Privacy

What we hold, and where it is.

Markly holds a student's coursework and their phone number, which is enough that the boring parts are not optional. This is the plain version of what happens to both.

Last updated

Who this is

Markly is a project by raoco, based in Rotterdam, the Netherlands. For anything on this page, including a request to see or delete what we hold, write to support@raoco.io.

What we hold

  • Your phone number, encrypted. It is your iMessage identity and the number Mark texts, so we cannot avoid holding it — but the account’s email address is a synthetic one derived from a peppered hash of the number rather than the number itself, so it does not sit in cleartext next to your name.
  • The material you upload — past papers, problem sheets, chapters, the syllabus, and photographs of any of them.
  • Your answers and their marks, including photos of handwritten working, and which topics you keep dropping marks on.
  • Your subjects, exam dates, deadlines and settings, which is what the revision plan is built from.
  • Sign-in codes, hashed, for ten minutes. A code is single-use, capped at five attempts, and only its hash is ever stored.

What we do not hold

  • No password — there is no password to store, because there is no password.
  • No advertising identifiers, no third-party analytics and no trackers. This site sets no cookies except the ones that keep you signed in, which is why it does not ask you to accept any.
  • No card details. Markly is free through your first exam period and takes no payment.

Where it lives

In an encrypted Postgres database run by Supabase in the EU (Frankfurt), encrypted in transit and at rest and backed up nightly. Access is scoped to your account by row-level security in the database itself, not by application code that could forget. The website is served by Cloudflare.

Who else processes it

Supabase
The database, authentication and file storage. EU region.
Cloudflare
Serves getmarkly.app and its assets.
OpenAI
The model that reads a written answer, a proof or a photograph of your working and marks it against the scheme. Numeric and algebraic answers are marked without any model being asked anything, so most of what you send never reaches one.
Photon Spectrum
Sends and receives Mark’s messages over iMessage.
Composio
Only if you connect an outside account yourself, and only for the account you connected. Nothing is connected by default.

Your work is never used to train a model, never sold, and never shared with advertisers.

Why we are allowed to

For everything that makes the product work — storing your material, marking your answers, texting you — the basis is the contract between you and us: you asked for a revision service and this is the service. For keeping accounts secure and stopping abuse of the sign-in flow, the basis is our legitimate interest in the service not being used to text strangers.

How long

While your account exists. Sign-in codes expire after ten minutes whether they are used or not. When you ask for deletion, the account and its history go within 24 hours, and you can export a copy first.

Deleting it

Text Mark “delete everything”, or write to support@raoco.io from the account. Either one ends it — there is no retention flow designed to talk you out of it.

Your rights

Under the GDPR you can ask for a copy of what we hold, ask for it to be corrected, ask for it to be deleted, ask for it in a portable form, and object to or restrict what we do with it. Write to support@raoco.io and a person answers. If we get it wrong you can complain to the Dutch data protection authority, the Autoriteit Persoonsgegevens.

Age

Markly is for university students and anyone sixteen and over. It is not built for children and we do not knowingly hold their data.

Changes

If this changes in a way that matters, the date at the top changes and we say so in the app before it takes effect.