Privacy & Data Protection
Built for trust. Designed for nonprofits.
Marta was designed specifically for nonprofit professionals who work with confidential donor, prospect, and organizational information.
Privacy is built into the platform’s architecture. In protected workflows, identifying information is processed by Marta’s Privacy Shield before content is sent for AI processing. Names and other identifying details are replaced, when detected, with descriptive placeholders such as DONOR_1, SPOUSE_1, ADVISOR_1, or ORGANIZATION_1.
In Text Mode, users can review and approve the protected version before it is submitted. Marta also uses session isolation, data minimization, secure transmission, and short retention periods to reduce unnecessary exposure of sensitive information.
How Marta Protects Information
Privacy by Design
Privacy protections are built into Marta’s architecture rather than added after processing.
Server-Side
Privacy Shield
Identifying information is processed on Marta’s server before protected content is sent for AI processing.
User Review
In Text Mode, users can review, edit, and approve the protected version before submission.
Role-Based
Protection
People and organizations may be replaced with descriptive placeholders such as donor, spouse, advisor, employer, or organization.
Data Minimization
Marta is designed to send only the information needed to complete the requested task.
Session Isolation
Conversations are separated by session to reduce unintended sharing of information between conversations.
Protected Voice
and Documents
Privacy Shield protections are applied to supported voice, document, contact-report, and data-analysis workflows.
Secure
Transmission
Information is transmitted through encrypted HTTPS connections.
Secure Exports
Export files are generated through a server-authoritative process using temporary references rather than browser-submitted document contents.
Continuous
Improvement
Marta’s privacy protections are regularly tested, reviewed, and strengthened.
Data Retention
Marta is designed to retain information only for as long as it is needed to provide the requested service.
| Data Type | Retention Period |
|---|---|
|
Conversation Session
|
Up to 2 hours of inactivity, allowing users to continue an active conversation before the session expires. |
|
Privacy Shield Alias Memory
|
Up to 2 hours of inactivity, preserving consistent protected references during the conversation. |
|
Export References
|
Up to 15 minutes, allowing users to securely generate or download an export. |
|
Structured Export Data
|
Up to 15 minutes, after which the temporary export data expires. |
|
Uploaded Files
|
Deleted after processing when the applicable workflow is complete. |
|
Temporary Processing Data
|
Retained only as needed to fulfill the request and then removed according to the applicable retention period. |