Privacy
What we hold, and what we do not.
Last updated 8 September 2026
The short version: we collect the least our software can work on, we sell nothing to anyone, we do not use what you create to train models, and identity is not required where a product can do without it.
The rest of this page is the same statement in detail.
What this policy covers
This is our company-level policy. It covers this website and sets out the principles that apply to everything Marzipan Labs publishes.
Individual products publish their own policy describing precisely what that product collects and why. Where a product policy exists, it governs that product; this document remains the standard it is written against.
Who we are
Marzipan Labs LLC is a limited liability company registered in the State of Wyoming, United States, and is the controller of the personal data described here. For anything relating to your data — access, correction, deletion, or a complaint — write to privacy@marzipanlabs.com.
The principles we hold to
These are constraints on how our software is designed, not preferences:
- We collect the least we can. Not the least we are legally obliged to — the least the product can function on.
- What you create is yours. We claim no ownership of it and take no licence to it beyond what running the feature you asked for requires.
- We do not sell personal data, share it with data brokers, or trade it for anything else of value. There is no version of our business that depends on this.
- We do not use your content to train models of our own.
- We do not run advertising and operate no advertising trackers.
- Identity is not required. Where a product can work without knowing who you are, it is built that way.
This website
This site sets no cookies, runs no analytics, embeds no third-party scripts and contains no forms. Our host keeps standard server logs, including IP addresses, for security and for keeping the site available. The single external request the site makes is to a font service to load its typeface.
When you write to us
Correspondence sent to any of our addresses reaches a mailbox we control. We keep it for as long as needed to deal with the matter and any follow-up, and we do not add it to a mailing list or use it for anything you did not write to us about.
Others who process data for us
We keep this list deliberately short. Each acts on our instructions, under contract, for a stated purpose:
- Infrastructure and network providers, which process request metadata in order to deliver traffic, keep services available and absorb attacks.
- Model providers, where a feature requires machine learning that cannot run locally. They process the content of that request in order to return a result. Their handling is governed by their own terms, which is a factor in which we are willing to use.
- Payment and distribution platforms, which handle purchases under their own terms. We receive aggregate reporting from them and never your payment details.
Legal bases for processing
Where the GDPR applies to you, we rely on the following:
- Performance of a contract — doing the thing you asked the product to do.
- Legitimate interests — keeping our services secure, preventing abuse, and understanding in aggregate how our software is used, balanced against your rights.
- Consent — where a product asks before accessing something on your device or collecting optional measurements. You can withdraw it at any time.
- Legal obligation — where we are required to retain something by law.
How long we keep things
- The content of a request: processed and discarded, not retained as a record attached to you.
- Operational and security logs: a short period, normally no more than 30 days.
- Aggregate measurements: for as long as they remain useful, in a form that does not identify you.
- Correspondence: as long as the matter and any follow-up require.
Your rights
Depending on where you live, you have some or all of the following rights: to know what we hold about you, to obtain a copy, to have it corrected or deleted, to restrict or object to its processing, to receive it in a portable format, and to withdraw consent you previously gave.
Write to privacy@marzipanlabs.com and we will respond within 30 days. Because our software generally does not require an account, we may need your help identifying what you are asking about; we will not ask for more identifying information than the request requires.
If you are in the European Economic Area or the United Kingdom, you also have the right to complain to your national data protection authority.
International transfers
We are a United States company and our providers operate internationally, so data processed on our behalf may be handled outside your country, including in the United States. Where data leaves the European Economic Area or the United Kingdom, we rely on the European Commission’s Standard Contractual Clauses or an equivalent recognised safeguard in our contracts with those providers.
Children
Our software is not directed at children and we do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, write to us and we will delete it.
Security
Traffic is encrypted in transit. Our services accept requests only from clients that have proved their authenticity, and no credential of ours is ever distributed inside something a user can download. No system is perfect; if you find a weakness in ours, we would rather hear from you than not — security@marzipanlabs.com.
Changes
If this policy changes materially we will update the date at the top of this page, and where the change affects how your data is handled we will say so in the affected products. The current version is always the one published here.