Effective date: 16 September 2026. This page says what Marrow collects, why, where it lives, who processes it, how long it is kept and what you can ask us to do. It is written to be read, not skimmed; if anything here is unclear, write to hello@usemarrow.com.
Marrow is operated by [OPERATOR NAME], [OPERATOR ADDRESS] (the operator, "we"). We are the controller of the personal data described on this page. You reach us at hello@usemarrow.com.
Marrow is a personal relationship memory: you send it messages, voice notes, photos of business cards, screenshots and contact files on Telegram, and it keeps a private record of the people you know, what was said, what was promised and when to follow up. Everything on this page follows from that: the data is yours, it is about your working life, and it exists so that you can remember.
Your Telegram id and the first name Telegram passes to the bot. They identify your account; the id is what ties your messages to your database. We never see your Telegram phone number unless you share it, and we never receive your Telegram password or contacts.
Contact photos, company data and your preferred language. When a contacts file you import carries a photo, Marrow keeps a small square copy of it on that contact, stripped of everything but the picture; it is shown only to you in the app, it leaves with the contact when you delete them and it is part of your export. Marrow does not fetch profile pictures from public networks unless that option is switched on for the product, and today it is off. When you ask about a company, the public facts Marrow gathers (what it does, where it is, its size, recent news with their sources) are kept on that company in your record for a fortnight so the next question is answered without a new search. Your preferred language, chosen at the start or later, is stored on your account so the bot and the emails speak to you in it.
Your phone number, optional. It is asked once when you start, arrives only through Telegram's own share button, and is skippable. It confirms that the account is yours, and it is what lets your Marrow follow you to WhatsApp or another messaging app later. It is not used to find you, to match you with other users or to contact you for marketing.
Your email address, optional. It is asked once when you start, confirmed with a six digit code, and skippable; it can be added later. It is a way back into your account if you ever lose this phone, and it is where receipts and a small number of account messages during and after the trial go. Each such message carries a link that stops them. You may also add an unconfirmed address in Settings; it is used for the same purposes.
The content you send: text, voice notes, photos, screenshots and contact files, and what Marrow derives from them: contacts, organisations, interactions, notes, follow ups, threads and life events. Voice notes are transcribed and the transcript is kept with the note; the audio itself is not kept after transcription. Photos and screenshots are kept only for the length of the request that reads them; the extracted fields are what is stored. This content is about you and about the people you meet; the section on your responsibilities in the Terms applies to it.
Public profile lookups, only on your request. When you ask Marrow to enrich a contact, it searches for that person's public professional profile and stores what it found (headline, role, recent public posts, a summary) in your database, attached to that contact. Nothing is posted anywhere and nobody is contacted.
Usage metrics: for each message, the time, the kind of message (text, voice, photo, file), the number of model tokens it used and its estimated cost, and the kinds of things it created. These are counts, not content, and we aggregate them per day to run the service and to see whether it is used.
Technical error records: when something breaks we store the kind of error, the first line of the technical trace, the command in use and your account id, never the message content. They are kept for at most 90 days.
Cookie free page counts: our website and the app count page views without cookies and without a personal identifier, using a counter we run ourselves on our own server. Nothing is set on your device, no identifier is generated, and browsers that send Do Not Track are not counted at all.
To run Marrow for you: to answer your messages, keep your record, brief you and remind you. To run the account: the trial, receipts, a few account messages, support when you write to us. To keep the service healthy: aggregated usage and error records. That is all. We do not sell, rent or share your data, we do not use it for advertising, and neither we nor our providers train models on it.
Your data is stored in a database of your own, one database per user, on servers in Switzerland. Nobody else can search it, and nobody at Marrow reads it in the course of normal operation; we look at an individual record only when you ask us to, to fix a problem you have reported, or when the law requires it.
A small number of providers process data on our behalf, each for one purpose:
Infomaniak, Switzerland: the servers Marrow runs on and the nightly backups, all in Switzerland.
Anthropic, United States: the language model that reads your messages, voice transcripts and images to understand them and writes the replies. Each request carries only what that message needs. Anthropic does not train on this data.
Mistral, France: the transcription of voice notes. The audio is sent for transcription and the transcript comes back; the audio is not retained by us.
Apify, Czech Republic: the public profile lookups you request, one search at a time, with the name and company you gave.
Resend, United States: the delivery of the emails we send you, the verification code, receipts and account messages. No tracking pixels, no link tracking.
Help Scout, United States: the inbox behind hello@usemarrow.com, so the messages you send us by email or with /support are received and answered.
GoatCounter, self hosted on our server in Switzerland: the cookie free page counts. No third party receives them.
Telegram is the messenger you use to reach Marrow and is not our processor; Telegram's own privacy policy applies to your use of Telegram.
Your record is kept for as long as your account exists. When you delete your account (from the app, in one step, or by asking us), your database and every row about you on the platform are removed at once, and the copies in the nightly backups fall out as the backups rotate: within 14 days on our server and within 30 days from the offsite copy. Error records are kept for at most 90 days. Aggregated daily usage numbers, which contain no content and no personal identifier beyond an internal account id, are kept to understand the service over time. Email sending records at our email provider are kept by that provider for a short period for delivery and abuse prevention.
If you stop using Marrow without deleting your account, your record stays readable and exportable for you. We may delete accounts that have been inactive for more than 24 months after writing to you first.
You can access everything Marrow holds about you at any time: send /export in Telegram or use Export in the app for a complete copy as JSON. You can correct anything by telling the bot or editing it in the app. You can delete everything in one step from the app or by writing to us. You can object to the account emails with the link in any of them, and to the Telegram nudges by the same link; the verification code and receipts still send because they are part of running your account. You can ask us questions about this page and complain to us at hello@usemarrow.com; if you are in a jurisdiction with a data protection authority you may also complain to it.
Traffic between you, Telegram, our servers and our providers is encrypted in transit. Each user has a separate database, so a mistake in one account cannot expose another. The servers accept connections only on the ports the service needs, run the application without administrative rights and with read only system files, and are updated automatically. Access to the servers is by key only, held by the operator. Backups are encrypted in transit to the offsite location. Secrets are kept out of the code and out of logs. No system is perfectly secure; if we learn of a breach affecting your data we will tell you without undue delay.
Marrow is for adults. You must be 18 or older to use it. We do not knowingly collect data from anyone younger, and we delete such accounts when we learn of them.
Your record is stored in Switzerland. The providers named above process data in the countries named next to them, including the United States. Where data leaves Switzerland or the European Economic Area, it does so under the providers' standard contractual clauses or an equivalent lawful mechanism, and only for the single purpose described.
We may change this page when the service or the law changes. Material changes are announced in the bot and, if you have given us an email address, by email, at least 14 days before they take effect, with the new effective date at the top of this page.
hello@usemarrow.com, or /support in the bot, which reaches the same inbox.
Press Escape or tap outside to close