Legal

Privacy policy.

The short version: I collect what I need to run your account and make your campaigns, nothing more. I never sell your data, and nothing that tracks you loads until you say yes.

The longer version is below, because the law quite reasonably asks us to be specific: what we hold, why we are allowed to hold it, who else touches it, where it goes, how long it stays, and how to make us stop. We have tried to write it the way we would explain it to you out loud.

Last updated: 26 July 2026

1. Who we are

heymarta.ai (“Marta”, “we”, “us”) is the data controller for the personal data described in this policy. That means we are the ones who decide what is collected and why, and we are the ones answerable for it.

We operate from the United Kingdom, so the UK GDPR and the Data Protection Act 2018 apply to what we do. Where we serve people in the European Economic Area, the EU GDPR applies as well.

The way to reach us about anything in this policy is hello@heymarta.ai. We are small enough that this is a person rather than a queue. We have not appointed a Data Protection Officer, because at our size the law does not require one; the same address reaches whoever is responsible.

Our full registered company name, company number and postal address will be published in this section. Until they are, hello@heymarta.ai is the contact of record for every request described here, and no request will be turned away for arriving at that address.

2. What we collect, why, and on what legal basis

Each block below is one thing the service actually does. “Legal basis” is the specific reason UK and EU law lets us do it, and it matters, because your rights change depending on which basis we are relying on.

Your account

What
Your email address, a hashed version of your password (we never store the password itself), and whether you have confirmed your address. If you sign in with Google, we receive your email address and basic profile from Google instead, and we never see your Google password.
Why
To create your account, sign you in, and send the email that confirms the address is really yours.
Legal basis
Performance of a contract, Article 6(1)(b). We cannot give you an account without it.
How long
For as long as you have an account, then deleted when you ask us to close it.

Credits, payments and receipts

What
A ledger of every credit you bought, were granted, or spent, with the timestamp and the job it belonged to. For purchases, the Stripe checkout and payment reference. Your card details are typed into Stripe’s own payment page; they never reach our servers and we never store them.
Why
To keep your balance correct, show your receipts, handle refunds and disputes, and keep the financial records a UK business is required to keep.
Legal basis
Performance of a contract, Article 6(1)(b), and for the accounting records, a legal obligation, Article 6(1)(c).
How long
At least six years after the end of the relevant financial year, because UK tax law requires it. This is the one category that survives account deletion.

Your work: prompts, references and generated assets

What
The prompts you write, the brand and product URLs you point Marta at, the reference images you upload, and the assets she generates back. Also a record of each job: what you asked for, when, whether it worked, what it cost, and the result returned by the generation step.
Why
To make the thing you asked for, to show you your history and receipts, and to recover jobs that fail halfway through so you are not charged for nothing.
Legal basis
Performance of a contract, Article 6(1)(b).
How long
While your account is open, so your history works, and deleted when you ask.

Keeping the service standing up

What
Your IP address at the moment you sign up, stored with the domain part of your email and a timestamp. Short-lived records when you pair Marta with a tool on your own machine. Records that stop a checkout being charged twice.
Why
To stop one person opening dozens of accounts to farm free credits, and to stop you being billed twice for the same thing.
Legal basis
Legitimate interests, Article 6(1)(f). Our interest is keeping a paid service affordable and available for the people actually using it. The data is minimal, it is never used to profile you or to market to you, and you can object to it at any time.
How long
Pairing records and rate-limit counters are cleared automatically. The signup IP records are not, yet: see section 7, where we say so plainly.

API keys, if you connect your own tools

What
A one-way hash of each key you create, the first few characters so you can tell your keys apart, and when each was last used. We cannot read your key back to you, only check that the one you present matches.
Why
To authenticate you when you use Marta from outside this website.
Legal basis
Performance of a contract, Article 6(1)(b).
How long
Until you delete the key, or until your account is deleted.

Error monitoring

What
When something breaks, a technical report of the failure: the error, the page it happened on, and the browser type. Before any report is sent, whether it came from your browser or from our own servers, we strip out credentials, API keys, email addresses and IP addresses. It sets no cookies, and it records nothing you type and nothing you see on screen.
Why
To find and fix faults in a service you are paying for.
Legal basis
Legitimate interests, Article 6(1)(f), in keeping a paid service working.
How long
Held by our error monitoring provider for a limited retention window set in that service, then deleted. We do not copy these reports anywhere else.

Waitlists

What
Your email address, which part of the product you left it from, and the fact and timestamp of your consent.
Why
To send you the update you asked for, and nothing else.
Legal basis
Consent, Article 6(1)(a), and for the email itself, your consent under the UK Privacy and Electronic Communications Regulations. You can withdraw it at any time.
How long
Until you unsubscribe or ask us to remove you.

Hosting and delivery

What
Standard request logs kept by our hosting provider, including your IP address, the address you requested, and how long it took.
Why
To serve the site at all, to keep it up, and to absorb attacks against it.
Legal basis
Legitimate interests, Article 6(1)(f), in running and defending the service.
How long
On the short rolling schedule set by that provider. These logs are not copied into our own database.

Product analytics, only if you say yes

What
Which pages you view, when you leave them, how far you scroll, where you arrived from including any campaign tags in the link, and the elements you interact with. Our analytics tool captures interactions automatically, which means it records what you clicked (the button, the link, its label) and not what you typed into it. If you are signed in, these events are tied to your account id, and your email address is attached to your analytics profile as a detail we already hold. Session recording is switched off.
Why
To see which parts of Marta genuinely help people and which parts we should fix or remove.
Legal basis
Consent, Article 6(1)(a), and your consent under the UK Privacy and Electronic Communications Regulations for the storage this places on your device. Nothing is downloaded, set or sent before you answer the banner.
How long
Withdrawing consent stops collection immediately and clears the identifiers from your browser. Events already recorded sit with the provider until you ask us to delete them, which we will.

Advertising measurement, only if you say yes

What
Advertising pixels from Meta and TikTok. They record that a browser visited a page and that a registration was completed, and they set their own cookies.
Why
To find out whether the ads we run bring in people who actually get value from Marta, so we stop paying for the ones that do not.
Legal basis
Consent, Article 6(1)(a), plus consent under the Privacy and Electronic Communications Regulations for the cookies. These load only after you accept.
How long
Set by Meta and TikTok under their own policies. Meta and TikTok also use this data for their own purposes, so on this one point they are not simply acting on our instructions, and their privacy policies govern what they do next.

3. Your uploads, and the temporary links they travel on

This one deserves its own section rather than a line in a table, because most people would not guess it.

When you upload a reference image, it is stored with our file storage provider. The generation step is a different company’s computer, and it has to be able to fetch your image over the web to work from it, so we hand it a temporary web address for that file. The address expires within a day of being issued. While it is live, anyone holding that exact address could open the image without signing in; it is not listed anywhere, not searchable, and we do not share it with anyone except the generation step that needs it.

We used to issue permanent addresses that never expired. We do not any more, and that is the honest reason this section exists rather than a claim that nothing is ever reachable.

So please keep that in mind before uploading anything you would mind a stranger seeing, and please do not upload photographs of other people unless they are happy for you to. If your references include recognisable people, you are the one deciding to use their images, and we handle them on your instructions.

4. Cookies and what sits on your device

Staying signed in. Session cookies from our authentication provider keep you logged in as you move around. They are strictly necessary to deliver a service you asked for, so the law does not require us to ask permission for them, and they are not used to track you.

Your answer to the banner. We store your consent decision and the time you made it in your browser’s local storage. It is how the banner knows not to ask again, and how we can show we asked.

Analytics and advertising. Nothing is loaded, set, or sent before you answer. Decline and none of it ever arrives. Accept and the analytics and advertising tools described in section 2 start, and they set their own cookies and local storage.

Changing your mind. Use the “Cookie choices” link at the bottom of any page. Withdrawing is one click, it takes effect at once, and it clears the analytics identifiers out of your browser. Withdrawing is as easy as giving, which is the whole point.

5. Who else processes your data

We do not run all of this ourselves. These companies process personal data on our behalf and on our instructions, each under a data processing agreement, and each only for the part of the service it provides:

  • Vercel, hosting, content delivery and request logs.
  • Supabase, authentication, the database, and file storage for your uploads. The email that confirms your address is sent by Supabase’s own mail service, so there is no separate email company in the picture.
  • Stripe, payments, refunds and disputes.
  • Sentry, error monitoring. Because ad blockers block error monitoring domains by default, these reports are routed through an address on heymarta.ai on their way out. The destination is the same, and the stripping described in section 2 happens before they leave.
  • PostHog, product analytics, only after you accept.
  • Meta and TikTok, advertising measurement, only after you accept.
  • Our generation infrastructure provider, and the model providers it routes work to, which turn your prompts, brand URLs and reference images into finished images, video and voice.

On that last one, we owe you an explanation. We do not name the individual generation and model providers on this page, because the specific mix is part of how Marta is built and it changes as models improve. That is not a way of hiding them from you. Email hello@heymarta.ai and we will send you the current named list of every provider that touches your prompts, reference images and generated assets, and where each one processes them. We keep that list up to date. Everything else about this processing, the categories of data, the purpose, the transfers and the safeguards, is set out in full on this page.

We do not sell your data, we do not share it with data brokers, and we do not use your work to train models of our own.

6. Where your data goes

Marta is run from the United Kingdom, but the companies that keep her running are not all here. Vercel, Supabase, Stripe, Sentry, PostHog, Meta, TikTok and our generation providers are all based outside the UK, and several of them are US companies. Some of them contract through European entities, but your data is stored or accessed outside the UK and the EEA either way, and you should assume that includes the United States.

UK and EU law does not treat the United States as automatically safe, so each of those transfers needs its own legal protection. For every provider above, we rely on the UK International Data Transfer Addendum and the European Commission’s Standard Contractual Clauses, which form part of that provider’s data processing terms. Where a provider is certified under the EU-US Data Privacy Framework and its UK extension, we may rely on that instead.

Alongside the paperwork there are the technical measures described in this policy: everything travels encrypted, error reports have identifiers stripped out before they are sent, and each provider gets only the data its part of the job needs.

If you want to see the transfer terms we rely on for any specific provider, ask at hello@heymarta.ai and we will send them.

7. How long we keep things

We will be straight with you about this: Marta does not yet have a self-serve delete button. Deletion is started by a person, by hand, when you ask for it, and we do it within one month. What that person runs is a single tool that clears everything below in one pass, rather than a memory and a to-do list.

  • Account, profile, prompts, reference images, generated assets and job records: kept while your account is open, then deleted when you ask us to close it. Your uploaded files are deleted outright. We keep the bare record that a generation happened and what it cost, with everything describing it or pointing at it removed, because that is part of the payment record below.
  • Payment and credit records: at least six years, because UK tax law requires it. We cannot delete these on request, and if you ask us to erase everything else, these stay. So that they still add up, a stripped-down account record stays with them: an internal reference number and nothing else. Your email address is removed from it and your sign-in is closed for good.
  • Signup IP records: deleted automatically after seven days. The rate limit itself only ever looks at the past hour; the rest of that week is so we can recognise a wave of fake signups after the fact. These records are not attached to your account — an address on its own does not identify which signup was yours — so we cannot pick yours out on request, which is exactly why they now expire on their own.
  • Device pairing records: the pairing expires ten minutes after you start it, and the record is deleted outright the moment your tool collects its key. Anything left unclaimed is swept automatically.
  • Rate-limit counters: expire after an hour and are swept the same way. The sweep runs twice a day, so neither these nor unclaimed pairing records last more than about a day past expiry.
  • Duplicate-charge records: deleted automatically after 30 days.
  • Waitlist email: until you unsubscribe or ask us to remove you.
  • Error reports and hosting logs: on the short retention windows set by those providers, then gone.
  • Analytics events: collection stops the moment you withdraw consent; events already recorded are deleted on request.

8. Automated decisions

We do not make decisions about you by solely automated means that produce legal effects or similarly significantly affect you, and we do not profile you.

We do run some automatic checks, and it is only fair you know what they are: a limit on how many accounts can be created from one internet connection in an hour, a blocklist of throwaway email domains at signup, and a cap on how many credits one account can spend in a day. These can stop a signup or pause spending.

If one of them catches you and it is wrong, email hello@heymarta.ai and a person will look at it and put it right.

9. Your rights

Under UK and EU data protection law you have all of the following. One email to hello@heymarta.ai starts any of them.

  • Access. Ask what we hold about you and get a copy of it.
  • Rectification. Have anything inaccurate corrected, or anything incomplete filled in.
  • Erasure. Have your data deleted. We will do it, with the one exception of the payment and credit records we are legally required to keep, and we will tell you exactly what stayed.
  • Restriction. Tell us to keep your data but stop doing anything with it while a dispute or a correction is sorted out.
  • Portability. Get the data you gave us in a structured, machine-readable format, or have us send it to someone else. This covers what we hold on the basis of your consent or our contract with you.
  • Objection. Object to anything we do on the basis of legitimate interests, which is the abuse controls, the error monitoring and the hosting logs. We stop unless we can show compelling grounds that override your rights. For direct marketing, there is no argument: you object, we stop.
  • Withdraw consent. At any time, for analytics, advertising and waitlist emails, and just as easily as you gave it. Withdrawing does not make what we did beforehand unlawful, it just stops it going forward.
  • Not be subject to solely automated decisions that significantly affect you. As explained in section 8, we do not make any.

These are free. We answer within one month, and if a request is genuinely complex we may take up to two months more, in which case we will tell you why inside the first month. We may need to check it is really you before we send personal data anywhere.

Where we got your data. Almost all of it comes from you. The exceptions: if you sign in with Google, your email address and basic profile come from Google, and when you buy credits, Stripe tells us that the payment succeeded and gives us the reference for it.

Do you have to give it to us? The account and payment data is needed to have an account and to buy credits; without it we cannot provide the service. Everything gated behind the consent banner is genuinely optional, and saying no costs you nothing.

10. Complaints

If you think we have got something wrong, please tell us first at hello@heymarta.ai. We would much rather fix it directly than have you hear about it from a regulator.

You also have the right to complain to the Information Commissioner’s Office, the UK data protection regulator, and you do not have to come to us first.

Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF.
Helpline 0303 123 1113. ico.org.uk

If you live in the EEA, you can complain to the supervisory authority in your own country instead.

11. Children

Marta is a tool for people running a business, and is not intended for anyone under 18. We do not knowingly collect personal data about children. If you believe a child has created an account, email hello@heymarta.ai and we will remove it.

12. How we keep it safe

Everything travels encrypted. Passwords are hashed by our authentication provider and never stored in a readable form. API keys are stored as one-way hashes, so we cannot read yours back to you. The one moment a key exists in readable form is while you are pairing Marta with a tool on your own machine: it is held only until that tool collects it, and the record is deleted the instant it does. Card details never touch our servers. Database access is restricted so one account cannot reach another account’s rows.

The one exception you should know about is upload links, which we describe in section 3. We would rather name it here than let it sit unmentioned under a sentence about how seriously we take security.

13. Changes to this policy

If this policy changes in a way that matters, we will update the date at the top and say what changed. Continued use after a change means the new version applies.