Privacy
Last updated 25 August 2026
What we collect, what we do not, and how to get it deleted. Plain language, because a privacy policy nobody can read protects nobody.
Who we are
Marxx AI ("Marxx", "we", "us") operates marxx.ai and the Marxx application. Under India's Digital Personal Data Protection Act, 2023 (the DPDP Act), Marxx is the Data Fiduciary for the personal data described in this notice. You are the Data Principal.
Person in charge of data protection: Nishant Kumar — privacy@marxx.ai. He answers questions about this policy, actions requests about your data, and is our grievance officer under Section 8(10) of the DPDP Act. Everything on this page routes to privacy@marxx.ai.
This notice is published in English and is available, on request to privacy@marxx.ai, in any language listed in the Eighth Schedule to the Constitution of India.
What we collect, why, and on what basis
When you visit marxx.ai. Aggregate page views through Plausible Analytics, which sets no cookies and collects no personal data. There is no consent banner because there is nothing to consent to.
When you book a demo or send the form. Your name, work email, brand website, stated ad spend band and category. Purpose: to prepare your teardown and reply to you. Basis: your consent, given when you submit the form, and the certain legitimate use in Section 7(a) of the DPDP Act for data you voluntarily provide for that purpose.
When you become a customer. Your account details (name, work email, organisation, role), authentication identifiers, the competitor list you build, your saved boards and briefs, and product usage and security logs. Purpose: to run the service you signed up for, support you, keep the account secure, and bill you. Basis: your consent.
When you connect an ad account. Optional and off by default. We receive the OAuth access and refresh tokens the platform issues, the account and campaign identifiers, and the spend, delivery and performance figures the account returns. We ask for read scopes only — Marxx cannot create, edit, pause or spend against your campaigns — and we never see or store your platform password. Purpose: to place your own numbers alongside the competitor picture. Basis: your consent, revocable at any time.
When you import from Google Drive. Optional and off by default. The files you select — creative assets and brand documents — their contents, file names and Drive file identifiers, plus the analysis Marxx derives from them. Purpose: to analyse your own creative inside your workspace. Basis: your consent, revocable at any time. Governed in detail by the Google user data section below.
What we treat as sensitive data
The DPDP Act does not divide personal data into categories, so we draw the line ourselves. These are handled under the stricter controls set out in "How we protect your data":
- OAuth access and refresh tokens for connected ad accounts
- Ad account, business and campaign identifiers
- Files imported from your Google Drive, their contents, and anything derived from them
- Spend, revenue, ROAS and other commercial performance figures
- Authentication credentials and session tokens
- Billing and payment records
Google user data
Marxx signs you in with Google and, if you choose, imports files from your Google Drive. This section governs that data specifically and takes precedence over anything more general on this page.
The scopes we request, and what each one is for.
userinfo.email— your primary Google Account email address. Used to create your Marxx account, identify you at sign-in, and send service email.userinfo.profile— your name and profile picture. Used to show who is signed in and to set up your workspace.drive.readonly— read-only access to files in your Google Drive. Used solely to import the creative assets and brand documents you select into your Marxx workspace, so that Marxx can analyse them alongside public ad data. The access is read-only: Marxx cannot create, edit, delete, move or share anything in your Drive, and has no ability to write to it at all.
How we access Drive files. Only at your direction. You choose what to import; Marxx opens a file when you select it for import, and afterwards only to refresh a file you have already imported. We do not browse, index, crawl or bulk-scan your Drive, and we do not open files you have not chosen.
How we store it. Imported files and the analysis derived from them live inside your workspace, encrypted at rest with AES-256 and in transit with TLS 1.2 or higher, logically isolated from every other customer. The OAuth access and refresh tokens are held in a managed secrets store under envelope encryption with cloud KMS-managed keys, are never written to logs, and are decrypted in memory only for the duration of an authorised call to Google on your behalf.
How we share it. We do not transfer or disclose Google user data, including the content of Drive files, to third parties — other than to the sub-processors listed below, acting on our written instruction solely to provide the feature you asked for, where you direct us to, or where the law compels it. We never sell it and we never expose it to advertisers or data brokers.
How long we keep it. An imported file and its derived analysis remain until you delete them or close your account, and are then purged within 90 days. Disconnecting Google inside Marxx, or revoking access from your Google Account, deletes the token immediately and everything imported from Drive within 30 days.
Limited Use. Marxx's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements. Because we request a restricted scope, those requirements apply to your Drive data in full. Specifically, we:
- limit our use of this data to providing or improving the user-facing features that are prominent in the Marxx interface, and only with your consent
- do not transfer this data except as necessary to provide or improve those features, to comply with applicable law, or as part of a merger, acquisition or sale of assets, and then only with notice to you
- do not use this data for serving advertising of any kind, including targeted, personalised or retargeted advertising
- do not sell or transfer this data to data brokers, information resellers or other information-resale services
- do not use this data to determine credit-worthiness or for lending purposes
- do not allow humans to read this data, unless we have your affirmative agreement for specific files, it is necessary for security purposes such as investigating abuse, it is required to comply with applicable law, or the data has been aggregated and anonymised and is used to improve internal operations
- do not use this data to develop, improve or train generalised or non-personalised AI and/or ML models. Google Workspace APIs are not used to develop, improve or train non-personalised AI and/or ML models.
How to revoke. Disconnect Google inside Marxx, or remove Marxx from your Google Account permissions at myaccount.google.com/permissions. Either route revokes the token immediately, and the deletion timelines above then apply.
How we protect your data
Section 8(5) of the DPDP Act requires reasonable security safeguards. These are the mechanisms in place, and they apply in full to the sensitive data listed above.
- In transit. TLS 1.2 or higher on every connection to and from Marxx, with HSTS enforced. No unencrypted transport, internal or external.
- At rest. AES-256 encryption on all application databases, object storage, caches and backups.
- Tokens and secrets. OAuth tokens, API keys and credentials live in a managed secrets store under envelope encryption with cloud KMS-managed keys. Keys are rotated. Secrets are never committed to source control, never written to logs, and are decrypted in memory only for the duration of an authorised API call.
- Access control. Least privilege by default. Role-based access, production access restricted to named engineers with an operational need, behind single sign-on with mandatory multi-factor authentication. Access is reviewed periodically and revoked the day someone leaves.
- Tenant isolation. Every workspace is logically separated and every query is scoped to the workspace that owns the data. Databases sit on private networks with no public interface.
- Logging and monitoring. Administrative actions and production data access are logged and monitored. Sensitive fields are redacted before anything reaches a log.
- Passwords. We store no third-party platform passwords at all. Marxx account passwords, where used, are stored only as salted Argon2id hashes and are never recoverable by us.
- People and devices. Company devices are disk-encrypted and screen-locked. Everyone with access to personal data is under written confidentiality obligations and completes data protection training.
- Sub-processors. Bound by written contract under Section 8(2) of the DPDP Act to process personal data only on our instruction and to maintain comparable safeguards.
- Testing and patching. Dependencies are patched on a schedule, and the application is put through security review and penetration testing at least annually and after any material change to how data is handled.
- Backups. Encrypted, access-controlled and restore-tested, and purged on the same schedule as the live data.
If something goes wrong
In the event of a personal data breach we notify the Data Protection Board of India and every affected Data Principal, without delay and in the form and manner required by the DPDP Act and the rules made under it — what happened, which data was involved, what we are doing about it, and what you should do. If Google user data is affected, we notify Google as well.
Found a vulnerability? privacy@marxx.ai, subject line "security". We confirm receipt within one working day and will not pursue anyone acting in good faith.
What we never do
- No advertising cookies, no pixels, no cross-site tracking
- No selling, renting or trading of personal data, to data brokers or anyone else, for any purpose
- No passwords for third-party platforms. Account connection uses the platform's own OAuth flow and we never see the credential
- No training of generalised or non-personalised AI or ML models on your account data, workspace content, connected-account figures or Google user data. The models Marxx uses to decompose creative are trained on public advertising
- No automated decision-making that produces legal or similarly significant effects on an individual
Public ad library data
Marxx reads publicly published advertisements. These are not personal data and are not yours or anyone else's private information; platforms publish them for transparency. This data is outside the deletion process below because it does not belong to any Marxx account.
How long we keep things
- Lead form submissions: 24 months, or until you ask us to delete them
- Customer account and workspace data: for the life of the account, then 90 days, then deleted
- Connected ad account tokens: until you disconnect or revoke, then deleted immediately
- Data derived from a connected ad account: 30 days after disconnection
- Files imported from Google Drive and their derived analysis: until you delete them or close the account, then 90 days; or 30 days after you disconnect Google
- Security and audit logs: 12 months
- Billing and tax records: as long as the applicable law requires
Where you withdraw consent, or the purpose we collected data for is no longer being served, we erase that data and instruct our sub-processors to do the same, as required by Section 8(7) of the DPDP Act. Deleted records clear from encrypted backups within 35 days.
Sharing and sub-processors
We share personal data only with the processors below, each under a written contract that limits them to processing on our instruction:
- Plausible Analytics — cookieless site analytics, EU hosted
- Resend — transactional email
- Google Calendar — demo scheduling
- Cloud hosting and managed database providers — running the product itself
- AI model providers — creative analysis inside the product, under agreements that prohibit training on data we send
We also disclose personal data where the law compels it, and we will tell you when we are permitted to.
Transfers outside India
Marxx is operated from India. Some of the providers above store or process data outside India. Such transfers are made under Section 16 of the DPDP Act and under contractual safeguards requiring protection equivalent to this policy. We do not transfer personal data to any country the Central Government has restricted by notification.
Your rights
Under the DPDP Act you have the right to:
- Access — a summary of the personal data we process about you, the processing activities involved, and the identities of the other Data Fiduciaries and Processors it has been shared with, along with what was shared
- Correction, completion and updating of inaccurate or incomplete personal data
- Erasure of your personal data, unless retention is required by law
- Grievance redressal, set out in the next section
- Nomination — nominate another individual to exercise these rights on your behalf in the event of your death or incapacity
- Withdraw consent at any time, as easily as you gave it. Withdrawal does not affect processing already carried out, and some features will stop working
Write to privacy@marxx.ai. We acknowledge within three working days and complete the request within 30 days. We verify identity through your registered email address. There is no charge.
Grievances
Raise it with Nishant Kumar at privacy@marxx.ai, subject line "grievance". We respond within 30 days.
If you are not satisfied with our response, or we fail to respond, you may complain to the Data Protection Board of India under Section 13 of the DPDP Act.
Children
Marxx is a business tool sold to organisations and is not intended for anyone under 18. We do not knowingly process the personal data of children. We do not undertake tracking, behavioural monitoring or targeted advertising directed at children, as prohibited by Section 9(3) of the DPDP Act. Where a lawful guardian's consent is required for a person with a disability, we obtain verifiable guardian consent before processing. If you believe a child's data has reached us, write to privacy@marxx.ai and we will delete it.
Changes
If this policy changes materially we will say so on this page, date it, and email account holders. We will not quietly broaden what we collect.
Contact
Marxx AI — Nishant Kumar, person in charge of data protection — privacy@marxx.ai