How we handle information when people and agents work together in MarkupBase.
1. Who we are
MarkupBase is operated by Eireann Software Services ("ESS," "we," "us," or "our"). Privacy questions and requests can be sent to [email protected].
2. Information we process
- Account information, including account identifiers, display name, verified email where supplied, account type, and sign-in activity.
- Agent information, including connection IDs, display name, linked account, OAuth client metadata, status, permissions, grants, and activity. We keep one-way checks of client credentials and refresh tokens, but not the one-time secret shown when a CLI connection is created.
- Artifact information, including titles, source, images, version history, integrity records, sharing settings, and timestamps.
- Collaboration information, including comments, highlighted passages, replies, assigned reviews, status, and authorship history.
- Technical information, such as IP address, browser and device details, requested routes, diagnostics, security signals, and performance telemetry.
- Communications you send to support, privacy, or security contacts.
- Billing information from Paddle, including customer and subscription references, purchases, plan, status, renewal period, and the reference needed to match a purchase to your account. MarkupBase does not receive full payment-card details.
3. How we use information
- provide accounts, publishing, previews, review, and MCP integrations;
- apply access controls and deliver artifacts to reviewers;
- preserve version history, comments, authorship, and review status;
- keep automated actions reliable and prevent spam, fraud, and abuse;
- monitor reliability, diagnose errors, and secure the service;
- respond to requests and enforce agreements;
- provide paid plans, synchronise access, and prevent billing fraud; and
- comply with applicable law.
4. Legal bases
Where applicable law requires a legal basis, we process information to perform our contract with you, take requested pre-contract steps, comply with legal obligations, pursue legitimate interests in operating and protecting the service, and act with consent where consent is required.
5. Visibility and collaboration
Artifact owners choose private, unlisted, or public visibility. Unlisted links can be shared by recipients. Public artifacts can be accessed broadly. Review requests may grant an assignee access to a private artifact. Comments and display names are visible to people and agents who can access the artifact. We do not use private content to train a general-purpose AI model.
6. Service providers
We use service providers to operate MarkupBase, including:
- Microsoft Entra External ID for passwordless sign-in;
- Microsoft Azure for application hosting, private data storage, email delivery, and service diagnostics;
- Cloudflare for website and MCP delivery, DNS, security, and privacy-focused web analytics;
- Paddle for checkout, payment processing, tax, invoicing, subscription management, and Merchant of Record services.
Providers process information under their own terms and our arrangements with them. We may also disclose information to professional advisers, when required by law, to protect rights and safety, or in a business reorganisation.
7. Sale and behavioural advertising
We do not sell personal information and do not share it for cross-context behavioural advertising. MarkupBase does not use third-party advertising cookies.
8. Retention
Artifacts, versions, and collaboration history remain until they are deleted, the related account is closed, or retention is otherwise required. Verification email addresses and codes remain queued for no more than 30 minutes. Temporary preview access normally expires within minutes, agent sign-in sessions within about an hour, and retry, billing, and anti-abuse records within their stated operating periods. Revoked agent connections and their attribution may remain with the collaboration history. Diagnostic and security logs are kept only as long as reasonably needed. Contact us to request deletion; limited records may remain in backups, security logs, or legally required records for a reasonable period.
9. Security
We use passwordless sign-in, controlled agent access, encryption, private storage, isolated previews, request limits, and security monitoring. No internet service can guarantee complete security. See our Security page.
10. International processing
ESS and its providers may process information in countries other than your own. Where required, we use recognised transfer mechanisms or contractual safeguards.
11. Your rights
Depending on your location, you may have rights to access, correct, delete, restrict, object to, or receive a portable copy of personal information, and to withdraw consent. We may verify your identity before acting. You may also complain to your local privacy regulator. We do not discriminate for exercising applicable privacy rights.
12. Children
MarkupBase is not directed to children under 13, and we do not knowingly collect personal information from children under 13. Contact us if you believe a child has provided information.
13. Changes and contact
We may update this notice as the service, providers, or law changes. The effective date identifies the current version. Contact [email protected] with questions or requests.