Trust
Security
Last updated July 2026 · Magic Marketer Pty Ltd · ABN 47 695 318 659
Our approach
Magic Marketer App handles marketing content, social credentials, and — when you connect them — calendar and call data. We treat that as sensitive by default. Our security practice is built around least privilege, encryption, and keeping customer data used only to provide the Service.
We do not use your call transcripts, content, or Google user data to train general AI models. Details on collection and retention are in our Privacy Policy, including the Google API Limited Use Disclosure.
Encryption
- All traffic between your browser and Magic Marketer App is encrypted in transit using TLS.
- Sensitive credentials (including OAuth tokens for connected social accounts) are stored encrypted and used only to provide features you enable — such as publishing on your behalf.
- We prefer providers and infrastructure that encrypt data at rest as standard.
Access control
- Customer accounts are protected by authentication; you are responsible for keeping your login credentials confidential.
- Internal access to production systems and customer data is limited to people who need it to operate or support the Service.
- Organisation accounts support admin-managed team access so you can control who can draft, review, and publish within your workspace.
Infrastructure & third parties
The Service runs on reputable cloud infrastructure. We use carefully chosen subprocessors only where needed to deliver the product — for example payment processing (Stripe), AI draft generation (Anthropic), call transcription (Recall.ai), and scheduling/analytics (Zernio). Where applicable, data is handled under data processing agreements, and we do not authorise those providers to use your content to train their models.
A fuller list of how we share data appears in our Privacy Policy §4.
Application security
- We keep dependencies and platform software reasonably up to date.
- We design features so high-risk actions (publishing, connecting accounts, calendar access) require explicit user action and provider consent flows.
- We monitor for abuse of public endpoints (rate limits and shared secrets where appropriate) and review security-relevant changes as part of shipping product updates.
Your responsibilities
Security is shared. You are responsible for protecting your account credentials, reviewing content before it publishes, obtaining any legally required consent before recording or uploading conversations involving others, and managing team access inside organisation accounts. See our Terms of Service for recording consent and acceptable use.
Reporting a concern
If you believe you have found a security vulnerability or suspect unauthorised access to an account, please contact us promptly at grow@magicmarketer.app. Include enough detail for us to reproduce or investigate the issue. We take responsible disclosure seriously and will acknowledge reports as quickly as we can.