Back

Legal

Privacy Policy

Effective May 1, 2026 · Last updated July 8, 2026

On this page
  1. Overview
  2. Data we collect
  3. Purposes and legal bases
  4. Recipients and transfers
  5. Retention
  6. Browser extension
  7. Cookies
  8. Public content
  9. Your rights
  10. Children
  11. Contact

Overview

Padding Labs LLC is the controller. We process the minimum needed to run Margin and do not sell your data.

This Privacy Policy describes how Padding Labs LLC ("we", "us", "our") processes personal data in connection with Margin and the Margin Personal Data Server at margin.cafe (together, the "Service"). For purposes of the EU and UK General Data Protection Regulations, we are the controller of personal data we process to operate the Service.

Data we collect

Identity from your AT Protocol account, the content you publish, and basic usage data.

We process the following categories of personal data:

  • Account identifiers obtained from your AT Protocol identity provider, including your decentralised identifier (DID), handle, display name, avatar, biography, and website.
  • OAuth access tokens, refresh tokens, and DPoP proof keys, used to maintain your authenticated session.
  • User Content, including the URL and title of pages you annotate, the text you select, surrounding context, your note text, tags, highlight colours, replies, likes, collections, and edit history.
  • Vector embeddings of your User Content and of public AT Protocol records, and an interest profile derived from those embeddings, used to generate recommendations on the Discover page.
  • Usage data, including IP address, browser type, operating system, extension version, and product analytics events such as page views and feature interactions.
  • For accounts on margin.cafe: your email address, used for account recovery and security notices, and a salted hash of your password. We do not store passwords in plain text.
  • Billing data: your Stripe customer ID and subscription status, used to manage your Margin Pro subscription. Payment card details are processed by Stripe and are not stored on our servers.
  • Any correspondence you send to [email protected].

We do not knowingly process special categories of personal data (such as health, biometric, or government identification data), and ask that you do not include such information in your User Content.

Purposes and legal bases

Performance of contract for the core Service. Legitimate interests for analytics, recommendations, and security.

Where the GDPR or UK GDPR applies, we rely on the following legal bases under Article 6(1):

  • Performance of contract: authenticating you, storing and synchronising your User Content, processing subscription payments for Margin Pro, and providing the core features of the Service.
  • Legitimate interests: maintaining a server-side index of public AT Protocol records, generating recommendations, conducting product analytics, preventing abuse, and improving the Service.
  • Consent: for analytics cookies in jurisdictions such as the EEA and the United Kingdom. You may withdraw consent at any time.
  • Legal obligation: to comply with applicable law or valid legal process.

We do not sell personal data, and we do not share personal data for cross-context behavioural advertising.

Recipients and transfers

Four sub-processors. All are based in the United States.

We engage the following sub-processors:

  • OpenAI generates vector embeddings of User Content and of public AT Protocol records under its API data usage policy. OpenAI does not use API inputs to train its models.
  • PostHog provides product analytics. We identify users to PostHog by DID, handle, and display name.
  • Stripe processes subscription payments for Margin Pro. We share your DID with Stripe as customer metadata. Stripe collects and processes payment details directly; we do not handle or store card information.
  • Cloudflare provides DNS, SSL termination, and request routing for custom Reading Room domains. Cloudflare processes IP addresses and HTTP request metadata for visitors to Reading Rooms served on custom domains.

Where personal data is transferred from the European Economic Area, the United Kingdom, or Switzerland to a country without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses (Decision 2021/914), supplemented by the UK International Data Transfer Addendum or the Swiss equivalent, as applicable.

We may also disclose personal data where required by law, to enforce these Terms, to protect users, or in connection with a merger, acquisition, or sale, subject to commitments at least as protective as this Policy.

Retention

Only as long as necessary, with short tails for backups, logs, and analytics.

  • Index of User Content: while the underlying record exists on the AT Protocol. Deletions propagate within 7 days, with up to 30 days in routine backups.
  • OAuth sessions: until expiry, revocation, or 90 days of inactivity.
  • Embeddings and recommendation profile: deleted within 30 days of account deletion.
  • Product analytics events: up to 12 months.
  • Server and security logs: up to 90 days.
  • margin.cafe account data: for the life of the account, deleted within 30 days of a verified deletion request, subject to any legal retention obligations.
  • Billing data (Stripe customer ID, subscription status): retained for the life of the subscription and deleted within 30 days of cancellation, subject to Stripe's own retention practices.

Once a record has federated to the wider AT Protocol, third parties may retain copies outside our control even after deletion from your Personal Data Server.

Browser extension

URLs are hashed locally before lookup. Hashing reduces, but does not eliminate, what we can infer.

The Margin browser extension requests the following permissions: storage, tabs, cookies, contextMenus, activeTab, scripting, and on Chrome sidePanel. Host access is requested for all URLs so that notes can be displayed on any page.

To check whether a page contains annotations, the extension normalises the URL, computes a SHA-256 hash locally, and transmits only that hash to our server. We do not receive the underlying URL during this lookup. We note for transparency that SHA-256 is a one-way function but the URL space is enumerable: a party with a list of candidate URLs can match hashes back to URLs. Hashing therefore reduces, without fully eliminating, what we can infer about your browsing. We treat URL hashes as personal data. You may disable overlays in the extension settings.

When you create a note, the full URL is included in the record stored on your Personal Data Server, because the URL is the subject of the annotation.

Cookies

Strictly necessary cookies for sign-in. Analytics cookies require consent in the EEA and UK.

We use a session cookie to maintain your authenticated session. PostHog sets analytics cookies. In the EEA, the United Kingdom, and other jurisdictions where prior consent is required, analytics cookies load only after you opt in. You may withdraw consent at any time through the cookie controls.

Public content

Notes federate publicly. Federated copies may persist after you delete.

Notes published through the AT Protocol are broadcast on the public firehose and may be retrieved, copied, indexed, or cached by any third party subscribing to the network. Do not include in a note any information you do not wish to be public.

Your rights

Access, rectification, erasure, restriction, portability, objection, and withdrawal of consent.

Subject to applicable law, you may exercise the following rights in respect of personal data we hold about you: access, rectification, erasure, restriction of processing, portability, objection to processing based on our legitimate interests (including profiling), and withdrawal of consent where processing is based on consent. You may also lodge a complaint with your competent supervisory authority. Your AT Protocol repository remains independently exportable from your Personal Data Server at any time.

To exercise these rights, contact [email protected]. We will respond within the timeframes required by applicable law (one month under the GDPR, extendable by a further two months for complex requests). We may need to verify your identity. We will not discriminate against you for exercising your rights.

If you reside in California, the CCPA and CPRA grant additional rights, including the right to know, delete, correct, and limit the use of sensitive personal information. We do not sell or share personal information for cross-context behavioural advertising.

Children

Not directed to children under 13, or under 16 in the EEA and UK.

The Service is not directed to children under 13 years of age, or under 16 in the European Economic Area, the United Kingdom, or other jurisdictions with a higher age of digital consent. We do not knowingly collect personal data from such children. If you believe a child has provided us with personal data, please contact [email protected] and we will take appropriate steps to delete it.

Contact

Padding Labs LLC
[email protected]

We may amend this Policy from time to time. The "Last updated" date reflects the most recent revision. For material changes we will provide reasonable advance notice.