Marian — privacy policy
Last updated: 31 July 2026 Applies to: the Marian browser extension and the Marian server it connects to.
Before publishing this, one thing has to be decided and filled in: who runs the server. Marian's extension talks to a Marian server, and whoever operates that server holds the data. Two very different answers:
- You run one server for everybody. You are the data controller. This policy is yours, and the placeholders below need your details.
- Each person runs their own (the current default —
localhost:8787). Then the extension sends data only to a server that user controls, and your obligations are much smaller. Say so plainly; it is a genuine selling point.Placeholders are marked
[…]. Do not publish with any of them left in.
The short version
Marian stores what you highlight, what you write about it, and the text of pages you highlight on. That data goes to one place: the Marian server configured in your settings. There is no analytics, no tracking, and no third party involved unless you turn AI on.
Everything below is the detail behind that.
1. What Marian stores
On your device, always
Held in the browser's local database, and it works with no account and no network:
- Your highlights: the exact text, where on the page it was, and the colour
- Your notes, tags, collections and sticky notes
- Pages you highlighted on: URL, title, author, and the extracted text of the page, so a highlight still means something after the page changes or dies
- Settings and preferences
On the server, if you sign in
Signing in is optional and adds one thing: the same data, copied to a server so it reaches your other browsers. Sync is not required to use Marian.
- Your email address — the only personal detail asked for, and only to sign in
- A copy of everything in the list above
- Conversations, if you use AI
- A credit balance and a record of AI actions you ran, for the meter described in §3. Each entry is the kind of action ("page summary"), when, and what it cost — never the question you asked or the answer you got. It exists so "where did my credits go?" has an answer you can check rather than one you have to take on trust, and you can read the whole of it on your account page.
If you turn on reading time — and only then
This one is described in full because it is the most sensitive thing Marian can hold, and because it is off until you switch it on.
With it on, Marian records every page you visit: the address, the page title, and how many seconds you actually spent reading it. That is a browsing history, and calling it anything else would be dishonest. It syncs with the rest of your account.
- Never the page content. What a page said is only ever stored for pages you chose to keep by highlighting or saving them.
- Seconds are counted only while you are actually there — the tab visible, the window focused, the machine not idle. A tab left open overnight counts as nothing, which is why the numbers are lower than you might expect and why they are worth trusting.
- One row per page per day, not one per visit. A minute-by-minute record of your day is not needed to answer "where did my reading time go", so it is not kept.
- Sites on the blocklist are never timed at all — not recorded and then hidden. Where you spent an hour can say more about you than what was written there.
- Deleted automatically after 90 days, enforced by the database itself rather than by a cleanup task that could quietly stop running.
- You can erase all of it at any time without deleting your account or losing a single highlight.
If you share open tabs — and only then
Also off until you switch it on, separately from signing in.
Marian normally keeps your open tabs entirely on the device they are open on. Switch this on and this browser publishes its list — page addresses, titles and icons — so your other signed-in devices can show it. That is what lets you reach your laptop's tabs from your phone.
It is worth being clear that this is a live list of what you have open, which is in some ways more revealing than a record of where you have been.
- Only tabs, never their content.
- Blocked sites are never included, on the device or on the server.
- Each device replaces its own list — a tab you close disappears from your other devices rather than lingering.
- A device that stops reporting expires after 14 days, and every list shows when it was last updated, so an old one reads as old.
- Turning it off withdraws what was shared straight away — not when some timer runs out.
Not stored at all
- No telemetry and no usage tracking of the extension itself. Marian does not report what features you use, or that you use it at all. The only network requests are to the Marian server you configured.
- No advertising identifiers, no third-party scripts, no cookies for tracking.
- No browsing history unless you asked for it (above). With reading time off — the default — a page you merely visited leaves no trace anywhere.
2. Pages Marian never touches
Some pages are excluded before anything is read, stored, or sent:
- Banking, healthcare and other sensitive domains, by keyword
- Anything on your own machine —
localhost,file://,chrome:// - URLs containing what look like tokens, session ids, or passwords
- Any domain you add to your own blocklist in settings
On those pages Marian does not run, does not store, and does not send. The rule is enforced on the server too, so a bug in the extension cannot bypass it.
3. AI, which is off until you turn it on
AI is disabled by default. Turning it on is a deliberate choice with a screen that explains what it means, and it can be turned off again at any time.
With AI on, the following is sent to a model:
- The passage you asked about, and your note on it
- The text of the page it came from
- For library questions, the passages that matched your question
Where it goes depends on how your Marian server is configured, and the settings panel tells you which:
| Local | A model running on the same machine as your Marian server. Nothing leaves that machine |
| Hosted | Ollama Cloud, when enabled |
What is never sent: anything from a blocked page (§2), and any page you have not highlighted on.
Training: no. Ollama's own privacy policy states that prompts and responses sent through Ollama Cloud are processed transiently to provide the service and are never used to train any model — including in support requests. See ollama.com/privacy.
Right now, AI is not enabled on this deployment at all — no model, local or hosted, is reachable, so nothing above can currently happen no matter what a user's own setting says. The policy above is the one that will apply once it is turned on.
Conversations are stored so you can return to them. Deleting one deletes it.
4. Fetching a page you asked about
If you ask Marian about a link it does not already have, it will fetch that page — and only then. It identifies itself honestly as MarianBot, obeys robots.txt, does not use your cookies or session, and stops at a paywall rather than working around one. Fetched pages are used to answer that one question and are not added to your library unless you save them.
5. Feedback
If you send feedback, Marian stores what you wrote, and optionally the page you were on and any browser errors, so the report is actionable.
To stop spam, submissions are rate-limited. Signed-in reports are counted against your account; anonymous ones against a salted hash of your IP address. The address itself is not stored and cannot be recovered from the hash.
If you delete your account, feedback you sent is anonymised, not deleted — the report survives without anything linking it to you. A bug report that disappears with its reporter is a bug that comes back.
6. Deleting your data
Three levels, all immediate and none of them soft deletes:
| A single item | Delete a highlight, note, page or conversation |
| Everything local | Delete everything in settings clears this device |
| The whole account | Delete account in settings |
Deleting the account removes your email, every highlight, note, page, snapshot, sticky note and conversation, and the search index built from them. There is no grace period and no recovery.
Two deliberate exceptions, both stated above: feedback is anonymised rather than deleted (§5), and workspaces shared with other people survive — only your membership goes, because someone else's reading is not yours to delete.
7. How long things are kept
- While your account exists: your data is kept until you delete it. Nothing expires on its own, because a library that quietly forgets is not a library.
- Reading time: 90 days, then deleted automatically by the database. Not by a scheduled job, because a job that fails silently is how "we keep 90 days" becomes "we kept everything".
- The credit record: kept for as long as your account exists, deliberately without expiry. A spending history that silently truncates is one nobody can reconcile against their balance.
- Login codes: deleted automatically after 10 minutes.
- Sign-in sessions: expire after 30 days of not being used.
- After account deletion: immediate. Backups are retained for 30 days — deleted data persists in a backup until it rolls off that window (
scripts/backup.py pruneis what actually enforces this, on the same nightly schedule as the backup itself).
8. Who else sees it
Nobody, with two exceptions you control:
- The model host, only if you turn AI on (§3)
- People you share a workspace with, only for the workspace you shared
Marian does not sell data, does not share it with advertisers, and has no analytics partners.
- avahana.ai — runs the server and stores the data
- Resend — sends login codes, and therefore sees your email address
9. Security
- Sign-in is by emailed one-time code; no passwords are stored because none exist
- Session tokens are held where page scripts cannot reach them
- Refresh tokens are stored hashed, and rotate on each use
- Every request is scoped to your workspace, enforced centrally and covered by tests written specifically to attempt cross-account access
- All traffic to the server is over HTTPS
No system is perfectly secure, and anyone who tells you otherwise is selling something. If you find a vulnerability, please report it to marian@askmarian.com.
10. Permissions, and why each is needed
The install prompt is blunt about access to "all websites". It is worth explaining, because the reason is boring:
| Permission | Why |
|---|---|
| Access to all websites | Highlighting has to work on whatever you are reading. Marian cannot know in advance which page that is. It runs on the page only to paint your highlights and watch for a selection |
storage | Keeping your library on your device |
tabs, activeTab | Knowing which page you are on, so the panel shows its highlights |
scripting | Extracting page text when you highlight, so the highlight survives the page changing |
sidePanel | The library panel |
contextMenus | Right-click → highlight |
downloads | Exporting your library to a file |
alarms | Scheduling sync; a background page cannot use a timer |
11. Children
Marian is not directed at children under 13 and does not knowingly collect their data.
12. Changes
Material changes will be noted here with a new date, and anything that widens what is collected or where it goes will be surfaced in the product rather than only in this document.
13. Contact
marian@askmarian.com 2/20 Sant Kabir Nagar, Ujjain