MarkMate
Sign in
Back to MarkMateReadable legal. Real AI boundaries.

Privacy Policy

What MarkMate reads, what the AI receives, what stays encrypted, and how you can disconnect or delete it. No mystery-data fog machine.

Updated July 10, 2026Human veto documentedAI boundaries included
READConnected evidenceTHINKAI analysisWRITEHuman approval first
On this page
01Information we collect02Google user data03How we use information04Sharing05Security06Retention and deletion07Cookies08Children09Changes10Contact
Legal documentsPrivacyTerms

MarkMate (“MarkMate”, “we”, “us”) is an AI marketing automation platform — it tracks your connected channels, runs scheduled workflows and reports, and prepares approval-gated changes — available at https://markmateos.com. This policy explains what information we collect, how we use and protect it, and the choices you have. If anything here is unclear, contact us at support@markmateos.com.

1. Information we collect

  • Account information. Your name, email address, and password hash when you create an account — or your name, email, and profile identifier from Google if you sign in with Google.
  • Workspace content. Workflows, agent conversations, connection settings, approval decisions, and other content you create in the product.
  • Connected platform data (with your consent). When you connect a marketing platform (for example Google Analytics 4 or Google Search Console), we access that platform’s data on your behalf through its official API, using OAuth tokens you grant. We request read-only scopes unless a feature clearly requires more, and we show you exactly which scopes are requested at connect time.
  • Usage and log data. Operation runs, credit usage, audit events, and standard technical logs (IP address, browser type) needed to operate and secure the service.
  • Payment information. Payments are processed by Dodo Payments, our merchant of record. We never see or store your card details — we receive only payment status and metadata (such as the credits purchased).

2. Google user data

When you connect Google Analytics or Search Console, MarkMate accesses that data solely to provide the features you request — reports, audits, digests, and workflow runs inside your workspace. Specifically:

  • We request read-only scopes (analytics.readonly, webmasters.readonly).
  • OAuth tokens are encrypted at rest with AES-256-GCM in an isolated token vault, bound to your workspace. Tokens are never written to logs and are never exposed to the AI model.
  • We do not sell Google user data, use it for advertising, or allow humans to read it except with your consent, for security, or to comply with law.
  • Disconnecting a connection in Connections deletes the stored tokens. You can also revoke MarkMate’s access at any time in your Google Account permissions.

MarkMate’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

3. How we use information

  • To provide the service: run operations, workflows, and agent requests you initiate.
  • To process the content you submit with AI models (we send only what a feature needs — never your OAuth tokens).
  • To meter usage (credits), prevent abuse, and enforce spending guardrails you configure.
  • To send transactional email about your account (we do not send marketing email without consent).
  • To comply with legal obligations.

4. Sharing

We do not sell personal data. We share data only with the processors needed to run MarkMate — hosting infrastructure, Dodo Payments (payments), and AI model providers (for the content of requests you make) — each bound to use it only to provide their service to us, and with authorities where the law requires it.

5. Security

All traffic is encrypted in transit (TLS 1.2+). Platform credentials live only in an encrypted vault (AES-256-GCM with per-workspace binding). Every change that touches money or a live campaign requires an explicit human approval, and every action is recorded in an audit trail.

6. Retention and deletion

  • Workspace content is retained while your account is active.
  • Disconnecting a platform deletes its stored tokens immediately.
  • To delete your account and associated personal data, email support@markmateos.com from your account email — we complete deletion within 30 days, except records we must keep by law (e.g. payment records).

7. Cookies

We use only first-party session cookies required to keep you signed in. We do not use advertising or cross-site tracking cookies.

8. Children

MarkMate is a business tool and is not directed to children under 16.

9. Changes

We will post any changes to this policy on this page and update the date above. Material changes will be announced in the product or by email.

10. Contact

MarkMate · markmateos.com · support@markmateos.com

© 2026 MarkMatesupport@markmateos.com