Pricing · Deployment · Terms of Service

Marker
  • Signed images
  • SBOM
  • SAML/OIDC
  • RBAC

Engine

  • Overview
  • Product
  • Pricing

Deployment

  • Options
  • Deployment guide

Team

  • About Marker

Resources

  • Docs

© 2026 Marker AI, Inc.

  • Terms
  • Privacy