Privacy policy

Last updated: 22 August 2026

This policy explains what Marc does with personal information. Marc is operated by Open Field, a sole proprietorship in South Africa, and is governed by the Protection of Personal Information Act 4 of 2013 (POPIA). It is written to be read, not to be survived — if anything here is unclear, ask us and we will explain it.

Who is responsible

Open Field is the responsible party for the personal information described here. Our Information Officer is reachable at support@projectmarc.com.

Where you use Marc to manage content for your own clients, you are the responsible party for their information and we act as an operator on your instructions.

What we collect

Account information. Your email address, password (stored only as a cryptographic hash — we never see it), display name, and the workspaces you belong to.

Content you create. The topics you enter, the copy and prompts generated from them, and the images and videos produced. This is your content; we store it so the product works.

Connected social accounts. When you connect an account we store its identifier, display name, and the access tokens the platform issues. Tokens are encrypted at rest and are used only to publish what you approve and to read back performance.

Performance data. For posts Marc published, we retrieve metrics such as views, reach, likes, comments, shares, saves, watch time and completion rate, and store them as a time series so you can see how a post performed.

Billing information. Your subscription tier, status and payment history. Card details are entered directly with our payment processor and never reach our systems.

Technical data. Error reports and diagnostic logs when something breaks.

Early-access list. If you give us your email address before Marc opens, we store that address and the date you gave it. We use it for one thing: to tell you when the app is ready. It is not a newsletter, we do not send anything else to it, and it is never sold, shared or handed to anyone outside the processors named below.

What we take from connected platforms

When you connect a social account, Marc requests only the permissions it needs to do the two things it does — publish what you approve, and read back how it performed:

PlatformWhat we readWhat we write
FacebookYour Pages, and video insights for videos Marc published (views, reach, watch time)Publishes videos to a Page you select
InstagramYour Business/Creator account, and insights for Reels Marc published (views, reach, likes, comments, shares, saves, watch time)Publishes Reels to the account you select
TikTokYour basic profile information, and statistics for videos Marc published (views, likes, comments, shares)Publishes videos to your account

We do not read your direct messages, your followers' personal information, or posts that Marc did not publish. We do not post anything you have not explicitly approved. Disconnecting an account in Settings revokes our access immediately and deletes the stored tokens.

Why we may use it (lawful basis)

To perform our contract with you — creating your content, publishing it where you tell us to, showing you how it performed, and billing you.

Our legitimate interests — keeping the service secure, diagnosing faults, and preventing abuse.

Your consent — for the optional pooled model training described below, and for the early-access list. Both are things you opt into: the first is off unless you switch it on, and the second only exists because you typed your address into the form. You can withdraw either at any time.

Legal obligation — retaining financial records where the law requires it.

Automated processing and AI

Marc uses third-party AI models to generate content from the topics you provide, and to analyse how your posts performed. Concretely: your topic and post copy are sent to Anthropic to write prompts and to analyse performance; prompts are sent to OpenAI to generate still images and to BytePlus to generate video.

These systems produce suggestions, not decisions about you. Nothing here has legal consequences for you, and nothing is published without your explicit approval.

We do not permit these providers to train their own models on your content under our commercial terms with them.

Pooled model training — optional, and off by default

You can choose to let your workspace's results improve the recommendations everyone receives. This is a per-workspace setting, only a workspace owner can change it, and it is off unless you turn it on.

When it is on, we use derived patterns only. Specifically:

  • Shared: aggregate signals such as “posts opening with a question tend to hold attention longer” or “this posting time performs better for this format”.
  • Never shared: your captions, your videos, your metrics, your account names, or anything identifying you or your clients. No other customer can see your content or your numbers.

Turning it off stops your workspace contributing from that point onward. Patterns already learned cannot be individually unlearned, which is why it is opt-in.

Who else processes it

We use the following providers to run Marc. Several are outside South Africa, so using the service involves the cross-border transfer of personal information under section 72 of POPIA. We rely on contractual safeguards requiring each provider to protect the information to a standard comparable to POPIA.

ProviderWhat they doWhere
SupabaseDatabase, authentication and file storage for your account and generated mediaUnited States / European Union
Anthropic (Claude)Writes post copy and prompts from the topics you provide, and analyses post performanceUnited States
OpenAIGenerates the still images used as reference frames for videoUnited States
BytePlus (Seedance)Generates video from those prompts and reference imagesSingapore
PaystackProcesses subscription payments. Card details go to Paystack directly and never reach usSouth Africa / Nigeria
SentryCollects technical error reports so faults can be diagnosedUnited States

We do not sell personal information, and we do not share it for advertising.

How long we keep it

Your content, connected accounts and performance history are kept for as long as your account is open, because that history is what makes the recommendations work.

When you delete your account, we delete your workspaces, content, generated media, connected accounts and stored tokens. Financial records are retained for five years where South African tax law requires it. Backups are cycled out within 30 days.

Early-access addresses are kept until we have told you the app is open, and are deleted within 30 days of that — or sooner if you ask. If the launch never happens, they are deleted rather than kept.

Deleting your data

You can delete your account yourself at any time: sign in, go to Settings → Danger zone, and confirm by typing your email address. This removes your account and the data attached to it. It cannot be undone.

To disconnect a single social account without deleting anything else, go to Accounts and disconnect it. The stored tokens are deleted and our access is revoked.

If you cannot sign in, email support@projectmarc.com from the address on the account and we will action it within 30 days.

To come off the early-access list, email the same address from the address you signed up with and say so. There is no account to sign into, so that is the whole process.

Your rights under POPIA

You have the right to:

  • ask what personal information we hold about you, and get a copy;
  • have inaccurate information corrected;
  • have information deleted where we no longer have grounds to keep it;
  • object to processing based on legitimate interests;
  • withdraw consent — such as pooled model training — at any time;
  • complain to the Information Regulator of South Africa if you believe we have handled your information unlawfully.

Email support@projectmarc.com to exercise any of these. We respond within 30 days.

Information Regulator (South Africa) — enquiries@inforegulator.org.za

Security

Access to your data is scoped to your workspace and enforced at the database level, so one customer's data cannot be read by another. Social platform access tokens are encrypted at rest. Passwords are hashed and never visible to us. Access within a workspace is further limited by the role each member holds.

No system is perfectly secure. If a breach affects your personal information, we will notify you and the Information Regulator as POPIA requires.

Children

Marc is a business tool and is not intended for anyone under 18. We do not knowingly collect information from children.

Changes

If we change this policy materially, we will notify you by email or in the app before the change takes effect. The date at the top always reflects the current version.

Contact

Information OfficerOpen Field
support@projectmarc.com

See also our terms of service.