Privacy Policy
Effective June 8, 2026
This Privacy Policy explains what information Marlowe ("we," "us") collects when you use the Marlowe service (hiremarlowe.com and any subdomains), how we use it, and the choices you have. We try to keep this short. If a section isn't clear, email hello@marloweapp.com and we'll explain.
1. Information we collect
Account information. When you sign up, we collect your email address, name (if provided), and authentication credentials. Authentication is handled by Clerk; we store the Clerk user ID and your primary email.
Idea + campaign inputs. The problem statement, target buyer role, industry, company-size band, ACV band, and geography you provide when creating a campaign.
Generated content. The 100 prospect profiles, draft emails, and reasoning text Marlowe generates for your campaign. These are stored against your account so we can show them to you in the dashboard.
Gmail integration data. If you connect a Gmail account, we store an OAuth refresh token and the email address you connected. We use restricted Gmail scopes: gmail.compose (to write drafts into your inbox) and gmail.readonly (to read replies on threads you started through Marlowe). We do not read, store, or analyze any email in your inbox that wasn't sent from a draft we created.
Payment information. Stripe handles all card data; we never see or store card numbers. We store the Stripe Checkout session ID, amount, currency, and timestamp for each purchase.
Product analytics. We use Amplitude to track funnel events (page views, button clicks, signup, checkout). Amplitude receives an anonymized device ID and your authenticated user ID once you sign in. We also enable session replay at 100% sample rate for early launch — replays exclude form inputs marked as sensitive.
Advertising pixels. If you arrived from a paid ad, we may load the Meta Pixel and/or Google Ads tag for conversion attribution. You can opt out via the cookie banner on first visit.
2. How we use information
To deliver the service: research prospects, generate drafts, place drafts in your Gmail, classify replies, show you funnel data.
To process payments and issue refunds.
To improve Marlowe — including capturing draft edits you make so Marlowe learns your voice over time. We never use the content of replies you receive to train models that touch other customers.
To communicate with you about your campaign, billing, and product updates. You can unsubscribe from product updates at any time.
3. Subprocessors
We share data with the following services only as needed to deliver the product:
- Clerk — authentication.
- Neon — Postgres database hosting (US East).
- Vercel — application hosting.
- Anthropic — AI generation (Claude). Inputs and outputs are processed via the Anthropic API; per Anthropic's terms, API content is not used to train their models.
- Findymail — prospect lookups (B2B email + company enrichment).
- Exa — web search for company research.
- Google (Gmail API) — to write drafts and read replies on threads you started through Marlowe.
- Stripe — payments.
- Amplitude — product analytics and session replay.
- Meta and Google Ads — conversion measurement (only for visitors arriving from paid ads who do not opt out).
We do not sell your data. We don't share customer data with anyone other than the subprocessors above, except where required by law.
4. Your choices
Access and deletion. Email hello@marloweapp.com and we will export or delete your account data within 30 days.
Disconnect Gmail. Use the "Disconnect Gmail" button in your dashboard. We revoke the OAuth grant and delete the stored tokens; drafts already in your Gmail are unaffected (they're your emails).
Opt out of ad pixels. Use the cookie banner on first visit, or send "do not track" headers.
5. Data retention
Account data, campaign data, and Gmail tokens persist while your account is active. If you delete your account, we delete this data within 30 days. Stripe payment records are retained for 7 years for tax and accounting compliance.
6. Security
Data in transit uses TLS. Data at rest is encrypted by Neon (Postgres) and Clerk. We follow the principle of least privilege for internal access. We use Clerk-managed authentication and rotate the Stripe and Anthropic API keys periodically.
7. Children
Marlowe is a B2B tool for founders building a business. We do not knowingly collect data from anyone under 18.
8. Changes to this policy
We may update this policy. Material changes will be announced via email to your account address.
9. Contact
Questions: hello@marloweapp.com.
See also our Terms of Service and Refund Policy.