Effective 3 August 2026
Privacy Policy
This policy explains what personal data Marlowë Ltd ("Marlowë") collects, why, how long we hold it, who we share it with, and your rights under UK GDPR. If anything here is unclear, email help@marlowe.com.
Data controller
Marlowë Ltd, United Kingdom. Contact: help@marlowe.com.
What we collect
- Account data — email, name, password hash (never the password itself).
- Profile data — current role, employer, discipline, years of experience, LinkedIn URL, and in-app preferences.
- Job search data — jobs you save, interview stages, notes, briefs.
- CVs — files you upload, stored in encrypted object storage.
- Career evidence — the wins you log, plus any files you attach to them: documents, decks, meeting notes, screenshots.
- Voice recordings — audio you record for interviews, quick logs, debriefs or the onboarding brief. CVs and audio are held in separate private storage buckets; transcripts derived from recordings are stored alongside them.
- Imported content — if you connect Notion, the pages you choose to import and the access token for that connection.
- Transcripts and AI output — the text version of your recordings, and the analysis Marlowë generates from your data.
- Billing data — subscription status and payment records held by our payment provider. We never see or store your card details.
- Usage data — features you use and errors you hit, recorded first-party in our own database. Minimal, product-analytics only.
Why we process it (lawful basis)
- Contract — to deliver the service you signed up for (auth, storage, AI analysis, showing results back to you).
- Legitimate interests — keeping the service secure, preventing abuse, product analytics, direct communication about your account.
- Consent — optional marketing emails (you can opt out any time).
- Legal obligation — tax, accounting, and lawful requests from authorities.
Who we share it with (processors)
We do not sell your data. We share the minimum needed with sub-processors that help us run the service:
- Supabase (EU) — database, auth, object storage.
- Lovable — operates the AI gateway that proxies our model requests, and hosts the application.
- Google, OpenAI — text generation and analysis via that gateway. Data sent to these models is not used to train them under the APIs we use.
- ElevenLabs — transcription of interview recordings and quick logs.
- OpenAI — transcription of shorter voice answers in the job brief flow, via the same gateway.
- Notion — only if you connect it. We read the pages you select so they can be imported as career logs.
- Perplexity, Firecrawl — web research when you use the Research Company feature. We send the company name and role; we do not send your personal data.
- Stripe — subscription billing and payment processing.
- Cloudflare — hosting and edge compute.
Some processors are based outside the UK/EEA. Where they are, we rely on Standard Contractual Clauses or equivalent safeguards.
Which AI model handles a given request is our choice, not yours: user-facing generation and background classification jobs may run on different models from the providers listed above.
How long we keep it
- Account and profile data: for as long as your account is open.
- CVs, recordings, transcripts, attachments, AI output: until you delete them individually or delete your account.
- Connected integrations: the access token is deleted when you disconnect the integration or delete your account.
- On account deletion: removed within 30 days (backups purged within 90 days).
- Billing records: 7 years, as required by UK tax law.
Deleting your account is permanent. There is no restore, so keep your own copies of anything you want to keep before you delete.
Your rights
Under UK GDPR you have the right to:
- Correct inaccurate data — edit it in-app or email us.
- Delete your data and account — use "Delete my account" in your profile.
- Access or port your data — Marlowë has no self-serve export, so email help@marlowe.com and we will send you a machine-readable copy within one month.
- Restrict or object to certain processing.
- Complain to the UK ICO (ico.org.uk) if you believe we have mishandled your data.
Security
Data is encrypted in transit (TLS) and at rest. Access to production data is restricted and logged. We do not have plaintext access to your password.
Children
Marlowë is not intended for anyone under 18 and we do not knowingly collect data from children.
Changes
Material changes to this policy will be notified in-app or by email at least 14 days before they take effect.
Contact
Privacy questions or requests: help@marlowe.com.
