Privacy policy
In short
- We process only what we need to give you the service: your account, what you do and write in the Academy, your purchases and what you tell us when you write to us or hire us for a project.
- We don't sell your data or run ads. Analytics (PostHog, in the EU) and third-party videos only load if you accept them.
- What you write to Mariscal AI is sent to AI model providers so they can answer you. We don't train models on your data.
- The demos keep what you do only in your browser.
- Some providers are in the US: the data travels with the safeguards the GDPR requires.
- You can see, download, correct and delete your data, and opt out of marketing emails with one click. If something doesn't sit right with you, you can complain to the AZOP.
This summary helps you find your way; it doesn't replace the full text.
1. Who the controller is
- Controller
- Martín Silva Molina
- OIB
- 42550330688
- Address
- Ul. Ivana Rendića 28b, 10000 Zagreb, Hrvatska
- Privacy contact
- hey@themariscal.com
We haven't appointed a data protection officer because we aren't required to (art. 37 of Regulation (EU) 2016/679, the GDPR), but anything you send to the address above is read by the person responsible. This policy covers themariscal.com and all its subdomains.
When we build a project for a client and process their users' data, the client is the controller and we only process it on their behalf: that's covered by the Data processing agreement, not by this policy.
2. What data we process
- Account: email, first and last name, username, profile photo, language, password (encrypted, held by Clerk), the provider you sign in with (Google, Apple) and your role.
- Learning: lessons watched and finished, where you are in each video, your answers and results in exercises and exams, what you've read of the book and the guides.
- What you write: notes, highlights, sticky notes, notebooks, exercise routines, your chats with Mariscal AI and what you ask it, and the images you upload for analysis.
- Analyses: the diagnoses, estimated level and error patterns built from your results.
- Purchases: what you bought, when, the amount, the Stripe payment ID, your credits and their movements. We never see your card details.
- Gifts: if you give one, the recipient's name, email and your message; if you receive one, the code and when you redeemed it.
- Community: comments, votes, likes, saves and reports.
- Messages: what you send us by email, through the contact form or through the forms on this site.
- Clients: if you hire us for a project, your contact details and your company's, the proposal, the contract, the invoices and what we discuss about the project.
- Business contacts: if you're the contact at a company we write to offering our services, your name, job title, work email and phone, the company and its website, and whatever you reply (see Business contacts).
- Technical data: IP address, browser, operating system, device language, server logs and errors.
- Usage (only if you accept analytics): the pages you view, the buttons you tap, how far you scroll, load times and, if you accept session recording, how you moved around the page.
We don't ask for or want sensitive data (health, religion, political opinions and so on). Please don't put it in your notes or your chats with the AI.
3. Why we use it and on what legal basis
| Purpose | Data | Legal basis (GDPR) |
|---|---|---|
| Creating and maintaining your account, and letting you into every site with a single sign-in | Account, technical data | Contract (art. 6(1)(b)) |
| Giving you the courses, the book and the guides, and saving your progress, notes, highlights and notebooks | Learning, what you write | Contract (art. 6(1)(b)) |
| Mariscal AI features and the analyses of your learning | What you write, learning, analyses | Contract (art. 6(1)(b)) |
| Taking payment, delivering what you bought, sending gifts, keeping track of credits | Purchases, gifts, account | Contract (art. 6(1)(b)) |
| Preparing a proposal, carrying out the project you hired us for and invoicing it | Clients, messages | Pre-contractual steps and contract (art. 6(1)(b)) |
| Invoicing and meeting our accounting and tax obligations | Purchases, clients | Legal obligation (art. 6(1)(c)) |
| Writing to companies to offer our services and keeping track of those conversations | Business contacts | Legitimate interest in business-to-business marketing (art. 6(1)(f) and recital 47); one-click opt-out in every email |
| Sending the recipient a gift someone bought for them | Recipient's name and email | Legitimate interest of the giver and the recipient (art. 6(1)(f)) |
| Showing your comments, moderating the community and handling reports | Community, account | Contract (art. 6(1)(b)) and legal obligation (DSA) |
| Answering your messages, complaints and requests about your rights | Messages, account | Pre-contractual steps or contract (art. 6(1)(b)), legal obligation (art. 6(1)(c)) |
| Security, preventing fraud and abuse, finding and fixing errors | Technical data, account | Legitimate interest in a secure service that works (art. 6(1)(f)) |
| Measuring how the sites are used so we can improve them (PostHog) | Usage, technical data, identifier | Consent (art. 6(1)(a) GDPR and art. 43 of the Zakon o elektroničkim komunikacijama, the Croatian Electronic Communications Act) |
| Session recording (PostHog) | Usage | Consent (art. 6(1)(a)) |
| Watching YouTube videos in lessons and posts | Technical data | Consent to YouTube's cookies (art. 43 ZEK) |
| News or offers by email, if we ever send them | Email, name | Consent or, for existing customers, similar products with an opt-out in every email (art. 50 ZEK) |
4. Where the data comes from
- Almost all of it from you: what you write and what you do on the sites.
- If you sign in with Google or Apple, they pass us your name, your email (or Apple's private relay email) and your photo.
- If someone gives you a course, they give us your name and email. We tell you so in the gift email itself.
- Stripe confirms each payment and its status.
- Business contacts come from public professional sources (the company's website, professional profiles, business directories) or from an introduction by someone who knows you. We tell you so in the first email.
5. The demos
The sample shops and configurators (the T-shirts, 3D printing, the publisher, the cube, the cars and the rest) don't send to our servers what you configure, your test orders or the files you upload (images, 3D models, text): it's all processed in your browser and kept in your device's local storage, where you can delete it whenever you like. The only thing that can leave your device is analytics, and only if you've accepted it.
6. Artificial intelligence and your data
For Mariscal AI to answer you, analyse something or generate an exercise, we send AI model providers your message and the minimum context needed: the lesson or page you're on, the point in the video, your results when you ask for an analysis, and the image if you uploaded one. The request goes through The Mariscal's API and through our own server, which picks the model (in Germany (EU)); from there it goes to Groq or Cerebras (US).
- We don't use your data to train AI models, and we choose providers who commit not to do so with the data we send them.
- Conversations are saved in your account so you can pick them up again, until you delete them or delete your account.
- Profiling and automated decisions: the AI uses your results to build diagnoses and an estimated level. This is profiling (art. 4(4) GDPR) used only to tailor your learning. We don't make decisions with legal effects, or that significantly affect you, based solely on automated processing (art. 22 GDPR): the marks are only a guide and you can ask for a person to review them.
More detail: Artificial intelligence at The Mariscal.
7. What other people can see
Your notes, notebooks, progress, chats and purchases are visible only to you. What you post on the blog (comments) is visible to anyone, with your name and profile photo, and is machine-translated into the site's other languages. If you delete a comment, it disappears.
8. Business contacts
The Mariscal writes to companies to offer its services, either directly or through business partners who work with us from a @themariscal.com mailbox. We follow these rules:
- We only write to work addresses, about services that relate to what the company does.
- Every email says who we are and where we got your contact, and includes a link to stop hearing from us with one click (plus the one-click unsubscribe header that email clients understand).
- If you unsubscribe or tell us you're not interested, we won't write again. To make sure of that, we keep only your email on a suppression list.
- If you reply, the conversation is recorded so we can follow it up. If there's no further contact, we delete your data 24 months after the last message.
- Business partners see only the contacts assigned to them, under the same rules.
9. The emails we send you
We send you service emails: sign-in codes (sent by Clerk), purchase confirmations, gifts, replies to your messages, everything to do with a project, and important notices about your account or these documents. Right now we don't send newsletters or advertising to account holders; if we ever do, it'll be only with your consent or, if you've already bought from us, about similar products, with an unsubscribe link in every email.
10. Who we share data with
We don't sell or rent out your data. We share it only with the providers we need to run the service, who process it on our behalf (processors, art. 28 GDPR) under a data processing agreement, or as independent controllers where stated:
| Provider | Purpose | Data | Location |
|---|---|---|---|
| Clerk, Inc. | Accounts, sign-in, sessions | Account, IP, device | US |
| Convex, Inc. | The Academy database and the business partners' database | Account, learning, what you write, purchases, business contacts | US |
| Vercel Inc. | Hosting for the sites and the API | Technical data, everything that passes through the sites | US and global network |
| Cloudflare, Inc. | DNS and, once we use it, file storage for the courses | Technical data (IP) | US and global network |
| Stripe Payments Europe, Ltd. | Payments. For fraud prevention and its own legal obligations it acts as an independent controller (its policy) | Email, name, payment details, country, IP; for gifts, the recipient's name and email | Ireland (EU) and US |
| Resend (Plus Five Five, Inc.) | Sending and receiving emails for the sites and the business partners | Email, name, email content | US (inbound email in Ireland, EU) |
| Zoho Corporation B.V. | Email for themariscal.com (the mailbox where we read what you send us) | Email, name, message content | EU |
| PostHog, Inc. | Analytics and session recording, only with your consent | Identifier, usage, technical data; when signed in, your email and name | EU (Frankfurt) |
| Functional Software, Inc. (Sentry) | Error monitoring | Identifier, browser, the error | EU (Germany) |
| Groq, Inc. and Cerebras Systems Inc. | Artificial intelligence models | Your messages and the minimum context | US |
| Our own AI server (VPS) | A go-between that picks the model; it doesn't store your messages | Your messages and the context | Germany (EU) |
| Google LLC (Cloud Translation) and Translated S.r.l. (MyMemory) | Machine translation of comments | The text to be translated | US / Italy (EU) |
| Google Ireland Ltd. (YouTube) | Playing videos. Independent controller for its cookies (its policy) | Technical data, YouTube cookies | Ireland (EU) and US |
| Google and Apple | Signing in with your account. Independent controllers | Whatever you allow them to share | US |
| jsDelivr (content delivery network) | Serving the sheet music engine on one of the team's pages | Technical data (IP) | Global network |
11. Data outside the European Union
Several providers are in the United States. Transfers rely on the safeguards in Chapter V of the GDPR: the adequacy decision for the EU-US Data Privacy Framework (Decision (EU) 2023/1795) for certified providers and, as well or instead, the European Commission's standard contractual clauses (Decision (EU) 2021/914). You can ask for a copy of the safeguards at hey@themariscal.com.
12. How long we keep it
| Data | How long |
|---|---|
| Account, progress, notes, notebooks, chats, analyses | For as long as you have the account. Once you delete it, it's erased within 30 days; backups follow their own cycle, up to 90 days more. |
| Unused free accounts | If an account with no purchases isn't used for 36 months, we email you and, if you don't reply within 30 days, we delete it. |
| Purchases, invoices, client contracts and paid credits | The period required by Croatian accounting and tax law (up to 11 years). |
| Client projects (messages, deliverables) | For the length of the contract and 5 years after, the general limitation period for contractual claims. |
| Business contacts with no relationship | 24 months from the last message. The suppression list, for as long as it's needed to honour it. |
| Public comments | Until you delete them, we remove them through moderation, or you delete your account. |
| Content reports and moderation decisions | 2 years from the decision. |
| Consumer complaints | At least 1 year from our reply (art. 10 of the Zakon o zaštiti potrošača); generally 3 years. |
| Messages and requests about your rights | 3 years from our last reply. |
| Analytics (PostHog) | 24 months. |
| Errors (Sentry) | 90 days. |
| Server logs | As long as each provider keeps them (usually under 30 days). |
| Your cookie choice | 12 months (then we ask you again). |
13. Your rights
At any time, free of charge, you can ask us for:
- Access: to know what data of yours we process and get a copy (art. 15).
- Rectification: to correct data that's wrong (art. 16). You can change almost all of it from your account.
- Erasure: to delete your data (art. 17), except what the law requires us to keep.
- Restriction: for us to stop using it while a problem is sorted out (art. 18).
- Portability: to receive your data in a structured format (JSON) so you can take it elsewhere (art. 20).
- Withdrawal of consent whenever you like (art. 7(3)): for cookies, from your preferences.
Write to hey@themariscal.com or use the form below. We'll reply within one month at the latest (this can be extended by two more months if the request is complex, and we'll let you know). If we can't be sure it's you, we'll ask you to write from your account email.
14. Deleting your account
- Write to hey@themariscal.com from your account email, or use the form above and choose “Delete my data or my account”.
- We check with you first, because deleting the account means losing what you bought and your credits.
- Within 30 days we delete your account and everything linked to it: progress, notes, highlights, notebooks, routines, chats and analyses. Your public comments are deleted or anonymised.
- We keep only what the law requires: the record of purchases and invoices, for the tax retention period.
15. Children
In Croatia, the age at which you can consent to online services yourself is 16 (art. 19 of the Zakon o provedbi Opće uredbe o zaštiti podataka, the Croatian Act implementing the GDPR). If you're under 16, you need permission from your parent or guardian to create an account, and you can't accept analytics on your own. If you're a parent or guardian and believe a child has given us data without permission, write to us and we'll delete it.
16. Security
We use encrypted connections (HTTPS), encrypted passwords, access to data only for those who need it, session-based access checks on every feature, limits against abuse, providers with security certifications, and masking of everything you type in session recordings. If a security breach put your data at risk, we'd notify the AZOP within 72 hours and, if the risk is high, you too.
17. Complaining to the authority
If you think we've mishandled your data, please tell us first: we'll want to put it right. But you have the right to lodge a complaint with the supervisory authority (art. 77 GDPR). In Croatia, that's:
- Authority
- Agencija za zaštitu osobnih podataka (AZOP)
- Address
- Selska cesta 136, 10000 Zagreb, Hrvatska
- azop@azop.hr
- Phone
- +385 1 4609 000
- Website
- azop.hr
or the authority in the EU country where you live or work.
18. Changes to this policy
If we change something important (for example, a new provider or a new purpose), we'll let you know by email or on the sites before it takes effect. Previous versions are listed at the bottom of this document.
Versions
- v1.0 · 11 October 2026 · First version.