Legal
Effective May 1, 2026 · Last updated July 8, 2026
Padding Labs LLC is the controller. We process the minimum needed to run Margin and do not sell your data.
This Privacy Policy describes how Padding Labs LLC ("we", "us", "our") processes personal data in connection with Margin and the Margin Personal Data Server at margin.cafe (together, the "Service"). For purposes of the EU and UK General Data Protection Regulations, we are the controller of personal data we process to operate the Service.
Identity from your AT Protocol account, the content you publish, and basic usage data.
We process the following categories of personal data:
We do not knowingly process special categories of personal data (such as health, biometric, or government identification data), and ask that you do not include such information in your User Content.
Performance of contract for the core Service. Legitimate interests for analytics, recommendations, and security.
Where the GDPR or UK GDPR applies, we rely on the following legal bases under Article 6(1):
We do not sell personal data, and we do not share personal data for cross-context behavioural advertising.
Four sub-processors. All are based in the United States.
We engage the following sub-processors:
Where personal data is transferred from the European Economic Area, the United Kingdom, or Switzerland to a country without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses (Decision 2021/914), supplemented by the UK International Data Transfer Addendum or the Swiss equivalent, as applicable.
We may also disclose personal data where required by law, to enforce these Terms, to protect users, or in connection with a merger, acquisition, or sale, subject to commitments at least as protective as this Policy.
Only as long as necessary, with short tails for backups, logs, and analytics.
Once a record has federated to the wider AT Protocol, third parties may retain copies outside our control even after deletion from your Personal Data Server.
URLs are hashed locally before lookup. Hashing reduces, but does not eliminate, what we can infer.
The Margin browser extension requests the following permissions: storage, tabs, cookies, contextMenus, activeTab, scripting, and on Chrome sidePanel. Host access is requested for all URLs so that notes can be displayed on any page.
To check whether a page contains annotations, the extension normalises the URL, computes a SHA-256 hash locally, and transmits only that hash to our server. We do not receive the underlying URL during this lookup. We note for transparency that SHA-256 is a one-way function but the URL space is enumerable: a party with a list of candidate URLs can match hashes back to URLs. Hashing therefore reduces, without fully eliminating, what we can infer about your browsing. We treat URL hashes as personal data. You may disable overlays in the extension settings.
When you create a note, the full URL is included in the record stored on your Personal Data Server, because the URL is the subject of the annotation.
Notes federate publicly. Federated copies may persist after you delete.
Notes published through the AT Protocol are broadcast on the public firehose and may be retrieved, copied, indexed, or cached by any third party subscribing to the network. Do not include in a note any information you do not wish to be public.
Access, rectification, erasure, restriction, portability, objection, and withdrawal of consent.
Subject to applicable law, you may exercise the following rights in respect of personal data we hold about you: access, rectification, erasure, restriction of processing, portability, objection to processing based on our legitimate interests (including profiling), and withdrawal of consent where processing is based on consent. You may also lodge a complaint with your competent supervisory authority. Your AT Protocol repository remains independently exportable from your Personal Data Server at any time.
To exercise these rights, contact [email protected]. We will respond within the timeframes required by applicable law (one month under the GDPR, extendable by a further two months for complex requests). We may need to verify your identity. We will not discriminate against you for exercising your rights.
If you reside in California, the CCPA and CPRA grant additional rights, including the right to know, delete, correct, and limit the use of sensitive personal information. We do not sell or share personal information for cross-context behavioural advertising.
Not directed to children under 13, or under 16 in the EEA and UK.
The Service is not directed to children under 13 years of age, or under 16 in the European Economic Area, the United Kingdom, or other jurisdictions with a higher age of digital consent. We do not knowingly collect personal data from such children. If you believe a child has provided us with personal data, please contact [email protected] and we will take appropriate steps to delete it.
We may amend this Policy from time to time. The "Last updated" date reflects the most recent revision. For material changes we will provide reasonable advance notice.