Privacy Policy
Version of September 17, 2026
This policy explains which personal data Marqa processes, why, who we share it with and how you can exercise your rights under Brazil's General Data Protection Law (Law 13,709/2018, LGPD).
Who runs Marqa
Reach us through the contact form.
1. Controller and data protection officer
The controller is the party identified in the "Who runs Marqa" box on this page. To reach the data protection officer, use the contact form and choose "Privacy and my data (LGPD)".
When an agency registers its own clients and professionals, the agency is the controller of that work data and Marqa acts as a processor on the agency's instructions.
Brands that sign up directly on Marqa, without an agency's invitation, are looked after by Marqa's own team: that team can see and edit the brand's data to give support and, if the brand chooses to have an agency handle its work, to deliver it. No other agency can see that data.
2. Data we process
- Sign-up: name, email, username, password (stored only as a hash), account type, date and version of the terms you accepted.
- Usage: sign-in records, source IP (for security and rate limits), first-session events, theme and language preferences.
- Content: briefs, uploaded files and images, deliverables, comments, messages, reports and AI output.
- Spoken brief: the transcript of what you say. Your browser's speech recognition produces it (in Chrome, a Google service); Marqa only receives the text and does not record audio.
- Messaging (when an agency connects it): contact names and numbers/identifiers and the text of WhatsApp/Instagram messages.
- Payments: plan, amounts, status and transaction ID. Card and Pix details stay with Mercado Pago; we never receive them.
- Contact: name, email and message sent through the form, and agency public pages (name and WhatsApp number of people asking for a quote).
3. Purposes and legal bases
- Providing the service (accounts, AI generation, approvals, reports) — performance of a contract (art. 7, V).
- Charging for plans and coins and keeping financial records — contract and legal obligation (art. 7, II and V).
- Security, fraud and abuse prevention, rate limits and access logs — legitimate interest and the legal obligation in Brazil's Internet Civil Framework (art. 7, II and IX).
- Answering contact and access requests — pre-contract steps and legitimate interest (art. 7, V and IX).
- Improving the product with aggregated usage metrics — legitimate interest (art. 7, IX).
We do not sell personal data and we do not use it for third-party advertising.
4. Who we share data with (sub-processors)
- Anthropic (United States) — AI models that produce strategy, copy and analysis from the content you provide.
- Mercado Pago (Brazil) — payment processing in BRL. Stripe (United States) may be used for other currencies once enabled.
- ElevenLabs and OpenAI (United States) — text-to-speech in the spoken brief, when voice is enabled.
- Meta / WhatsApp and Instagram (United States and other countries) — sending and receiving messages, when an agency connects the official API.
- Google (United States) — Google Analytics data and image generation, only when that account is connected.
- Hostinger — hosting of the server that stores the database and files.
We may also disclose data when the law or a competent authority requires it.
5. International transfers
Some providers above process data outside Brazil. These transfers are needed to perform our contract with you (LGPD art. 33, II and IX) and go to providers that use contractual clauses and security measures compatible with the LGPD. Please avoid putting sensitive data in briefs and messages.
6. Retention
- Account data and content: while the account exists. When you delete your account we erase it together with your own workspace (self-registered brand or professional profile).
- Financial records: kept for the period tax law requires (usually 5 years), unlinked from you after account deletion.
- Access logs (date, time and IP of sign-ins): 6 months, as Brazil's Internet Civil Framework requires, then deleted.
- Contact messages: up to 2 years after they are answered.
- Backups: rotated within a few weeks; deleted data leaves them at the end of that cycle.
7. Your rights
You can ask for confirmation of and access to your data, correction, anonymisation, blocking or deletion, portability, information about sharing, and withdrawal of consent (LGPD art. 18).
Under My account you can download your data as JSON and delete your account yourself. For anything else, use the contact form with "Privacy and my data (LGPD)"; we answer within 15 days. You may also complain to Brazil's data protection authority (ANPD).
If an agency created your account, some work data belongs to that agency and we may forward your request to it.
8. Security
We use encrypted connections (HTTPS), strong password hashing, sessions that expire and can be revoked, limits against repeated attempts and role-based access control. No system is fully immune; if a relevant incident happens we will notify the people affected and the ANPD as the law requires.
9. Cookies
We only use an essential sign-in cookie and local storage for theme and language. See the Cookie Policy.
10. Children
Marqa is meant for adults (18+) and businesses. We do not knowingly collect data from minors.
11. Updates
This policy may change. The date of the current version is at the top; relevant changes are announced in the platform.