Privacy Policy

Last updated: September 14, 2026

This Privacy Policy explains how Aristo Intelligence, Inc. ("Aristo Intelligence," "we," "us," or "our") collects, uses, discloses, and protects personal information when you use the Marble mobile application, visit heymarble.ai, join the Marble waitlist, or contact us (collectively, the "Services"). It also explains how we handle records from the discontinued Marble Break leaderboard.

Information We Collect

Marble App Account Information

When you create or use a Marble app account, we may collect:

  • Your email address, including an Apple private relay address if you choose Hide My Email.
  • A user identifier and limited account information provided by Apple or Google when you sign in. We do not receive your Apple or Google password.
  • Authentication and session information needed to keep you signed in and protect your account.
  • A phone number and verification result when phone verification is required for shopping.

You may also use Marble without creating an Apple or Google account. In guest mode, we create a random anonymous user identifier and authentication session so that the app can save and retrieve your conversations on that device. We do not collect your name or email address for a guest session.

Marble App Conversations

When you use the Marble app, we collect:

  • The grocery-related messages and instructions you submit.
  • Conversation titles derived from your messages.
  • Responses generated for you and associated conversation history.
  • Operational metadata such as request and run identifiers, model name, timestamps, token usage, latency, completion status, and error codes.

We do not intentionally log complete prompts or responses in our application logs. Conversation content is stored with your signed-in account or anonymous guest identifier so that you can view your history until you delete it or the associated user record.

Shopping, Delivery, Food Preference, and Payment Information

When you use shopping features, we may collect and store:

  • Your delivery address and, when different, the recipient's name and phone number.
  • Food preferences that you choose to provide, including diet selections, allergies, and notes. Allergy information may be sensitive; you may skip these questions or update your answers later.
  • Product searches, cart items, retailer selections, order plans, prices and estimates, approvals, retailer order status, purchase history, cancellation and refund records, and support requests about an order.
  • Payment-method and transaction identifiers, card brand, last four digits, expiration details, authorization and charge amounts, and payment status. Stripe handles card entry and payment processing; we do not store your full card number or security code in Marble's database.

We may use an address-search provider to return address suggestions and resolve an address you select. To place an approved order, we may provide the relevant retailer or delivery service with the products, delivery address, recipient details, and delivery instructions needed to fulfill it.

Website, Waitlist, and Historical Marble Break Information

When you use our website, join the waitlist, or contact us, we may collect:

  • Your email address.
  • Your age and gender when you complete the waitlist survey.
  • Your waitlist referral relationships and referral progress.
  • Historical Marble Break records may contain a nickname or handle, score, round reached, and rank. New scores are no longer accepted.
  • Information you include in support messages, requests, or feedback.
  • Any other information you choose to provide.

Information Collected Automatically

When you use the Services, we and our service providers may automatically collect:

  • Browser type, device type, operating system, language, app version, and similar technical information.
  • IP address, approximate location derived from IP address, timestamps, diagnostic information, and security logs.
  • The referring page or URL and the source associated with a waitlist submission.
  • Website page views, interactions, and related usage information.
  • Cookies, private email-link credentials, local storage identifiers, and similar technologies used to operate, secure, and understand the website.
  • Historical Marble Break records may include a browser identifier and pseudonymous network hash previously used to limit abusive submissions. The leaderboard record does not contain the raw network address.

The mobile app's analytics and diagnostic processing is described under "Analytics and Advertising Technologies" below.

How We Use Information

We may use personal information to:

  • Create, authenticate, maintain, and secure Marble app accounts.
  • Save and display conversation history.
  • Verify phone numbers, save delivery and food preferences, maintain carts, and support shopping in available locations.
  • Prepare and submit orders you approve, manage payment methods and transactions, provide order updates, and handle cancellations, refunds, and order support.
  • Generate grocery lists, meal plans, substitution ideas, comparison criteria, and budgets in response to app messages.
  • Enforce message limits, prevent duplicate requests, rate-limit usage, and detect abuse.
  • Process account deletion requests and revoke Sign in with Apple tokens when required.
  • Manage the waitlist and administer waitlist submissions and referrals.
  • Restrict access to and delete historical Marble Break records after applicable preservation obligations are resolved.
  • Send early-access notices and product updates that you requested.
  • Respond to support messages, requests, and feedback.
  • Operate, maintain, secure, troubleshoot, and improve the Services.
  • Measure website usage and the effectiveness of website advertising and marketing campaigns.
  • Detect, prevent, and investigate fraud, abuse, security incidents, and technical problems.
  • Comply with law, enforce our agreements, and protect our rights and the rights of others.

Artificial Intelligence Processing and Your Permission

Before Marble sends conversation content to OpenAI for the first time, the app identifies OpenAI as the recipient, explains what information will be sent and why, and asks for your permission. If you allow AI data sharing, Marble may send up to 30 recent user and assistant messages from the same conversation, including the message you submit, and relevant shopping context to OpenAI. The context may include your saved delivery address, recipient name and verified phone number, diet and allergy answers and notes, cart, and order plan. Anything personal that you include in a message or these fields may therefore be included in the content sent to OpenAI. We do not send your Apple or Google password or full payment card details to OpenAI.

OpenAI processes this content on our behalf to generate the response you request and support the shopping tools you use. We configure model requests not to be stored for product features. OpenAI may nevertheless retain API inputs and outputs for up to 30 days for abuse monitoring unless a shorter approved retention setting applies.

We do not use app conversations, waitlist information, website interactions, or other submissions to train our own AI models, and we do not permit OpenAI to use Marble app conversation content to train its models.

You may decline this sharing and still view the app and saved conversations, but Marble cannot generate new AI responses without sending the relevant conversation content to OpenAI. You may withdraw permission at any time under Menu → Settings → AI data sharing. After you withdraw permission, Marble will not send further conversation content to OpenAI unless you allow it again.

AI-generated responses can be inaccurate or incomplete. Marble does not use conversation content to provide medical diagnoses. If a response concerns allergies, ingredients, or food safety, verify product labels and consult an appropriate professional when necessary.

Analytics and Advertising Technologies

We use PostHog in the Marble mobile app for product analytics, diagnostics, and error monitoring. This may include app interactions, pseudonymous identifiers, device and app information, performance data, and sanitized error details. We seek to remove or mask sensitive values from telemetry, but diagnostic events can still contain account-linked or device information. The app does not use mobile session replay or Meta Pixel.

We use PostHog on the Marble website to help us understand how the website and waitlist are used. Depending on our configuration, PostHog may process information about visits and interactions, browser and device information, analytics identifiers, and information associated with a visit or waitlist submission.

We use Meta Pixel on the Marble website to measure visits, waitlist signups, and the effectiveness of advertisements on Meta services. Meta may use cookies and similar technologies to provide measurement, personalization, and advertising services. We do not send the email address, age, or gender entered in the waitlist form to Meta through the Meta Pixel.

You may control cookies and similar technologies through your browser or device settings and manage advertising preferences through Meta's settings. Restricting these technologies may affect parts of the website.

How We Disclose Information

We may disclose personal information to:

  • Supabase, which provides authentication, database, and infrastructure services for the Marble app and website.
  • OpenAI, which processes app conversation content to generate requested responses.
  • Apple and Google, which provide account authentication services when you choose their sign-in option.
  • Twilio, which helps verify phone numbers and deliver verification messages.
  • Google Maps Platform, which helps search for and resolve delivery addresses.
  • Stripe, which processes payment methods, authorizations, charges, cancellations, and refunds.
  • Retailers and delivery providers, which receive order and delivery information needed to process or fulfill an approved purchase.
  • PostHog, which provides analytics, diagnostics, and error monitoring for the Marble app and website.
  • Meta, which provides advertising measurement and optimization services for the Marble website through Meta Pixel.
  • Hosting, security, communications, and other vendors that process information on our behalf to operate the Services.
  • Professional advisers, regulators, courts, law enforcement, or other parties when disclosure is required by law or reasonably necessary to protect rights, safety, security, or the integrity of the Services.
  • Parties involved in a merger, financing, acquisition, reorganization, bankruptcy, sale of assets, or similar business transaction.

Service providers may process information only for the services they provide to us and subject to applicable contractual and legal requirements. We require third parties with whom we share personal information to provide the same or equivalent protection described in this Privacy Policy and required by applicable law.

Data Retention

We retain Marble app account information, delivery and food preferences, and conversation history while your account remains active. Guest conversation history is retained with the associated anonymous user record until you delete the guest data. If you remove the app or otherwise lose the guest session without deleting the guest data first, you may no longer be able to access that record; you may contact us for help with a deletion request. We retain order, payment, refund, fraud-prevention, support, operational, diagnostic, and security records for as long as reasonably necessary for the purposes described above and as required or permitted by law. Retention periods vary based on the type of information, operational needs, and legal requirements.

We retain waitlist information through the Marble product launch and for the period reasonably necessary to send related follow-up communications. After that period, we will delete or de-identify the information unless continued retention is reasonably necessary to:

  • Comply with legal obligations.
  • Resolve disputes or enforce agreements.
  • Maintain security, prevent abuse, or investigate incidents.
  • Maintain limited backups and business records as permitted by law.

The Marble Break leaderboard is discontinued and its entries are no longer publicly available. Historical entries remain access-restricted while we verify applicable backup and preservation obligations, after which we will delete them from active systems. If you request deletion sooner, please provide enough information for us to identify the relevant entry.

Account and Data Deletion

You can delete your Marble app account from Menu → Settings → Delete account. Guest users can delete the anonymous user record and associated conversations from Menu → Settings → Delete guest data. After confirmation, we delete the user record and associated stored conversations and messages from our active systems. For accounts that use Sign in with Apple, we require fresh Apple authentication and attempt to revoke the associated Apple token before deleting the account. Payment processors, retailers, and other third parties may retain their own transaction records under their policies. We may retain limited transaction records where required or permitted by law or needed to resolve a pending charge, refund, dispute, or fraud investigation.

To safely recognize a repeated deletion request if a network response is lost, we keep a limited technical receipt containing the former account identifier and a random command identifier for up to 24 hours. This receipt does not contain conversation content.

We may retain limited information where reasonably necessary to comply with law, resolve disputes, prevent fraud or abuse, protect security, or maintain backups for a limited period. Deleting a Marble app account does not automatically delete a separate website waitlist submission or historical Marble Break entry that cannot reasonably be linked to that account. You may ask us to delete those records by contacting us.

Your Choices and Privacy Rights

You may unsubscribe from product-update emails by following the instructions in the message or by contacting us.

Depending on where you live, you may have the right to request:

  • Access to personal information we hold about you.
  • Correction of inaccurate personal information.
  • Deletion of personal information.
  • A portable copy of certain personal information.
  • Restriction of or objection to certain processing.
  • Withdrawal of consent where processing is based on consent.
  • Opt out of the sale or sharing of personal information or targeted advertising, where applicable.
  • An appeal of a decision concerning a privacy request, where applicable.

We may need to verify your identity before completing a request. These rights may be subject to exceptions permitted by law. We will not discriminate against anyone for exercising a privacy right.

European Users

Aristo Intelligence is the controller of personal information described in this policy.

Where European data protection law applies, we process personal information on one or more of the following legal bases:

  • Performance of our agreement with you, including providing account access and requested app responses.
  • Your consent, including when you ask to join the waitlist or receive product updates.
  • Our legitimate interests in operating, securing, analyzing, and improving the Services, provided that those interests are not overridden by your rights.
  • Steps requested by you before entering into a contract.
  • Compliance with legal obligations.

We are based in the United States, and personal information may be processed in the United States and other countries where our service providers operate. Where required, we use appropriate safeguards for international transfers.

You may lodge a complaint with the data protection authority in your country. We encourage you to contact us first so we can address your concern.

California Privacy Notice

California residents may have rights to know, access, correct, delete, and obtain a copy of personal information, and to opt out of certain sales or sharing.

The categories of personal information we collect are described in "Information We Collect." The purposes for collection and use are described in "How We Use Information." The categories of recipients are described in "How We Disclose Information."

We do not sell personal information for money. Our use of Meta Pixel on the Marble website may be considered "sharing" personal information for cross-context behavioral advertising under California law. California residents can opt out by contacting us. We do not discriminate against anyone for exercising applicable privacy rights.

Security

We use reasonable administrative, technical, and organizational safeguards designed to protect personal information. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

Age Requirement

The Services are intended only for people who are at least 18 years old. We do not knowingly collect personal information from anyone under 18. If you believe a person under 18 has provided personal information, please contact us so we can investigate and delete it where appropriate.

Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will provide notice by posting the updated policy, changing the "Last updated" date, sending an email, or using another reasonable method as required by law.

Contact Us

To ask a question, exercise a privacy right, or request deletion of information, contact:

Aristo Intelligence, Inc.

2108 N ST #16175
Sacramento, CA 95816
United States

Email: support@aristo.so