MARSHAL STACK How it runs Console Studio · soon ENRURO Contact

← Marshal Stack

Marshal AI — Privacy Policy

Last updated 25 September 2026

Marshal AI is a voice assistant for iPhone. The app does not answer on its own: it talks to an assistant server (the “core”) whose address and access token you enter in the app — either our core at ai.marshalstack.com, hosted by Marshal Stack in the EU (Hetzner, Germany), or a core you run yourself. The app connects only to that server, over TLS. This page describes what the app and our core do with your data. If you use a core run by someone else, that operator decides how the data on their server is handled.

Microphone and speech

The microphone is on only while you are talking to the assistant, and the app shows when it is listening. Your speech is turned into text by Apple’s Speech framework on the iPhone itself. Only on devices or languages where on-device recognition is not available, Apple’s speech recognition service processes the audio under Apple’s privacy policy. Audio is never sent to our servers or to any other party, and it is not recorded or stored. Spoken replies are synthesised on the iPhone as well.

What the app sends to the core

Only text and settings, never audio:

  • Your requests — the recognised text of what you asked, with a conversation id and the device type.
  • Plans — events, tasks and shopping items you add, with their time, place and notes.
  • Settings — your assistant preferences, such as which briefings and alerts you want.
  • A push notification token — issued by Apple, so the core can send you the morning briefing and alerts.

How answers are made

Simple commands — adding or reading plans, the time, weather, waves, project status — are handled by the core itself. Any other request is passed as text, through our Marshal Stack relay, to the Claude language model by Anthropic; to answer, the model may look up your plans and project status on the core. Anthropic processes this text to produce the reply under its privacy policy.

What our core stores

Your plans; the last 20 turns of each conversation, so the assistant can follow context; a log of requests and answers with their timing, used to fix errors and improve speed; answers waiting to be delivered; your settings; and the push tokens of your devices. A push token is removed as soon as Apple reports it invalid.

Calendar, weather and other connections

The core talks to other services only for features that are switched on:

  • Calendars — iCloud Calendar (CalDAV) or Google Calendar and Tasks (OAuth), if connected. The core reads and writes events and tasks there with the credentials given to it; they are kept on the core and used for nothing else.
  • Weather and waves — from Open-Meteo, for a place set in the core’s settings. The app never reads your location.
  • Project status — the state of your projects and servers from Marshal Stack, if you use it.
  • Notifications — Apple Push Notification service delivers the briefing and alerts; their text passes through Apple.

On your iPhone

The access token is kept in the system keychain, on this device only and excluded from backups; the server address is kept in the app’s settings. Both are shared, through a keychain group, only with other apps from the same developer on the same iPhone, so they can connect to the same assistant. If you allow access to Reminders, the app copies your plans into a “Marshal” list in Apple Reminders so iOS can remind you; that list stays in your Apple account. Deleting the app removes its local data.

What we do not collect

The app contains no analytics, advertising, attribution or crash-reporting SDKs and no third-party trackers. It does not read your location, contacts, photos or health data, and it does not track you across other apps or sites. No data is sold, and none is shared for advertising.

Retention and deletion

There is no sign-up in the app: access to our core is given by an access token. Data on our core is kept while your access is active. To have it deleted — plans, conversations, the request log, settings and device tokens — write to the address below from the email you used to get access; we delete it and revoke the token within 30 days. To stop using the app on a device, delete the app; this removes the token and the server address from that iPhone.

Children

Marshal AI is not directed at children under 13.

Changes

If this policy changes, the updated version will be posted on this page with a new date above.

Contact

Questions and deletion requests: [email protected]

© 2026 Marshal Stack
Studio · soon Privacy Terms Contact