← Back to Mrkup.aiPrivacy Policy
Last updated: 28 June 2026
1. Who we are
Mrkup.ai is a web-based HTML annotation and review platform operated from Zürich, Switzerland. As data controller, we are responsible for the personal data we collect when you use the service. Questions? privacy@mrkup.ai
2. Data we collect
- Account — name, email address, hashed password (if password auth is used).
- Projects — HTML files you upload, annotations, comments, version history, and AI-generated revisions.
- Usage — pages visited and features used. Collected anonymously and only with your consent via the cookie banner.
- Technical — IP address, browser type, and device information, retained for up to 90 days for security and abuse prevention only.
- Payment — plan status and Stripe customer ID. Card data is processed directly by Stripe and never touches our servers.
3. Legal basis (GDPR Art. 6)
- Performance of contract (Art. 6(1)(b)) — to create and maintain your account and deliver the service.
- Legitimate interests (Art. 6(1)(f)) — fraud prevention, abuse detection, and product improvement using aggregated data.
- Consent (Art. 6(1)(a)) — for optional analytics cookies. You may withdraw consent at any time via the cookie banner.
4. How we use your data
- To operate and improve Mrkup.ai.
- To send transactional emails (magic-link sign-in, share notifications, account alerts).
- To process payments via Stripe.
- To detect and prevent abuse, fraud, and security incidents.
- To generate aggregate, anonymised product analytics (with consent).
5. AI processing
When you trigger AI Apply, the HTML content and annotations you select are sent to the AI model provider you choose (Anthropic, OpenAI, Google, or Mistral). This happens only on your explicit instruction. We do not use your content to train AI models, and we do not retain copies with AI providers beyond the time required to return a response.
6. Sub-processors and data sharing
We do not sell your data. We share data only with third-party processors required to operate the service:
- Vercel — hosting and edge network (USA, EU SCCs).
- Neon — PostgreSQL database (USA, EU SCCs).
- Resend — transactional email delivery (USA, EU SCCs).
- Stripe — payment processing (USA, EU SCCs).
- Anthropic / OpenAI / Google / Mistral — AI inference on your explicit instruction (USA, EU SCCs).
- Sentry — error monitoring, anonymised stack traces only (USA, EU SCCs).
7. Cookies
- Strictly necessary — session cookie (expires on browser close) and locale preference cookie (1 year). These cannot be disabled.
- Analytics — anonymous usage data collected only with your consent. Declined by default; opt in via the cookie banner.
- No advertising or third-party tracking cookies are used.
8. Data retention and deletion
- Account data is retained while your account is active.
- Uploaded HTML files and project data are retained until you delete them or close your account.
- On account deletion, all personal data is removed within 30 days. Encrypted backups are purged within 90 days.
- To request deletion at any time, email privacy@mrkup.ai.
9. Your rights
Under the GDPR and the Swiss Federal Act on Data Protection (nFADP), you have the right to:
- Access — request a copy of the personal data we hold about you.
- Rectification — ask us to correct inaccurate data.
- Erasure — ask us to delete your data ("right to be forgotten").
- Portability — receive your data in a structured, machine-readable format.
- Restriction — ask us to limit how we process your data.
- Objection — object to processing based on legitimate interests.
- Withdraw consent — withdraw analytics consent at any time via the cookie banner.
- Supervisory authority — lodge a complaint with your national data protection authority. In Switzerland: the Federal Data Protection and Information Commissioner (FDPIC) at fdpic.ch.
10. Security
- All data is transmitted over HTTPS with TLS 1.3.
- Data at rest is encrypted with AES-256.
- Access to production systems is restricted to authorised personnel with MFA.
- We will notify you of any personal data breach within 72 hours where required by applicable law.
11. Children
Mrkup.ai is not directed at individuals under 16 years of age. We do not knowingly collect personal data from under-16s. If you believe we have inadvertently done so, contact privacy@mrkup.ai and we will delete the data promptly.
12. International transfers
Our sub-processors are primarily located in the United States. Data transfers to the USA are governed by Standard Contractual Clauses (SCCs) approved by the European Commission, ensuring an equivalent level of data protection.
13. Changes to this policy
We will notify you by email at least 14 days before any material change to this policy takes effect. The date at the top of this page always reflects the most recent update.
14. Contact
Data protection enquiries: privacy@mrkup.ai — Mrkup.ai, Zürich, Switzerland.