Privacy & Security

Your documents stay yours. Always.

Last updated: January 1, 2026

How We Handle Your Data

AI Processing: Azure OpenAI with zero retention
File Storage: Azure Blob with encrypted storage
Access: Time-limited tokens (expire in minutes)
Training: Your data never trains AI models
Compliance: SOC 2, ISO 27001, GDPR
Jurisdiction: US (Texas) entity

Our Commitment

Maros is built on a simple principle: provenance data belongs to the people and institutions who create it. We treat every document — certificates, invoices, catalog pages, museum records — as a sensitive cultural asset that deserves the highest level of care.

We never sell, publish, or share your data.
We never use your private documents to train models.
You stay in full control at all times.

1. Privacy by Default

Your uploads are private to you

Anything you upload is visible only within your account unless you explicitly choose to share it. No one else — not other users, not partners, not researchers — can access your documents or extracted data.

No training on private documents

Your private uploads are not used to train AI models or improve the system. They remain isolated to your workspace.

You control your data

You can delete any document, artwork, or record at any time. When you delete it, it is removed from our systems.

2. Secure Storage & Encryption

Encrypted in transit

All data sent to and from Maros is encrypted using industry-standard HTTPS/TLS 1.3 protocols.

Encrypted at rest

Documents and extracted data are stored using encrypted storage to protect against unauthorized access.

Modern, cloud-native infrastructure

Maros runs on secure, professionally managed cloud infrastructure with continuous monitoring and hardened defaults. Our infrastructure providers are SOC 2 Type II compliant.

3. Document Handling & AI Processing

We treat your documents like museum assets

Art provenance materials often contain sensitive ownership histories, private sales, estate information, and internal institutional records. We handle them with the same care expected by collectors, galleries, and museums.

AI processing with zero data retention

We use Microsoft Azure OpenAI Service for document extraction. This means:

  • Your data stays within our Azure tenant — never shared with OpenAI directly
  • Zero data retention after processing completes
  • Your documents are never used to train AI models
  • SOC 2, ISO 27001, and GDPR compliant infrastructure

Short-lived access tokens

Document URLs use time-limited access tokens that expire within minutes. Even if a link is intercepted, it becomes invalid quickly — reducing exposure risk for sensitive materials.

4. Account Security

Password protection

All accounts require secure passwords and are stored using industry-standard hashing.

Session protection

We use secure session handling to prevent unauthorized access.

Planned enhancements

Two-factor authentication (2FA) and advanced access controls are on our roadmap as the platform grows.

Privacy Policy

Information We Collect

When you create an account, we collect your email address, name (optional), and password (securely hashed). Payment information is processed by Stripe; we do not store card numbers.

When you use our services, we collect artwork information you provide, documents you upload, data extracted from documents using our AI processing, and collections you create.

We automatically collect device/browser information, IP address, pages visited, and usage patterns.

How We Use Your Information

We use your information to provide and improve our services, process documents and extract provenance information, process payments, send service-related communications, respond to support requests, detect fraud, and comply with legal obligations.

Data Sharing

We do not sell your personal information. We may share data with service providers (hosting, payment processing), for AI processing via Azure OpenAI (within our secure tenant, with zero retention), when required by law, or in connection with business transfers.

Public and Private Information

By default, all artwork records are private. You control whether to make artworks publicly accessible. When public, basic artwork information is viewable but your identity remains private unless disclosed. Document contents, prices, and personal notes always remain private.

Data Retention

We retain your information for as long as your account is active. Upon account deletion, personal information is deleted within 30 days, artwork records and documents are deleted, and only anonymized usage data may be retained for analytics.

Your Rights

Depending on your location, you may have the right to access your personal information, correct inaccuracies, delete your account and data, export your data, object to certain processing, and withdraw consent. To exercise these rights, contact us at admin@maros.art.

Cookies

We use essential cookies for authentication and session management. We may use analytics cookies to understand how users interact with our platform. You can control cookie preferences through your browser settings.

Children's Privacy

Maros is not intended for users under 18 years of age. We do not knowingly collect information from children.

International Data Transfers

Your information may be transferred to and processed in countries other than your own. We ensure appropriate safeguards are in place in compliance with applicable data protection laws.

Changes to This Policy

We may update this policy from time to time. We will notify you of material changes by posting the new policy and updating the "Last updated" date. Continued use after changes constitutes acceptance.

Questions? We're here.

If you have concerns about privacy, security, or data handling, reach out anytime. We're happy to walk you through how Maros protects your information.