Margo Hart privacy notice · updated August 8, 2026
How the Margo Hart service handles your data
Who is responsible
The Margo Hart service is responsible for the processing described here. Privacy questions and requests can be sent to privacy@margohart.com. The current service operator and payment details are also shown at checkout where applicable.
What we process
Depending on what you use, we process account and email data; a limited encrypted guest exchange; messages with Margo Digital; account conversation history and memories when enabled; consent choices; requests for human follow-up; replies written personally by Margo on eligible plans; subscription, optional-content purchase, or voluntary-support payment metadata; support correspondence; and technical security data.
Sensitive conversation content
Relationship, intimacy, desire, and emotional conversations may reveal highly private information. Say only what you want to share. Do not provide another person’s private information unless you have a lawful reason to do so. The service does not ask for medical records, identity documents, precise location, or financial credentials in chat.
Guest mode
Before the first guest message, you are asked to accept encrypted storage of that limited guest chat for 30 days. This lets the conversation continue and supports safety, aggregate statistics, and service debugging. Guest storage does not enable long-term memory, sensitive memory, proactive messages, or sharing with Margo or another human. Guest messages are not used by us to train external foundation models. Basic anti-abuse and security records are kept separately.
AI processing and providers
Conversation text is sent through the configured secure API gateway and AI model provider to generate a reply. On the Margo Personal plan, when conversation storage is enabled, messages may instead be processed in our model-bound FanLTV conversation infrastructure so Margo Digital can keep continuity and the eligible human follow-up workflow can operate. The integration receives an opaque account identifier, not your email or password. Hosting, database, email, and payment providers process only the data needed for their role. Payment providers receive checkout and transaction data; we do not receive full card details. Contact us for the current processor list and applicable international-transfer safeguards.
Advertising attribution
When you arrive through a TrafficJunky campaign, the service stores the campaign click identifier (ACLID) in your private session for up to 30 days. It is attached to payment attribution metadata and returned to TrafficJunky only after a confirmed transaction. The conversion request contains a transaction reference, a generic product description, the configured conversion value, and ACLID; it does not contain your email, chat messages, or profile details. No conversion is reported merely for viewing the landing page.
Human access
Private conversations are not routinely read by Margo or a human moderator and are not shown as plaintext in the normal tenant dashboard. Selected records may be accessed by specifically authorized staff under a controlled, logged procedure when needed to investigate a reported defect, service-quality problem, credible safety or security issue, fraud, support you request, or a legal obligation. A summary for ordinary human follow-up is shared only when you explicitly approve it. Human-written and AI-written replies are labeled separately.
Why we process it
Account access, requested replies, security, billing, and support are processed to provide the service you ask for and protect it. Guest storage depends on the specific notice shown before the first message. Account history, memory, proactive messages, and sharing a summary for human follow-up depend on their separate controls. Fraud prevention, accounting, legal compliance, and system security may be processed where necessary for legitimate interests or legal obligations.
Retention
Encrypted guest messages and replies expire after 30 days and are then cryptographically tombstoned by the daily retention process. Account conversations and memories remain while the related account and storage choice are active, until you delete them or request account deletion, subject to backup and legal limits. Consent records and privacy-request records are retained to demonstrate your choices. Payment, tax, fraud, dispute, and security records may be retained for the period required by law or reasonably needed to resolve the issue, then deleted or de-identified.
Automated processing
Margo Digital generates replies automatically and may apply automated safety routing. It is not used to make decisions that produce legal or similarly significant effects about you. AI can make mistakes, and you should not rely on it for medical, legal, financial, emergency, or crisis decisions.
Your controls and rights
Your account provides separate controls for conversation storage, memory, sensitive memory, proactive check-ins, and sharing a summary for requested human follow-up. Depending on applicable law, you may request access, correction, export, deletion, restriction, objection, or consent withdrawal, and may complain to the competent data-protection authority. We verify ownership before disclosure or deletion. Contact: privacy@margohart.com.
Public-page analytics
Public marketing pages use Yandex.Metrika counter 111408457, including Webvisor, click maps, and link tracking. It may process the page URL and referrer, browser and device data, IP address, cookies, clicks, and a recording of page interaction. The counter is not loaded in account, quiz, payment, conversation, support, privacy-request, or administration surfaces.