Privacy Policy
Last updated 30 July 2026
Who we are
Marcelo is a marketing automation service operated by Marcelo AI Inc, of Los Angeles, California, United States, reachable at support@meetmarcelo.ai. It is used by marketing agencies to plan, draft and publish marketing work for the businesses they represent.
This policy covers meetmarcelo.ai and the Marcelo application. It does not cover the websites Marcelo publishes to — those belong to our customers and their own policies apply.
What we collect
Three kinds of data, for three different reasons.
- Account data. Your name, email address and sign-in credentials, handled by our authentication provider. We use this to know who you are and to contact you about the service.
- Content you give us. Business details you enter, photographs you upload, website addresses you ask us to analyse, and the drafts and approvals that follow. This is the material the service works on.
- Data from services you connect. If you connect a Google account, a website or a social profile, we read the data those services expose to us. What we read from Google is set out in the next section.
We also record which features were used and what each generation cost, so that usage can be billed and attributed to the right client. We do not use advertising trackers and we do not sell data to anyone.
Google user data
Connecting a Google account grants Marcelo access to a specific, limited set of Google data. We ask for the narrowest scopes that let the features work:
- Search Console (read-only). The list of properties you can access, and search performance data — queries, impressions, clicks and average position — for the property you map to a brand. We use it to report what a site already ranks for and which terms are close to the first page.
- Analytics (read-only). The list of properties you can access, and aggregate traffic figures for the property you map to a brand. We use it to report how many people visited and where they came from. We do not read individual user identifiers.
- Analytics (create and configure). Permission to create a Google Analytics property and its web data stream, and to read the measurement ID of one. We use it for one thing: setting measurement up for a brand that has none, so that nobody has to be walked through the Analytics interface. We do not delete properties, and we do not change a property that already exists.
- Tag Manager (read-only).The list of containers you can access, and the tags published live in the one you map to a brand. We use it to tell “this site has no visitors” apart from “nothing is measuring them” — two findings that look identical in an empty Analytics report and mean opposite things. We cannot change a container.
- Site verification. Permission to prove ownership of a website in Search Console. We use it so that a client with no Google account never has to make one in order for their site to be measured. It grants nothing but proving ownership — it cannot read a site, a report or a profile.
- Google Ads.The advertising accounts you can access, their campaigns, and what those campaigns spent and returned. We use it to report on paid performance and to propose changes — a budget, a bid, a keyword, a campaign's status. Google grants Ads as a single permission that also allows changing an account; every change Marcelo makes is written down first, checked with Google without being applied, and applied only after a named person has approved it. Nothing is spent, paused or started automatically.
- Blogger. The list of blogs on the account, so that a brand whose website is a Blogger blog can be connected to it. Google grants Blogger as a single permission that also allows posting; as with everything else, Marcelo publishes only what a person has approved.
- Google Drive (files Marcelo creates). Permission to create documents in your Google Drive, and to see and manage only those documents. We use it for one thing: building a set of public Google documents about the business — an about page, a services list, an areas list — that link to the website, when somebody presses the button that makes them. This permission cannot see anything else in your Drive. Files Marcelo did not create are invisible to it, including files somebody shared with you, and it cannot list, read, change or delete them.
Marcelo's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: we use Google user data only to provide and improve the features described above; we do not transfer it to others except as needed to provide those features, for security purposes, or to comply with applicable law; we do not use it for advertising; and we do not allow humans to read it except with your explicit consent, for security purposes, to comply with applicable law, or where the data is aggregated and anonymised.
We never train AI models on your Google data, and we do not use it to train models of our own.
Who else processes it
We rely on a number of providers to run the service. Each receives only what it needs to do its job.
- Anthropic — generates text. Receives the prompts and business facts relevant to the piece being written.
- fal.ai — generates images and video. Receives your prompt and any reference image you supply.
- OpenAI — generates text, and answers the questions the AI Search Lab asks. Receives the prompts and business facts relevant to the piece being written, and the questions asked about a business.
- Perplexity — answers AI Search Lab questions. Receives the question asked about a business, which usually names it.
- Google — the services described above, when you connect them. Also Gemini, where it is set up to answer AI Search Lab questions.
- DataForSEO — the licensed route to what ChatGPT Search and Google AI Overviews answer, and the source of backlink data and search volumes. Receives the question asked, or the website address being looked up.
- BrightLocal — directory listings, where that is used. Receives the business details being submitted to directories.
- Meta — where an Instagram account or a Facebook Page is connected, so that approved posts can be published to it. For a Facebook Page this includes reading which Pages the account manages, so the right one can be posted as.
- CompanyCam — where connected, jobsite photographs and their captions.
- Clerk — authentication. Holds your sign-in credentials.
- Neon and Cloudflare R2 — database and file storage.
- Vercel — hosting.
These providers process data in the United States and, in some cases, elsewhere — including the European Union. We do not sell personal data, and we do not share it for advertising.
How long we keep it
Content and reports are kept for as long as your account is active, because the value of a report is largely in comparing it with the last one. Delete a brand and its content, media and reports are deleted with it.
Close your account and everything in it is deleted straight away, in one go: every business, its content, media, reports and connections, the API keys you stored with us, and the record of what your usage cost. We keep billing records where tax law requires it.
Three things are kept on purpose, and none of them is deleted by that button. The email address you signed in with, so that signing in again works and lands you on an empty account rather than shut out. And any support request you had open, because a problem you asked us about does not stop being one when you leave. Ask us to remove either and we will — see “Your rights” below.
The third is the record of Marcelo Credits: how many a business was given each month and how many it used. It is kept when a business is deleted and when an account is closed, because it is the record of what was paid for. It holds no details about the business, its customers or its website — it is dates and numbers. Unlike the two above it cannot be removed on request: nothing can change or delete a line of it once it is written, which is what makes it a record rather than a note.
A fourth is kept where Marcelo bought a web address for a business: the address, what it cost, and the day it was bought. A registration is real property in our registrar account with a renewal date on it, so deleting the business here does not make it stop existing — and a record of what we spent on your behalf is one we have to be able to show you. It holds nothing about the business, its customers or its website beyond the address itself. Ask us to transfer the address to you, or to let it lapse at renewal, and we will.
Questions you ask Marcelo in the chat panel are kept with the business you asked them about, along with the answer, so that a follow-up question makes sense to it. Only the most recent few are ever read back, and older ones are removed as you keep asking — we do not keep a history of everything you have ever asked. They are deleted with the business, and with your account when you close it.
Disconnecting a service deletes the stored token immediately, so we can no longer reach that account. Withdrawing the permission at the provider itself is separate and yours to do — for Google, the link below.
Your rights
You can ask us for a copy of your data, ask us to correct it, or ask us to delete it. Write to support@meetmarcelo.ai and we will respond within 30 days.
You can revoke Marcelo's access to your Google account at any time, without asking us, at myaccount.google.com/permissions. Doing so stops any further reading immediately.
If you are a California resident, you have the right to know what personal information we collect, to have it deleted, to correct it, and not to be discriminated against for exercising those rights. We do not sell or share personal information as those terms are defined by California law. If you are in the EEA or the UK, you also have the right to object to processing and to complain to your local data protection authority.
Security
Data is encrypted in transit and at rest. Access tokens and API keys are stored encrypted, and are never shown back to you in full once saved. Access to production data is limited to the people who operate the service.
No system is perfect. If a breach affects your data, we will tell you and the relevant authority as required by law.
Children
Marcelo is a business tool and is not intended for anyone under 18. We do not knowingly collect data from children.
Changes
If we change this policy in a way that materially affects you, we will email you before it takes effect. The date at the top always reflects the current version.
