MARUVI

Privacy, in plain words.

Last updated: September 28, 2026 · This is MARUVI's privacy policy. It covers the MARUVI app and this website.

The app

Your files live on your machine. When you call a cloud brain, something leaves — and gets a receipt.

MARUVI keeps your knowledge as plain files on your own computer. We run no server that stores them. When you choose to use a cloud brain, your question and the needed excerpts travel to that provider — and the receipt on screen shows what went out, where it went, and what stayed.

Honest note — developer-mode brains can open files on their own, and the app cannot always measure that traffic byte-for-byte. When it can't, the receipt says so instead of pretending.
Update check

Once a day the app reads one small notice file (maruvi.ai/update.json) to see whether a new version is out. It sends nothing of yours — not even your version number. Like any website visit, the request reaches Cloudflare from your internet address; MARUVI does not keep it. Switch off “Tell me when a new version is out” in Settings → Program & help → Program update, and the app stops going online for this.

The mic button

By default, your voice goes through whoever made your browser — not through MARUVI.

When you press the mic button and speak, the browser itself turns that audio into text. Chrome sends it to Google, Safari to Apple, Edge to Microsoft. This happens no matter which brain you picked, because the audio never passes through MARUVI — which also means it cannot appear on the receipt. We would rather say that plainly than let you assume otherwise.

  • ✕Left as it comes: your voice is transcribed by the browser maker's service.
  • →Switch on "mic stays on this computer" in settings: the recording is transcribed on your own machine, and the file is deleted right after.
The trade-off — with the switch on, words no longer appear while you are still speaking. The text arrives after you press stop. That is the cost of keeping the audio here, and it is the reason the switch is not on for everyone by default.
MARUVI account

To sign you in, our server keeps only what sign-in needs. Your conversations and files are not among them.

MARUVI signs you in with an email address and no password. We email you a sign-in link and a six-digit code, and you approve it. This is the one place where MARUVI's server keeps something that identifies you, so here is all of it.

  • →What the server keeps: your email address, the date you signed up, the date your sign-in was last checked, and your computer type (Mac, Windows or Linux — the operating system only, not the device name).
  • →Why: only to confirm it is you when you sign in. We do not use it for ads, we do not sell it, and we share it only with the services listed below.
  • →Every 30 days the app checks that your sign-in is still valid. It sends only its sign-in key and the app version.
  • →To stop one address from being flooded with sign-in mail, each sign-in request keeps a scrambled (hashed) form of your internet address. Records older than 24 hours are deleted together the next time anyone asks for a sign-in email, so one can stay a little longer if no one signs in for a while. The sign-in key and the code in the email are also stored only in scrambled form.
  • →Legal basis: signing in is needed to provide the service you asked for, so we process this without a separate consent (Personal Information Protection Act of Korea, Article 15(1)4 — performance of a contract).
  • →Who handles it for us: Resend sends the sign-in email and Cloudflare stores the account records. Both are US companies — see “Information that goes abroad” below for the countries, contacts and how long each keeps it.
  • ✕Children under 14 cannot sign up. If we learn that information from a child under 14 has come in, we delete it right away.
  • ✕Never sent to this server: your conversations, questions, files, API keys, or which brain you use.

How long: until you delete your account. Delete it in Settings → Program & help → MARUVI account, and your email, sign-up date and sign-in records are erased from the server right away. Signing out removes only that computer's sign-in; to make the next sign-in easier, that computer remembers your email in its own settings file until you delete your account.

Honest note — if you sign out while our server cannot be reached, that computer's old sign-in record may stay on the server. It opens nothing, because the key that matches it is already gone from your computer, and deleting your account removes it too.
Improvement stats

Anonymous usage counts — only if you say yes.

During setup we ask whether you'd like to share anonymous counts that help us improve. It stays off unless you say yes, you can turn it off anytime, and every send is printed on the receipt.

  • →What it would send: which features ran and how many times, setup steps completed, error codes, operating system and app version.
  • →One random install number (12 meaningless characters, generated on your machine only after you say yes) travels with those counts, so we can tell one install's records from another's. It is not derived from your name, email, or hardware, and it identifies no one.
  • ✕Never sent, even with consent: your conversations, questions, file names or contents, API keys, your name or email. Your sign-in email stays with the account section above and is never attached to these counts.
  • ✕No ad networks, no ad trackers. The counts go to one place only — Aptabase, a service that collects app usage stats — once a day. See “Information that goes abroad” below for the company, country and how long it keeps them.
This website

No cookies. No ad trackers.

This site uses cookie-free visitor counting only — how many people visited which page. It cannot follow you across the web, and there is nothing to accept or dismiss. If you email us, we use your address only to reply, and you can ask us to delete it anytime.

The ask window

What you type here is kept — for 90 days.

The ask window on this site (and the ask button inside MARUVI) sends your question to Anthropic's Claude, which writes the answer. We store it in three layers, each with its own clock. Your question and the answer are deleted automatically after 90 days. To count how many questions arrive from one place each day, the internet address (IP) that sent the question is kept only as a scrambled value (hash), alongside the question, for the same 90 days. A de-identified type record — what broke, which operating system, which version, whether a person had to step in — is kept without a time limit, so we can fix the guides. If you leave an email address, that address is deleted after 30 days. If you attach a screenshot, we keep that image for 30 days only when a person has to look at it; otherwise it is discarded as soon as the answer is written, and only the number of images remains. Nothing from inside your computer is attached: the ask button sends only what you wrote, the version and error lines you can see before you press send, and any screenshot you attach yourself. If you are signed in, the ask button fills the reply-address box with your sign-in email; you can erase it before you send.

Information that goes abroad

Sign-in, the ask window and — only if you say yes — usage stats run on four overseas services. Here is what each one gets.

The first three (Resend, Cloudflare, Anthropic) are needed to provide the service you asked for, so there is no separate consent — the law asks us to publish it here instead. The fourth, Aptabase, gets anything only if you said yes to usage stats. Everything travels over an encrypted internet connection (HTTPS), at the moment you use the feature.

  • →Resend (Plus Five Five, Inc., United States · support@resend.com) — gets your email address and the sign-in email itself (link and six-digit code), each time you ask for a sign-in email. The mail is sent from its Tokyo, Japan region, but Resend stores its records in the United States. It only delivers the email, and keeps its sending records for 30 days.
  • →Cloudflare (Cloudflare, Inc., United States · dpo@cloudflare.com) — runs this website and our server, and stores the account records above (when you sign up, sign in and at each 30-day check) and the ask-window records (when you send a question). Account records sit in an Asia-Pacific data center; Cloudflare picks the exact country and does not disclose it. Ask-window records are spread across Cloudflare's data centers worldwide. They are kept for the periods stated in the account and ask-window sections.
  • →Anthropic (Anthropic PBC, United States · privacy@anthropic.com) — gets what you typed in the ask window, the version and error lines shown before you send, and any screenshot you attach, each time you send a question. It only writes the answer, and deletes the data within 30 days — except that if a message is flagged as breaking Anthropic's usage policy, Anthropic may keep it for up to 2 years.
  • →Aptabase (Technov Solutions SRL, Romania · office@technov.ro) — only if you said yes to usage stats. Gets the random 12-character install number, operating system and its version, app version, and the feature-use and error counts described under “Improvement stats”, once a day. Aptabase processes and stores it only inside the European Union (the app shows this as its German server). It is used only to count how the app is used, and Aptabase keeps it for up to 5 years. Turn it off anytime in Settings → Program & help → Improvement stats.
  • ✕If you do not want this: the MARUVI app cannot be used without signing in, so declining sign-in means not using the app (if our server is not answering or the sign-in email is slow to arrive, you can skip sign-in for now, but the app asks again the next time it starts). For questions, skip the ask window and email contact@maruvi.ai — then nothing goes to Anthropic. Usage stats stay off unless you turn them on, and turning them off stops anything from going to Aptabase.
Questions

Anything unclear, or want your data removed? Write to us — a person reads it.

contact@maruvi.ai

  • →Privacy contact: MARUVI Privacy Office · contact@maruvi.ai. This is where privacy requests and complaints go.
  • →Your rights: you can ask to see, correct, delete, or stop the processing of your information. Email the address above and we will reply within 10 days. Deleting your account in Settings erases it right away, without writing to us.
  • →If you disagree with our answer: reply to that email and we will review it again and answer within 10 days. You can also go to the Personal Information Infringement Report Center (privacy.kisa.or.kr · call 118) or the Personal Information Dispute Mediation Committee (kopico.go.kr · 1833-6972).
  • →How we delete: when a holding period ends or you delete your account, the records are deleted from the server. Cloudflare's automatic database backup may still hold them for up to 30 days, after which they are gone.
  • →How we protect it: every transfer is encrypted (HTTPS); sign-in keys, email codes and internet addresses are stored only in scrambled (hashed) form, so a leaked copy would not reveal them.