Privacy Policy
Effective September 12, 2026
Aurova, Inc. (“Margin,” “we,” “us,” or “our”) currently operates usemargin.io and the Margin application at app.usemargin.io. This Policy explains our handling of personal information through those sites, the waitlist, and related features that link to this Policy. Contact us at alvin@aurova.io with privacy questions or requests.
1. Information we collect
Waitlist information
When you join the waitlist, we collect your email address and any information you enter about the agents you use. For a submission through the agent interface, we also collect the agent’s name and its assertion that its owner authorized the submission. We record whether the submission used the human or agent channel, its creation time, and an internal record identifier. A channel label is not identity verification.
We receive this information directly from you or from an agent you instruct. We use a hidden form field and request limits to reduce spam. The waitlist rate-limit records contain shared request counters and time windows, not a per-person browsing profile. Do not include bank credentials, financial account numbers, government identification, or other sensitive information in a waitlist field.
Account information, when registration is available
For email-and-password registration, we process your email address, authentication information, verification status, account identifier, and records needed to manage the account and its sessions. We also record acceptance of the applicable Terms version. Authentication information is used to verify access and recover an account, not for advertising.
If you choose Google, Apple, or GitHub sign-in, we receive the identity information made available through the permissions you approve. This can include a provider account identifier, email address, email-verification status, and basic profile information such as a name, username, or picture. Apple may provide a private relay email address. We do not receive your password for the sign-in provider. Sign-in does not give us permission to read your email inbox, private repositories, or financial accounts.
Communications
If you contact us, we receive your contact details, the content of the message, and any information you choose to include. We use this information to respond and keep a record of the request.
Site and device information
Our hosting platform, Floot, provides visitor analytics processed by Tinybird. These record a random session identifier, page path, referrer, browser user-agent, language, and a country estimate based on timezone. Those analytics do not record IP addresses or URL query strings.
Infrastructure providers also process network requests to deliver pages and media. The site loads fonts from Google Fonts and media through content-delivery infrastructure, so those providers receive the technical information necessary to serve the requested resources, including a network address. Operational logs help identify errors and maintain availability.
The current demonstrations do not connect to your financial accounts. Displayed balances, payment-card details, transactions, and positions are demonstration content, not financial information collected from you.
2. How we use information
We use personal information to:
- Maintain the waitlist, understand demand for supported agents, and contact you about requested access or relevant product updates.
- Create and administer accounts, verify sign-in, manage sessions, and record legal acceptance when those features are available.
- Respond to support, privacy, and security requests.
- Measure site use and improve navigation, reliability, and product design.
- Detect abusive submissions, protect the Services, investigate errors, and enforce applicable terms.
- Meet legal obligations and establish, exercise, or defend legal claims.
We do not sell personal information or share it for cross-context behavioral advertising. We do not use sign-in information to make credit, lending, employment, or other decisions with legal or similarly significant effects.
3. When we disclose information
We disclose information only as relevant to the following purposes:
Operating the Services. Hosting, database, content-delivery, analytics, authentication, communications, and support providers process information needed for their roles. Floot supplies the application infrastructure; its hosting and database infrastructure includes AWS and Neon. Tinybird processes the visitor analytics described above. Google Fonts supplies typefaces. A sign-in provider receives information when you choose its sign-in flow.
Your instructions. We may disclose information when you ask us to or expressly authorize an integration. If you instruct an external agent to interact with Margin, its operator may separately process your instructions and any information you provide to it. That operator’s privacy practices apply to its own processing.
Legal and protective purposes. We may disclose information when reasonably necessary to comply with law or valid legal process, protect people or the Services, address fraud or abuse, or establish, exercise, or defend legal claims.
Business transactions and operator changes. Margin’s operator may change at any time, including if Margin is spun off from Aurova, Inc. into an independent company. We may disclose personal information, subject to appropriate confidentiality protections, when evaluating or completing a financing, merger, reorganization, spin-off, sale, or transfer of Margin to an affiliate or successor operator.
If the operator changes, information needed to continue the Services may transfer to the new operator. The new operator must honor the privacy commitments applicable to that information. We will update this Policy to identify the new operator, its contact details, and the effective date, and notify affected individuals through the website and by email where we have their address. We will provide any advance notice and obtain any consent required by law.
A change of operator does not itself authorize new uses of previously collected information or retroactively weaken existing privacy commitments. Any later change in processing must follow Section 9 and applicable law.
Waitlist records are not published or made available through a public lookup. Authorized personnel and service providers may access information for the purposes described in this Policy.
4. Cookies and browser controls
Floot’s analytics use a first-party cookie named session-id with a 30-minute sliding expiry. When account sign-in is available, authentication may also use cookies or similar storage to maintain a session and protect the sign-in process.
You can block or remove cookies using your browser’s controls. Blocking cookies may prevent sign-in or other features from working. The site does not currently change its analytics behavior in response to a browser’s Do Not Track setting. We do not conduct the sale or advertising-related sharing to which Global Privacy Control opt-out signals apply.
Links to external websites do not make those sites part of Margin. When you follow them or use an external sign-in service, those providers may use their own cookies and collect information under their own privacy notices. We do not authorize third parties to use Margin’s waitlist records for their own advertising.
5. How long we keep information
We keep waitlist information while it is needed to manage your interest in access, unless you request removal sooner. We assess continued need as the product and waitlist change. If the waitlist is discontinued, we delete or de-identify information no longer needed for the purposes described here.
Account information is kept while needed to provide the account and handle closure, security, and legal obligations. Support correspondence is kept for as long as needed to resolve the matter and maintain appropriate records. We may keep limited information to comply with law, resolve disputes, document consent or a request, prevent abuse, or honor a communications opt-out.
Hosted visitor analytics are retained for 12 months. Application logs are retained for 90 days and content-delivery logs for 30 days under the hosting provider’s published practices. Deletion from active records may precede expiry from backups or fixed-retention operational logs; retained copies remain subject to applicable protections.
6. Your choices and requests
Contact alvin@aurova.io to request access to, correction of, or deletion of your personal information, to leave the waitlist, or to ask about our practices. You do not need to create an account to make a request. Tell us the email address associated with the information and what you want us to do. Do not send a password or financial credentials.
We may ask for information reasonably necessary to verify a request and protect against unauthorized disclosure or deletion. An authorized representative may contact us for you; we may need to confirm their permission and your identity. The agent waitlist endpoint is for joining the waitlist, not for authenticating a privacy request.
Depending on where you live and which laws apply, you may have rights to obtain a copy of information, correct or delete it, withdraw consent, object to or restrict certain uses, appeal a denied request, or complain to a privacy regulator. We will respond under the applicable requirements and explain any lawful reason we cannot fulfill a request. To ask us to reconsider a decision, reply to our response and state that you are appealing. We will not unlawfully discriminate against you for exercising a privacy right.
If we send marketing email, use the unsubscribe instructions in that email or contact us to stop it. Necessary account, security, or legal notices may still be sent when relevant. Revoking a sign-in provider’s permission through that provider does not by itself delete a Margin account; contact us separately for closure.
7. Security and processing locations
The site uses HTTPS to protect information in transit. Our hosted database uses the infrastructure provider’s disk encryption, and waitlist access is restricted to authorized backend and administrative access. These measures reduce risk but do not guarantee that every security incident can be prevented.
Our application data is hosted in the United States. Content delivery and some provider processing may occur in other countries. Where applicable law requires safeguards for a transfer, we will use the safeguards required for that processing. This Policy is not a request for you to waive protections that apply to your information.
8. Children
Registration and the waitlist are intended for adults aged 18 or older. We do not knowingly collect children’s personal information through those features. If you believe a child has submitted personal information, contact us so we can investigate and delete information collected contrary to this Policy or as otherwise required by law.
9. Changes to this Policy
We will update this Policy when our practices change and show the new effective date. For material changes, we will provide an appropriate additional notice, such as a prominent notice on the site or an email when we have your contact details. If a new use requires consent or another step under applicable law, we will take that step before the new use begins.
10. Contact
Aurova, Inc. (Margin)
Email: alvin@aurova.io