Skip to content
Margo

Privacy policy

How Margo handles your journal. Written to be read, not to be survived.

Last updated 29 September 2026.

The short version

  • Your recordings never leave your phone. Audio is stored in the app and is never uploaded or synced anywhere, not even to your own iCloud.
  • Speech is recognized on your iPhone wherever the device supports it, using Apple’s Speech framework. On supported iPhones that covers all eight launch languages.
  • Only the text is sent out, to be written up as a journal entry. It is sent with no user id attached.
  • Your journal syncs only through your own iCloud, and only when iCloud is on. Burrow Studio cannot read it.
  • You can lock the journal with Face ID, Touch ID, or your passcode, and keep entries off the Lock Screen with private notifications.
  • There is no tracking. No advertising identifier, no ad networks, no third-party trackers, no cross-app profiling.
  • You can delete everything from inside the app, on the phone and in iCloud, at any time, without asking anyone.

Who this is about

Margo is an iPhone app published by Burrow Studio. This policy covers the app and this website. Burrow Studio is the data controller for the small amount of information described below.

Privacy questions and data requests go through the support form in the app, on the Account page (the button at the top of Home). See the support page for the other ways to reach Burrow Studio.

What is collected, and why

This list matches the privacy manifest shipped inside the app binary. There is nothing collected that is not named here.

Email address

Linked to your identity. Collected for app functionality only, not for analytics and not for advertising.

Your email address is your account. It is the address a six-digit sign-in code is sent to, or the address Apple or Google hands back when you sign in that way. It is used to sign you in and to reply to you if you contact support. It is never sold, never rented, and never used to send marketing you did not ask for.

User content

Not linked to your identity. Collected for app functionality only.

Two things fall under this. The first is the transcript text of what you said, which is sent to a structuring service so it can come back as a journal entry with a title, tidied prose, a category, extracted to-dos, and the one remark or question Margo leaves you. The request carries no account id and no device id, so the text arrives without anything attached that says who you are.

The same route, with the same absence of any id, carries the text of an entry when you ask for a creation or a translation, and the text of the week’s entries when Margo writes your weekly letter.

The second is anything you type into a support message from inside the app, because that is how it reaches a person who can answer it.

Product interaction, and a random install id

Not linked to your identity. Collected for analytics only.

The app records basic events such as which screen was opened, which action was taken, and which app version you are on. This is used to find out where the app is confusing or broken.

Those events are stamped with a random identifier that the app generates for itself on first launch. It is not the IDFA and not the IDFV. It is a random UUID with nothing derived from your device or your identity, and it is thrown away and replaced if you delete and reinstall the app.

What is never collected

  • Audio. Recordings are written to the app’s own storage on your phone and stay there. No recording is ever uploaded or synced, to Burrow Studio, to iCloud, or to anybody else. The app’s privacy manifest deliberately declares no audio collection, because there is none.
  • Your journal. Entries live in the app’s database on your phone and, if iCloud is on, in your own private iCloud database. They are never stored on a Burrow Studio server.
  • Face ID and Touch ID data. When the lock is on, iOS checks your face, fingerprint, or passcode and tells the app only whether it matched. Margo never sees biometric data.
  • Location. The app does not ask for it and does not use it.
  • Contacts, photos, calendars, or health data. None of it is requested.
  • Payment details. Purchases go through Apple. Burrow Studio never sees your card.

Margo only records while the recording page is open. Nothing runs in the background, and nothing listens when you are not looking at it.

How speech becomes text

Margo uses Apple’s Speech framework and asks it to recognize speech on the iPhone itself wherever the device supports that for the language you speak. On supported iPhones that covers all eight launch languages.

On an iPhone that cannot recognize a language on the device, iOS uses Apple’s own speech recognition service instead, under Apple’s privacy policy. Either way, the recording file stays on your phone and no audio reaches Burrow Studio.

Tracking

There is none. The app’s privacy manifest declares tracking as false and lists no tracking domains. Margo does not use the advertising identifier, does not ask for App Tracking Transparency permission, does not embed an ad network, and does not share anything with data brokers.

This website carries no analytics script, no advertising pixel, and no third-party embed. That is also why there is no cookie banner. There is nothing to consent to.

Your entries and transcripts are not used to train any AI model.

Who receives data

A handful of companies handle parts of the service. They are named here because they do receive something, and you are entitled to know which.

Anthropic

Writes the transcript text up as a journal entry. Also writes creations and translations when you ask for them, and your weekly letter from that week's entries. Receives the text with no user id attached.

Cloudflare

Runs the proxy that forwards that text to Anthropic. Receives the same text in transit.

Supabase

Stores analytics events and support messages. Receives product interaction events, the random install id, and anything typed into a support message.

RevenueCat

Tracks subscription state so the app knows whether Plus is active.

Resend

Delivers sign-in codes and support email. Receives the email address.

Apple

Processes payments and runs the App Store account. When iCloud is on, also stores your synced journal (entries, to-dos, creations, and weekly letters) in your own private iCloud database through CloudKit. Burrow Studio cannot read that database and never sees card details. Recordings are never synced.

Each of them acts on Burrow Studio’s instructions for the purpose described, and none of them is permitted to use your data for their own advertising. Some of them operate servers outside your country, which means data may be processed internationally.

Where your journal lives, and iCloud sync

On your phone, and in your own iCloud if you use it.

When iCloud is on for your iPhone, Margo syncs your entries, to-dos, creations, and weekly letters through your own private iCloud database, using Apple’s CloudKit. That database belongs to your Apple Account and is kept by Apple under Apple’s privacy terms. Burrow Studio cannot read it. It is what lets the journal follow you to a new phone.

Recordings are never synced. They stay on the phone they were made on, so a new phone gets every written entry but not the audio.

If iCloud is off, or you are signed out of it, the journal stays on this phone only, and deleting the app deletes it. Settings in Margo, under Privacy, shows whether the journal is reaching iCloud. You can export the whole journal as markdown at any time.

Notifications

Every notification Margo sends is scheduled on the phone itself, through iOS. There is no push server, and no notification passes through Burrow Studio. Nothing arrives unless you allow notifications, and you can switch them off in the iPhone’s Settings at any time. Daily reminders and returning questions each have their own switch in Margo’s Settings too.

  • Daily reminders, only if you turn them on. You choose from 1 to 24 a day and the hours they fall between. If you stop writing, they become a short comeback series that stops entirely after 30 days.
  • An open question, the next morning, when Margo asked you something you have not answered yet.
  • A reminder that your weekly letter is ready.
  • A notice before a free trial ends, if you start one.

With private notifications on, none of them shows the text of an entry or a question on the Lock Screen. A question arrives as “Margo left you a question” and the words wait inside the app. Turning the lock on switches private notifications on too.

The lock

The lock is optional and off until you turn it on, in Settings, under Privacy. When it is on, Margo asks for Face ID, Touch ID, or your passcode each time you come back to it, and covers the screen in the app switcher so no entry shows there. iOS does the check and tells the app only whether it passed. Margo never sees or stores biometric data.

The widget and the Lock Screen list

The Home Screen widget shows your streak and the day’s prompt. To do that, the app writes a small snapshot into a shared space on the phone called an app group: the streak count, your goal, whether today is written, and the day’s prompt. The widget reads only that snapshot. It never opens your journal and never shows entry text. The snapshot stays on the device.

The Lock Screen to-do list is different. It appears only if you pin a to-do list there, and it shows the text of those to-dos on the Lock Screen until you unpin it.

How long things are kept

  • Recordings and entries: as long as you keep them. Deleting an entry deletes it and its audio, and removes the entry from your iCloud too.
  • Transcript text sent for structuring: processed to produce the entry and not retained as a stored record afterwards. It carries no account id, so it cannot be tied back to you.
  • Your email address: for as long as you have an account. Deleting your account deletes it.
  • Analytics events: kept for up to 24 months, then removed. They are not linked to your identity at any point.
  • Support messages: kept while the conversation is open and for a reasonable period afterwards so a follow-up makes sense.
  • Subscription records: kept as long as needed to honour your subscription and to meet tax and accounting obligations.

Your rights

Depending on where you live, you have the right to ask what is held about you, to have it corrected, to have it deleted, to object to some processing, and to receive a copy in a portable form. If you are in the EU or the UK, these are your GDPR rights. If you are in California, they are your CCPA rights.

Most of them you can exercise yourself, immediately, without asking. See below.

The legal basis for handling your email address is performance of the contract, meaning giving you an account. For analytics it is legitimate interest in making the app work properly, and the data is not linked to you. For support messages it is your request.

Privacy questions and data requests go through the support form in the app, on the Account page (the button at the top of Home). See the support page for the other ways to reach Burrow Studio.

If you are in the EU or the UK and are not satisfied with the response, you may complain to your national data protection authority.

Deleting your data

Both of these are inside the app.

  • Delete all data, at the bottom of Settings, erases every entry, recording, to-do, creation, and weekly letter, on the phone and in your iCloud, and Margo starts over. Your account stays.
  • Delete account, on the Account page (the button at the top of Home), removes your account, the email address attached to it, and the records kept for it on Burrow Studio’s servers, such as support messages. It then erases your journal the same way, on the phone and in iCloud. This cannot be undone.

Deleting your account does not cancel an active subscription. Subscriptions are managed by Apple, and you cancel them in your Apple account settings. There is more about that on the support page.

Children

Margo is not directed at children. It is not intended for anyone under 13, and where local law sets a higher age for consent to data processing, that age applies instead. Burrow Studio does not knowingly collect information from children. If you believe a child has created an account, get in touch and it will be removed.

Security

Everything that leaves the phone travels over an encrypted connection. Your entries and recordings sit inside the app’s own storage area, which iOS keeps separate from other apps and protects with your device passcode and encryption. With the lock on, the app itself asks for Face ID, Touch ID, or your passcode too. A synced journal sits in your private iCloud database, protected by your Apple Account.

No system is perfect, and nobody honest claims otherwise. What can be said is that the design keeps the most sensitive part, the recordings of your voice, on your phone and nowhere else.

Changes to this policy

If this policy changes in a way that affects what is collected or who receives it, the date at the top of this page changes and the change is described in the app’s release notes. Continuing to use Margo after a change means the updated policy applies.

Contact

Privacy questions and data requests go through the support form in the app, on the Account page (the button at the top of Home). See the support page for the other ways to reach Burrow Studio.

Burrow Studio, publisher of Margo.