Lemarc Back to lemarc.ai

Privacy policy

Last updated 29 July 2026

Lemarc is a marketing workspace. This policy explains what data Lemarc handles, where it comes from, what we do with it, and what we do not do with it. It is written to be read, not to be survived.

The short version

  • From the platforms you connect, Lemarc stores performance and spend numbers. It does not store names, email addresses, or anything else that identifies a person.
  • CRM contacts and companies are hashed before they are written. Those tables have no name, email, phone or address column at all.
  • Lemarc holds your login email and the access tokens for the accounts you connect. It needs both to work.
  • Inside the product, four third parties receive data: our AI model provider, an image-generation provider, a page-reading service, and our database host. The public marketing site uses standard analytics, which is separate.
  • We do not sell your data, and we do not share it for advertising.

1. Who we are

Lemarc ("we", "us", "our") provides an AI-powered marketing workspace that helps businesses analyze and manage their marketing operations. Lemarc is operated by Matan Buganim, based in Israel.

For anything in this policy, write to support@lemarc.ai.

Lemarc is currently a single-tenant product: one account, one workspace. There is no shared multi-user access and no cross-customer data.

2. Data from platforms you connect

Lemarc is useless without your marketing data, so you connect the accounts you already use. You choose which ones. You can skip any of them and disconnect any of them.

2.1 What we ask for, and why

PlatformPermissionWhat it lets Lemarc do
Google Analytics analytics.readonly Read traffic, conversion and channel reports for the properties you select. Read only.
Google Ads adwords Read campaign structure, spend and performance. Google issues one permission covering both reading and writing. Lemarc uses it read only. It does not create, edit, pause or delete campaigns, and it does not change budgets.
Meta ads_read Read campaign structure, spend and performance for the ad accounts you select.
LinkedIn openid, profile, email, r_organization_social, r_ads, r_ads_reporting Identify you when you connect, read the content of company pages you administer, and read ad accounts and their reporting.
HubSpot oauth, crm.objects.contacts.read, crm.objects.companies.read, crm.objects.deals.read, crm.schemas.deals.read Read contacts, companies and deals so that Lemarc can work out which marketing produced which outcomes.

Every one of these is a read permission in practice. Lemarc does not post, publish, comment or advertise on your behalf on any of these platforms.

2.2 What we store

The hashing happens before anything is written to the database, and it is fail-closed: if the hashing key is unavailable, the record is not written at all rather than written in the clear.

2.3 What we do not store

If a record fails to import, we log enough to debug the failure. Names, email addresses, click identifiers and property values are stripped before that log is written.

2.4 What we do with it

We use this data to show you how your marketing is performing, to work out what to recommend next, and to produce marketing material for you.

Lemarc uses an AI model provider to do some of that work. CRM data reaches the model only as aggregates: sums, counts, win rates, cycle times, grouped by channel. A single function is the only route from CRM data into a model prompt, and it returns totals. No individual record, no hash and no identifier is ever placed in a prompt.

We do not sell this data. We do not share it for advertising. We do not use it to build products for anyone other than you.

Model training. Your data is not used to train AI models, ours or anyone else's. We send data to our model provider only to generate results for you in the moment, and our agreement with that provider does not permit them to train on it. A human at Lemarc does not read your connected data except when you ask us to for support, when the law requires it, or when we must to keep the service secure.

2.5 Google user data

Lemarc's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically: we use Google user data only to provide and improve the features described in this policy, we do not transfer it except as needed to provide those features or as required by law, we do not use it for advertising, and we do not allow humans to read it except with your explicit permission (for example when you ask for support), where required by law, or where necessary for security.

2.6 Meta Platform Data

Lemarc's use of data received from Meta's APIs ("Platform Data", as that term is defined in Meta's Platform Terms) follows Meta's Platform Terms and Developer Policies.

Specifically: we use Platform Data only to provide and improve the features described in this policy; we do not sell it, and we do not transfer it to any third party such as a data broker, advertising network or information reseller — the only parties that receive it are the processors listed in section 5, acting on our instructions; and we delete Platform Data when you disconnect Meta, when you ask us to, when your access to Lemarc ends, or when Meta requires it, and in any event once we no longer need it for the purpose it was collected.

2.7 LinkedIn member data

Data received from LinkedIn's APIs — which LinkedIn calls "member data" — is used only to provide the features described in this policy: identifying you when you connect, and reading the company pages and ad reporting you authorize. We use it read only. Lemarc does not post, comment or advertise on LinkedIn on your behalf.

In line with LinkedIn's API Terms of Use and Marketing API restrictions, we do not use LinkedIn member data for advertising, sales or recruiting, to build or enrich audience lists, or to enhance CRM records; we do not combine it with other data to build member profiles; and we do not export, sell or transfer it, except to the processors listed in section 5 acting on our instructions. We hold it only within the limits LinkedIn's terms set, and we delete it when you disconnect LinkedIn, when you ask us to, or when your access to Lemarc ends. As noted in 2.8, LinkedIn does not currently offer a working token-revocation endpoint, so you can also remove Lemarc's access directly in your LinkedIn settings.

2.8 Disconnecting a platform

You can disconnect any platform at any time from inside Lemarc. When you do, we delete the stored token and stop reading from that platform immediately.

We also ask the platform to revoke the token on its side. Google and Meta support this and we do it. LinkedIn does not currently offer a working revocation endpoint, so a LinkedIn token stays valid on LinkedIn's side until it expires, even though Lemarc has deleted it and no longer uses it. You can remove Lemarc's access directly in your LinkedIn settings.

2.9 When we act as a processor

When you connect a CRM, the underlying records are your data about your customers, and Lemarc handles them on your instructions. We act as a data processor for that data and you are the controller.

That means: we process it only to provide the service, we will sign a data processing agreement on request, we will help you respond to access and erasure requests from your own contacts, and we will notify you without undue delay if we become aware of a breach affecting your data.

One detail worth stating plainly. When a record is deleted or merged in your CRM, Lemarc marks its local record as deleted and keeps a pointer so historical outcome totals stay correct. It does not remove the row immediately. Since the record holds no name or email in the first place, what remains is a hash and a set of numbers. If you want it gone entirely, ask us and we will remove it.

3. Data about you as an account holder

Separate from anything above, running an account means we hold a small amount of data about you.

This is the one place where the statement "Lemarc does not store personal data" would be wrong, so we are not making it. Lemarc holds no personal data from your connected platforms. It does hold your own account details, because it has to.

4. Data from early access applicants

The application form on lemarc.ai collects your name, your work email address, a LinkedIn URL, and an optional opt-in to hear from us.

We use it to decide whether Lemarc is a fit for you and to get in touch. If you tick the opt-in box, we will also send you occasional notes about what we are building. The box is not ticked by default, and every message we send has an unsubscribe link. Not ticking it does not affect your application.

We do not sell this data, we do not pass it to anyone, and we do not use it for anything other than what is described here. If you would like your application deleted, email support@lemarc.ai and we will remove it.

5. Third parties (our processors)

Four services process data on Lemarc's instructions as part of running the product. Each acts as our processor. Where you are the controller and Lemarc is your processor (section 2.9) — your CRM data, for example — these services act as our subprocessors. Each is bound by terms that permit it to process data only to provide its service to us, not for its own purposes. There is no fifth.

Current subprocessors: Anthropic (AI model provider, United States), OpenAI (image generation, United States), Jina Reader (page reading, United States), and Supabase (database and authentication host, United States).

These four are what the Lemarc application relies on. The application itself contains no product analytics, no session recording, no error-tracking service and no advertising pixels. The lemarc.ai marketing site is a separate surface with its own standard analytics, covered in section 10.

6. Deleting your data

There are three ways to remove data from Lemarc, depending on how much you want gone.

  1. Disconnect one platform. Inside Lemarc, go to the connections settings and disconnect it. The stored token is deleted and reading stops immediately.
  2. Delete specific data. Email support@lemarc.ai and tell us what you want removed. We will confirm when it is done.
  3. Delete everything. Email support@lemarc.ai with the subject "delete my account". We will delete your workspace, every connected token, all imported data and your account record within 30 days, and confirm in writing when it is finished.

If you connected Lemarc through Meta and want your data removed, option 3 above is the route. You can also remove Lemarc from your Meta account settings at any time, which stops access immediately.

7. How long we keep things

8. Security

Data is stored in a managed Postgres database with encryption at rest and row-level security. Access to production is limited to people who need it. Connections to and from Lemarc use HTTPS.

We are a small team and we are not going to pretend to hold certifications we do not have. If your security review needs specifics, ask and we will answer honestly rather than send you a badge.

9. Your rights

Depending on where you live, you may have the right to access the data we hold about you, to correct it, to delete it, to object to how we use it, to restrict how we use it, and to receive a copy in a portable format. If you are in the EU or UK, these come from the GDPR. If you are in California, similar rights come from the CCPA, including the right not to be discriminated against for exercising them.

We do not sell personal information and we do not share it for cross-context behavioural advertising, as those terms are defined under California law.

To exercise any of these, email support@lemarc.ai. We will respond within 30 days. If you are unhappy with our response, you can complain to your local data protection authority.

Where the data in question belongs to your customers rather than to you, we will pass the request to you and help you answer it, since you are the controller of that data.

10. Cookies and the marketing site

There are two different surfaces here, and they behave differently.

The Lemarc application (the product you sign in to) uses one cookie, to keep you signed in. It carries no third-party analytics, no session recording, no advertising or tracking pixels, and no error-tracking service. What it holds about your use of the product is the operational data described in section 3, kept in our own database.

The lemarc.ai marketing site (the public pages, including this one) can use one analytics service: Google Analytics 4, to understand how people find and read the site. It runs on the marketing pages only, never inside the product. We do not run advertising or retargeting pixels here.

Nothing analytics-related loads before you choose. A banner asks once on your first visit:

Either way, we record your choice in a first-party cookie named lemarc_consent for one year so that we do not ask again. To change your mind, clear this site's cookies in your browser and the banner will return.

11. Where data is stored

Lemarc is operated from Israel, and our database, AI model provider and page-reading service operate in the United States. Depending on where you are, your data may be transferred outside your region.

Israel has been recognised by the European Commission as providing an adequate level of data protection, which supports transfers from the EU to an Israeli operator. For transfers onward to the United States, and for any transfer not covered by an adequacy decision, we rely on the standard contractual clauses approved by the European Commission. We handle personal data in line with Israel's Protection of Privacy Law.

12. Children

Lemarc is a business tool. It is not for anyone under 18, and we do not knowingly collect data from children. If you believe a child has given us data, email us and we will delete it.

13. Changes to this policy

If we change what we do with data, we will update this page and change the date at the top. If the change is significant, we will email account holders before it takes effect. We will not start using data in a way this policy does not describe.

14. Contact

Questions, requests, complaints, or a security issue you would like to report: support@lemarc.ai.

Operator: Matan Buganim, Israel. Contact: support@lemarc.ai.