Privacy policy
Last updated: 22 August 2026
This policy explains what Marc does with personal information. Marc is operated by Open Field, a sole proprietorship in South Africa, and is governed by the Protection of Personal Information Act 4 of 2013 (POPIA). It is written to be read, not to be survived — if anything here is unclear, ask us and we will explain it.
Who is responsible
Open Field is the responsible party for the personal information described here. Our Information Officer is reachable at support@projectmarc.com.
Where you use Marc to manage content for your own clients, you are the responsible party for their information and we act as an operator on your instructions.
What we collect
Account information. Your email address, password (stored only as a cryptographic hash — we never see it), display name, and the workspaces you belong to.
Content you create. The topics you enter, the copy and prompts generated from them, and the images and videos produced. This is your content; we store it so the product works.
Connected social accounts. When you connect an account we store its identifier, display name, and the access tokens the platform issues. Tokens are encrypted at rest and are used only to publish what you approve and to read back performance.
Performance data. For posts Marc published, we retrieve metrics such as views, reach, likes, comments, shares, saves, watch time and completion rate, and store them as a time series so you can see how a post performed.
Billing information. Your subscription tier, status and payment history. Card details are entered directly with our payment processor and never reach our systems.
Technical data. Error reports and diagnostic logs when something breaks.
Early-access list. If you give us your email address before Marc opens, we store that address and the date you gave it. We use it for one thing: to tell you when the app is ready. It is not a newsletter, we do not send anything else to it, and it is never sold, shared or handed to anyone outside the processors named below.
What we take from connected platforms
When you connect a social account, Marc requests only the permissions it needs to do the two things it does — publish what you approve, and read back how it performed:
| Platform | What we read | What we write |
|---|---|---|
| Your Pages, and video insights for videos Marc published (views, reach, watch time) | Publishes videos to a Page you select | |
| Your Business/Creator account, and insights for Reels Marc published (views, reach, likes, comments, shares, saves, watch time) | Publishes Reels to the account you select | |
| TikTok | Your basic profile information, and statistics for videos Marc published (views, likes, comments, shares) | Publishes videos to your account |
We do not read your direct messages, your followers' personal information, or posts that Marc did not publish. We do not post anything you have not explicitly approved. Disconnecting an account in Settings revokes our access immediately and deletes the stored tokens.
Why we may use it (lawful basis)
To perform our contract with you — creating your content, publishing it where you tell us to, showing you how it performed, and billing you.
Our legitimate interests — keeping the service secure, diagnosing faults, and preventing abuse.
Your consent — for the optional pooled model training described below, and for the early-access list. Both are things you opt into: the first is off unless you switch it on, and the second only exists because you typed your address into the form. You can withdraw either at any time.
Legal obligation — retaining financial records where the law requires it.
Automated processing and AI
Marc uses third-party AI models to generate content from the topics you provide, and to analyse how your posts performed. Concretely: your topic and post copy are sent to Anthropic to write prompts and to analyse performance; prompts are sent to OpenAI to generate still images and to BytePlus to generate video.
These systems produce suggestions, not decisions about you. Nothing here has legal consequences for you, and nothing is published without your explicit approval.
We do not permit these providers to train their own models on your content under our commercial terms with them.
Pooled model training — optional, and off by default
You can choose to let your workspace's results improve the recommendations everyone receives. This is a per-workspace setting, only a workspace owner can change it, and it is off unless you turn it on.
When it is on, we use derived patterns only. Specifically:
- Shared: aggregate signals such as “posts opening with a question tend to hold attention longer” or “this posting time performs better for this format”.
- Never shared: your captions, your videos, your metrics, your account names, or anything identifying you or your clients. No other customer can see your content or your numbers.
Turning it off stops your workspace contributing from that point onward. Patterns already learned cannot be individually unlearned, which is why it is opt-in.
Who else processes it
We use the following providers to run Marc. Several are outside South Africa, so using the service involves the cross-border transfer of personal information under section 72 of POPIA. We rely on contractual safeguards requiring each provider to protect the information to a standard comparable to POPIA.
| Provider | What they do | Where |
|---|---|---|
| Supabase | Database, authentication and file storage for your account and generated media | United States / European Union |
| Anthropic (Claude) | Writes post copy and prompts from the topics you provide, and analyses post performance | United States |
| OpenAI | Generates the still images used as reference frames for video | United States |
| BytePlus (Seedance) | Generates video from those prompts and reference images | Singapore |
| Paystack | Processes subscription payments. Card details go to Paystack directly and never reach us | South Africa / Nigeria |
| Sentry | Collects technical error reports so faults can be diagnosed | United States |
We do not sell personal information, and we do not share it for advertising.
How long we keep it
Your content, connected accounts and performance history are kept for as long as your account is open, because that history is what makes the recommendations work.
When you delete your account, we delete your workspaces, content, generated media, connected accounts and stored tokens. Financial records are retained for five years where South African tax law requires it. Backups are cycled out within 30 days.
Early-access addresses are kept until we have told you the app is open, and are deleted within 30 days of that — or sooner if you ask. If the launch never happens, they are deleted rather than kept.
Deleting your data
You can delete your account yourself at any time: sign in, go to Settings → Danger zone, and confirm by typing your email address. This removes your account and the data attached to it. It cannot be undone.
To disconnect a single social account without deleting anything else, go to Accounts and disconnect it. The stored tokens are deleted and our access is revoked.
If you cannot sign in, email support@projectmarc.com from the address on the account and we will action it within 30 days.
To come off the early-access list, email the same address from the address you signed up with and say so. There is no account to sign into, so that is the whole process.
Your rights under POPIA
You have the right to:
- ask what personal information we hold about you, and get a copy;
- have inaccurate information corrected;
- have information deleted where we no longer have grounds to keep it;
- object to processing based on legitimate interests;
- withdraw consent — such as pooled model training — at any time;
- complain to the Information Regulator of South Africa if you believe we have handled your information unlawfully.
Email support@projectmarc.com to exercise any of these. We respond within 30 days.
Information Regulator (South Africa) — enquiries@inforegulator.org.za
Security
Access to your data is scoped to your workspace and enforced at the database level, so one customer's data cannot be read by another. Social platform access tokens are encrypted at rest. Passwords are hashed and never visible to us. Access within a workspace is further limited by the role each member holds.
No system is perfectly secure. If a breach affects your personal information, we will notify you and the Information Regulator as POPIA requires.
Children
Marc is a business tool and is not intended for anyone under 18. We do not knowingly collect information from children.
Changes
If we change this policy materially, we will notify you by email or in the app before the change takes effect. The date at the top always reflects the current version.
Contact
Information Officer — Open Field
support@projectmarc.com
See also our terms of service.