Privacy Policy
Last updated: August 4, 2026
Marea Lab ("Marea Lab", "we", "us") operates the website marealab.ar and its associated platform (the "Platform"), which helps small businesses create and publish their social media content and answer the messages their customers send them. This policy explains what personal data we process, why, who we share it with, how long we keep it, and how you can exercise your rights, including deletion.
1. Two different roles
This distinction matters, because it determines who decides what happens with your data:
- For our own purposes, we process the data of our business clients and of visitors to our website. Here Marea Lab is the data controller.
- On behalf of our clients, we process the messages that people send to our clients' business accounts. Here the business is the controller and Marea Lab acts only as a processor: we follow the client's instructions and use that data solely to provide the service. If you messaged a business and want your data deleted, see section 9 — you can ask us directly, or ask the business.
2. Data controller
Marea Lab — Carolina Mora · Puerto Madryn, Chubut, Argentina · caritodg2011@gmail.com. Write to that address with any question about privacy or about your data.
3. What data we collect
- Account data: name, email address and contact details of the businesses that use the Platform.
- Content: the text, images and video our clients create or approve for publishing on their social accounts.
- Connected accounts: when a client connects an account (for example Instagram, Facebook, WhatsApp, TikTok or Google), we store the access token that platform grants us and the basic identifiers of the connected account (username, account ID, profile picture). Per-platform detail is in sections 5 and 6.
- Conversations: the messages exchanged between a business and the people who write to it — message content, attachments, timestamps, and the sender's public profile name and identifier as provided by the messaging platform. We never receive the phone number or email address of a person writing from Instagram or Messenger unless they choose to share it in the conversation.
- Usage data: minimal technical logs needed to run the service (delivery states, errors).
We do not request or store special categories of data, and we do not knowingly collect information from minors (the Platform is intended for businesses and people over 18).
4. What we use the data for
- Provide the service: publish the content the client approved, and read and reply to the messages the client's customers send, on the accounts the client connected.
- Show the business its conversations in a shared console, so its team can take over any conversation from the assistant.
- Communicate with our clients about their service.
- Operate, maintain and improve the Platform.
- Comply with legal obligations.
We use the data for nothing else. We do not sell personal data, and we do not use it for advertising, profiling, or training artificial intelligence models.
5. Messaging data from Meta platforms
When a business connects its Facebook Page and its linked Instagram professional account, it grants our app permission through Meta's official authorization flow (Facebook Login for Business). We never ask for or store the account holder's password, and the business can disconnect at any time from its dashboard.
With the permissions pages_messaging, instagram_basic and
instagram_manage_messages, we receive and store:
- The messages people send to that business on Messenger and Instagram Direct, including attachments.
- The sender's public profile name, username and platform identifier — so the business knows who it is talking to.
- The Page and Instagram account identifiers, and the access token Meta grants.
We use this data only to display those conversations to the business and to reply on its behalf. We do not read messages of accounts that are not connected, we do not access the business's followers or private content beyond the conversations, and we do not use message data for advertising or for training models. Our use of information received from Meta follows the Meta Platform Terms and the Meta Developer Policies.
The same applies to WhatsApp when a business connects a number through the WhatsApp Business Platform: we receive and store the messages exchanged with that number, for the same purpose and under the same limits.
6. Data from other connected platforms
Access to every account happens exclusively through each platform's official APIs, with the permissions the account holder grants in that platform's authorization (OAuth) flow.
Meta (publishing)
Separately from messaging, a business may connect its accounts so we can publish content it approved. In that case we store the granted access token and the basic identifiers of the Page or account, and we use them only to publish that approved content.
TikTok
With the permissions user.info.basic, video.upload and video.publish
we obtain and store basic profile information (display name, avatar, open id / union id) and the
access and refresh tokens TikTok grants. We use them only to show the client which account is connected and
to publish the videos the client created and approved, at the privacy level the client chooses. We do not
access the client's private content, messages or followers. Our use of TikTok information follows the
TikTok Developer Terms of Service
and the TikTok Developer Guidelines.
Google (Business Profile)
We store the access token and the listing identifiers to publish the posts the client approved. Our use of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.
7. Automated replies and AI processing
The Platform includes an assistant that drafts replies on behalf of the business. To generate a reply, the content of the recent conversation is sent to a third-party AI provider (Google, through its Gemini API) and processed under that provider's API terms. Only what is needed to answer is sent: the recent messages of that conversation and the knowledge base the business itself wrote.
Marea Lab does not use conversations to train models, its own or anyone else's. A person from the business can take over any conversation at any time, and the assistant then stops replying in that conversation.
8. Who we share data with
We do not sell or rent personal data. We share it only with:
- Infrastructure providers that host the Platform (cloud services; servers may be located in the United States), under confidentiality obligations and only to operate the service.
- The AI provider described in section 7, only to generate replies.
- The official APIs of the platforms the client connects (Meta, TikTok, Google), strictly to deliver messages and publish approved content.
- Authorities, when required by law.
9. How long we keep data — and how to delete it
- Conversations and their messages are automatically deleted 30 days after the last activity. This is enforced by the Platform itself, without anyone having to request it.
- Access tokens for connected accounts are kept while the connection is active. They are deleted when the account is disconnected, when access is revoked, or when the client leaves the service.
- Account data and content are kept while the client relationship is active and deleted when no longer needed.
- Technical logs are kept for the minimum time needed to operate and debug the service.
Requesting deletion. You can ask us to delete your data in any of these ways:
- If you are a business using the Platform: disconnect the account from your dashboard (Channels → Disconnect). We delete the tokens and the data associated with that connection.
- If you messaged a business that uses Marea Lab: write to caritodg2011@gmail.com from the account you used, or ask the business directly. We will delete your conversation and confirm, normally within 30 days. In any case, it is deleted automatically 30 days after the last message.
- Revoking access from the platform itself (for example, Facebook → Settings → Business Integrations, or Instagram → Apps and Websites) also stops our access and removes the tokens.
10. International transfers
Because we use cloud providers and platform APIs, some data may be processed outside Argentina (for example, in the United States). We take reasonable measures so that such processing has an adequate level of protection.
11. Security
Tokens and data are stored on infrastructure with restricted access and encryption in transit. We apply the principle of least privilege: we store only what is needed to provide the service.
12. Your rights
You may request access, rectification, update or deletion of your data, and object to its processing, by writing to caritodg2011@gmail.com. We respond within the periods set by Argentina's Personal Data Protection Act No. 25.326. The supervisory authority in Argentina is the Agencia de Acceso a la Información Pública.
13. Changes to this policy
We may update this policy. The current version is published on this page with its update date, and we notify active clients of relevant changes.
14. Contact
Marea Lab · Puerto Madryn, Chubut, Argentina · marealab.ar · caritodg2011@gmail.com
This is an English translation provided for convenience. The Spanish version is the binding one for our Argentine clients.