Privacy & data handling

Effective date:

Iluvatar Labs operates Marvin, including the hosted Marvin Cloud service and marvinsci.com. This policy describes how Marvin handles personal data and customer content in that service. Customer-hosted Marvin is outside this scope unless a contract says otherwise.

For an organizational customer, Marvin follows the customer's instructions for Customer Content. Marvin determines the purposes of account administration, security, billing, support, and website operations, subject to applicable law and contract.

Data we handle

CategoryExamplesPurpose
Account and identityName, email, login-provider identifier, Account membership, role, and authentication session dataCreate, authenticate, secure, and administer Accounts
Customer contentResearch questions, prompts, files, datasets, project settings, transcripts, code, reports, figures, and findingsPerform and preserve customer-directed research
Connected-service dataRecords read from or written to a customer-selected service; resource identifiersPerform requested integration actions
CredentialsCustomer model/compute keys, OAuth grants, and integration secretsAuthenticate approved external routes
Usage and telemetryProvider/model, token/cost/duration records, session/project identifiers, UI events, and approved metadataMeter, operate, secure, troubleshoot, and improve reliability
Operations and securityLogs, timestamps, health, backup, release, error, and network/device dataSecure, debug, recover, and administer the service
Billing and supportSubscription status, contact details, support requests, and delivery metadataAdminister service and respond to customers

Data comes from customers, login providers, connected services, approved infrastructure and processing providers, public research sources, and Marvin's own service events. Marvin uses it only for service delivery, security, support, recovery, billing, and legal or contractual obligations. Marvin does not sell personal data or use it for advertising.

Storage and processing

The shared control plane stores Account, identity, access, billing, provider, and release data in Postgres. An Account-scoped backend and persistent volume hold workspace data. Object storage can hold datasets, durable artifacts, database replicas, and backups.

A configured model route can receive prompts, relevant customer content, tool results, generated output, and usage metadata. A compute route can receive the inputs, code, credentials, environment, logs, and outputs needed for a selected job. Research paths can send the minimum necessary queries, identifiers, URLs, and selected context to literature, search, private-research, and public-web destinations.

Customer-directed integrations read or write data within the permissions the customer grants. Disconnecting within Marvin does not necessarily revoke a provider-side grant or delete data already delivered to that provider.

Security and encryption

Marvin provides end-to-end encrypted handling between the customer endpoint and the authorized Marvin workload that performs requested processing. This covers encrypted ingress and managed service hops plus encryption of persistent storage and backups. Customer content is decrypted only inside authorized workloads as needed to provide the service. This is not zero-knowledge or customer-only-key encryption.

A transfer from Marvin's managed service to an external processing recipient uses approved encrypted transport and ends Marvin's technical encryption boundary at the handoff. Core hosting and storage services can operate inside the managed boundary.

Marvin protects access with Account-aware authorization, least privilege, controlled credentials, secure change practices, monitoring, incident response, and recovery controls.

Google sign-in and Google Drive

  • Google sign-in. When a customer signs in with Google, Marvin receives the customer's name, email address, and Google account identifier through the standard OpenID Connect openid, email, and profile scopes. Marvin does not receive or store the customer's Google password and does not request access to Gmail, Google Calendar, Google Contacts, or YouTube data.
  • Optional Google Drive connection. If a customer chooses to connect Google Drive, Marvin requests read-only access to the customer's Google Drive, including file contents, so the customer can reference those files in research sessions the customer initiates.
  • Use and disclosure. Marvin uses Google sign-in data to create, authenticate, secure, and administer the customer's account, display the customer's identity, and communicate about the account. It discloses Google sign-in identifiers only to infrastructure providers that operate Marvin. Marvin uses Google Drive data only to provide customer-initiated research and does not use it for advertising. Content a customer introduces into a Marvin session, including Google Drive content, may be processed by an external model provider under the applicable disclosed route and terms.
  • AI/ML model training. Marvin does not use Google Workspace API data to develop, improve, or train generalized or non-personalized AI or ML models, and does not transfer that data to third parties for those purposes. If a customer directs Google Drive content to an external model provider, the transfer is only to provide the customer-initiated research feature.
  • Storage and protection. Marvin stores the customer's name, email address, and Google account identifier in the account database under the access controls described in this policy. Marvin does not store Google OAuth access or refresh tokens for sign-in. Credentials for an optional connected service, including Google Drive, are encrypted when stored.
  • Retention and deletion. Google sign-in data is retained while the customer's account is active. A Google Drive connection is retained until the customer disconnects it. Account and personal-data deletion requests follow the process and timeframe described below.

External recipient classes

  1. Customer-selected providers and endpoints are governed by their terms and the customer's configuration.
  2. Fixed or optional Marvin-selected services are reviewed, contractually controlled, and disclosed by Marvin.
  3. Agent-selected public research destinations are authorized by the customer's research request but are not individually selected by the customer. Marvin records or exposes the destination and treats a recurring or fixed service as a vendor-review and register entry, rather than treating every open-web site as a contracted subprocessor.

Marvin remains responsible for accurate routing and for duties assigned by law or contract.

Except for the Google Workspace API data restrictions stated above, Marvin does not make a universal promise about an external provider's model-training use, retention, processing location, or international transfers. Marvin-selected providers are reviewed and disclosed with their applicable terms. Customers review the terms and permissions of customer-selected recipients before directing data to them.

Retention and deletion

Marvin retains Account data while an Account is active and retains project data while needed to provide the project or Account. Security, billing, support, and legal records are retained only for their approved purpose. Backup copies expire under the backup retention schedule rather than being modified in place.

Customers can delete projects and disconnect integrations through available product controls. A verified Account or personal-data deletion request triggers reconciliation across active databases, Account backends and volumes, object storage and backups, credentials and keys, provider grants, logs, and required legal records. Marvin completes a verified deletion request within 30 days, except where law or contract requires retention or permits a different period. Data that must be retained is restricted to the applicable purpose and deleted when that obligation ends.

Provider-side deletion or revocation may also require action in the provider's service and follows the provider's applicable process and terms. Marvin identifies both its responsibility and any required customer action in the applicable connection or provider disclosure.

Rights, choices, and contact

Depending on applicable law and Marvin's role, individuals may request access, correction, export, restriction, objection, or deletion. Marvin verifies the requester's identity, records the systems searched, documents actions and legal exceptions, and responds within the period required by applicable law or contract.

Privacy, data, and account-deletion requests: [email protected]

Location, transfers, and changes

Marvin makes no universal data-residency promise. Marvin-selected providers are reviewed for processing locations, onward transfers, and required contractual protections. Customer-selected recipients may process data wherever their terms and the customer's configuration permit.

Agent-selected public destinations process data under their own published terms and locations.

Material changes to this policy receive a new document date and any notice required by law or contract.