This privacy policy applies to the marble work application: the web application at open.marblework.app and the accompanying apps for iOS and Android. Our website at marblework.app is covered by a separate website privacy policy.
marble work is a workspace for marketing teams: projects and tasks, time tracking, working hours and absences, AI agents, and connections to third-party services such as Google.
When you use marble work, we process personal data in two distinct roles:
As controller for the data that arises about you when you sign up and use the service: your account details, your organisation, your subscription, technical logs.
As processor for everything you put into marble work: projects, tasks, time entries, client data, files, chat histories. You, or your company, alone decide the purposes and means of that processing. We process this data solely on your instructions.
For the second role we enter into a data processing agreement with you under Art. 28 GDPR. Request it at hello@marble.one.
marbleOne
Ricardo Köhne
Pagenstraße 6
49545 Tecklenburg, Germany
Phone: +49 151 287 98554
Email: hello@marble.one
The controller is the natural or legal person who alone or jointly with others determines the purposes and means of processing personal data.
For a user account we process your email address, your name, an optional profile picture and credentials in encrypted form, along with your role within the organisation and your language setting. The legal basis is Art. 6(1)(b) GDPR (performance of a contract).
Everything you create in marble work: projects, tasks and subtasks, comments, client records, uploaded files, notes, chat histories with AI agents and the memories an agent derives from those conversations. We process this data as a processor on your behalf.
marble work records project time, working hours including breaks, working time models and absences, among them holiday and sick days. Information about illness constitutes health data and therefore a special category of personal data under Art. 9 GDPR.
We store only that an absence of the category "sickness" occurred on a given day. We store no diagnoses, no medical certificates and no further health information. Whether and on what legal basis such data about employees may be collected is decided by your company as the controller; in Germany this is typically based on Sec. 26 BDSG in conjunction with Art. 9(2)(b) GDPR.
When the application is accessed, log data arises on the server: IP address, timestamp, resource requested, browser type. It serves operation and defence against attacks and is deleted after 14 days at the latest. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in secure operation).
marble work uses no analytics or tracking tools. We use only technically necessary browser storage: for sign-in, language selection and caching your data locally. No profiling takes place, and we do not share data for advertising purposes.
The application runs on servers operated by Hetzner Online GmbH, Industriestraße 25, 91710 Gunzenhausen, Germany. The servers are located in Germany.
Database, authentication and file storage run on Supabase, Inc., 970 Toa Payoh North #07-04, Singapore. Our project is provisioned in the eu-central-1 (Frankfurt am Main) region, so your data resides in the European Union. We have concluded a data processing agreement and standard contractual clauses with Supabase. Further information: supabase.com/privacy
At your explicit request, by clicking "Connect with Google" , marble work connects to your own Google account. Only after that, and only within the permissions you confirmed in the Google dialog, do we access your Google data. The legal basis is your consent under Art. 6(1)(a) GDPR.
We process:
Google Analytics (analytics.readonly): reporting data from your own GA4 properties (sessions, users, channels, landing pages) to display it in marble work and, at your request, have AI agents summarise it. Read-only; we never change settings. We use the Admin API solely to show you the list of properties to choose from.
Google Search Console (webmasters.readonly): performance data for your verified properties (clicks, impressions, CTR, average position) for SEO reports. Read-only.
Google Ads (adwords): reporting data from your own Ads accounts: campaign and ad group performance, search terms, account status. Read-only; we never create or modify campaigns, budgets or bids.
Google Sheets, Docs and Slides (spreadsheets, documents, presentations): creating and reading files in your own Google account when you ask an agent to do so, for example a campaign report as a Google Sheet, a content draft as a Google Doc, a client presentation as Google Slides. Write access is required because creating the deliverable in your own account is precisely the feature you asked for.
Google Drive (drive.file): only files that marble work created itself or that you explicitly opened for marble work. We cannot browse your Drive. We deliberately use drive.file rather than broader Drive scopes and accept the trade-off that you identify files by ID or URL instead of picking them from a browser.
We do not sell or transfer this data, do not use it for advertising and do not use it to train AI models. marble work's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Your access and refresh tokens are stored encrypted in a separate secrets vault. You can disconnect at any time in marble work under Settings → Connectors, which deletes the stored tokens. Independently of that, you can revoke access at myaccount.google.com/permissions.
Besides Google, you can connect marble work to further services. This too happens only at your explicit instigation, and you supply the respective credentials yourself. Available services include Asana, Atlassian (Jira/Confluence), Figma, GitHub, Hugging Face, Intercom, Linear, Meta Ads, Notion, PayPal, Square and Webflow.
Which data flows depends on the service and the permissions you granted. The respective provider's privacy terms apply in addition. The legal basis is your consent under Art. 6(1)(a) GDPR; you can disconnect any connection at any time in the settings.
marble work may send content to language models when you use a corresponding feature, for instance when you task an agent or use the chat. The services used are those of Anthropic PBC (Claude) and OpenAI, L.L.C.
You supply the API keys for these providers yourself within your organisation, so the processing takes place under your own contract with the respective provider. Only what is necessary for the requested task is transmitted: the task text, selected project data, or your instruction in the chat.
Please note: whatever you hand to an agent leaves our systems. Only pass on particularly sensitive data if you can take responsibility for it towards the respective provider.
marble work sends notifications by email, for example invitations to an organisation or updates on tasks. Delivery runs through Brevo GmbH, Köpenicker Straße 126, 10179 Berlin, Germany. We process your email address, your name and the reason for the notification; the data is processed on servers in Germany. We have concluded a data processing agreement with Brevo. You control which notifications you receive in your profile. The legal basis is Art. 6(1)(b) GDPR. Further information: brevo.com/legal/privacypolicy
Paid subscriptions are handled by Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Dublin 2, Ireland. Your payment details (card number, bank details) are processed exclusively by Stripe; we never receive them. We store only your subscription status, the number of seats booked and a Stripe identifier. The legal basis is Art. 6(1)(b) GDPR. Further information: stripe.com/privacy
The mobile apps access the same data as the web application and store your sign-in locally on the device. We use no tracking SDK, no advertising identifiers and no crash analytics with personal reference. Distribution via the App Store and Google Play is carried out by Apple and Google; those providers are responsible for the data arising there.
We store your data for as long as your account exists. Cancelling a paid subscription does not close your account: free access remains, and your data is retained; only the paid features cease once the paid period ends.
Independently of this, you can delete individual content yourself at any time. On request we will delete your account and the associated data promptly. Statutory retention periods, such as those under tax and commercial law for invoices, remain unaffected; in such cases we restrict processing rather than delete.
All transmission is TLS-encrypted end to end. Credentials for connectors and AI providers are stored encrypted in a separate secrets vault, kept apart from the remaining data. Access to data is restricted at the database level to the respective organisation and role; this restriction applies even when a request bypasses the application.
You have the right at any time to information about your stored personal data, its origin and recipients and the purpose of processing, as well as a right to rectification and erasure of that data.
You have the right to request restriction of processing and a right to data portability: we will provide the data we process automatically on the basis of your consent or in performance of a contract in a common, machine-readable format.
You may withdraw consent at any time. The lawfulness of processing carried out before withdrawal remains unaffected.
Where processing is based on Art. 6(1)(e) or (f) GDPR, you have the right to object at any time on grounds relating to your particular situation.
You also have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your residence, place of work or the place of the alleged infringement.
To exercise these rights, contact hello@marble.one. If you are an employee of a company that uses marble work, please address your request to that company first; it is the controller for the data processed about you there. We forward requests accordingly.
We adapt this privacy policy when the application or the legal situation changes. The current version is always available here.
Last updated: August 2026