Legal

Privacy Policy

Last updated: June 21, 2026 · Effective: June 21, 2026

1. Overview

Marech(“we”, “us”, “our”) is committed to protecting your privacy. This Privacy Policy explains what information we collect, how we use it, and your rights regarding that information when you use marech.tech and related services (the “Service”).

2. Information We Collect

Account Information

When you register, we collect your name, email address, and billing information (processed via our payment provider — we do not store raw card numbers).

Website Traffic Data (your visitors)

To detect and block AI scrapers, we process HTTP request metadata from visitors to your website: IP address, User-Agent string, requested URL path, timestamp, and headers used to classify bot traffic. This data reaches us either from our JavaScript snippet (monitoring) or from a server-side integration you install — our Cloudflare Worker, WordPress plugin, Vercel middleware, or nginx proxy (blocking). We act as a data processorfor this visitor data, on your behalf and under your instructions (see “Your Role vs. Ours” below).

Service Logs

Our servers keep standard operational logs of requests to the Service (timestamps, IP address, and the endpoint called) for security, debugging, and abuse prevention. We do not currently run product-analytics tracking of how you use the dashboard; if we add a privacy-focused analytics tool later, we will update this policy first.

Communications

If you contact us by email or through support channels, we retain that correspondence.

3. How We Use Your Information

  • Provide, operate, and improve the Service
  • Detect and classify AI bot traffic on your behalf
  • Send transactional emails (receipts, alerts, security notices)
  • Send product updates if you opt in
  • Comply with legal obligations
  • Investigate abuse and enforce our Terms of Service

We do not sell your personal data to third parties. We do not use your website visitor data to train AI models.

4. Data Retention

We retain your account data and website traffic logs for as long as you have an active account with us. There is no separate fixed expiry for traffic logs — they are kept for the lifetime of the account that generated them. If you delete your account, your account data and traffic logs are deleted at that time (subject to any copies retained briefly in backups, and any records we must keep to comply with law, e.g. billing records).

5. Your Role vs. Ours (Controller / Processor)

For account data (your name, email, billing), Marechis the data controller. For website traffic data about your visitors, Marech is a data processor acting on your instructions — you are the controller for that data and are responsible for having a lawful basis and appropriate notices for the visitors of your own site.

Business customers who need a Data Processing Agreement (DPA) (including EU Standard Contractual Clauses and the subprocessor list below) can read the Data Processing Agreement— it’s incorporated into these Terms for paid/trial Customers automatically. Email mohamed@muhsinai.com for a countersigned copy.

6. Subprocessors & Disclosure

We use a small set of vetted subprocessors to run the Service. Hosting on a provider does not put you under that provider’s policies — they process data on our behalf under contract:

  • Amazon Web Services (AWS) — cloud hosting & database for the API (United States)
  • Vercel — hosting for this website and the customer dashboard (United States)
  • Stripe — payment processing (we never store raw card numbers)
  • Google — “Sign in with Google” authentication (only if you use it)
  • Resend — transactional email delivery (verification, receipts, alerts)

We also disclose data when:

  • Legally required — by law, court order, or government request
  • Business transfer — in a merger or acquisition, subject to the same privacy commitments

Keep this list current — adding a subprocessor generally requires notifying customers under your DPA.

7. Cookies and Tracking

We use an essential cookie for authentication and session management. We do not currently use analytics cookies, and we do not use third-party advertising cookies. If we introduce a privacy-focused analytics tool in the future, we will update this policy before doing so.

You can disable cookies in your browser, but this may break authentication.

8. Security

Data is encrypted in transit (TLS 1.2+) and at rest (AES-256). We enforce access controls and conduct regular security reviews. No method of transmission over the internet is 100% secure — we cannot guarantee absolute security.

9. Your Rights

Depending on your location, you may have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate data
  • Request deletion of your data (“right to be forgotten”)
  • Object to or restrict certain processing
  • Data portability (receive your data in a machine-readable format)
  • Withdraw consent at any time where processing is based on consent

To exercise any of these rights, email mohamed@muhsinai.com. We will respond within 30 days.

10. Children's Privacy

The Service is not directed at children under 13. We do not knowingly collect data from children. If you believe we have collected data from a child, contact us and we will delete it promptly.

11. International Transfers

We operate primarily in the United States. If you are located outside the US, your data may be transferred to and processed in the US. Where required by law (e.g. GDPR), we rely on Standard Contractual Clauses or other lawful transfer mechanisms.

12. GDPR (EEA Users)

If you are in the European Economic Area, our lawful bases for processing are: (a) contract performance for operating the Service; (b) legitimate interests for security and abuse prevention; (c) legal obligation for compliance; and (d) consent where applicable. You have the right to lodge a complaint with your local supervisory authority.

13. CCPA (California Residents)

California residents may request disclosure of personal information collected, sold, or disclosed, and may opt out of the “sale” of personal information. Marech does not sell personal information. To submit a verifiable consumer request, email mohamed@muhsinai.com.

14. Changes to This Policy

We may update this policy. Material changes will be notified via email or an in-app banner at least 14 days before they take effect. Continued use after the effective date constitutes acceptance.

15. Contact Us

Privacy questions or requests: mohamed@muhsinai.com

Marech · Minneapolis, MN, USA