Privacy Policy
Effective date: September 15, 2026 · Version 2026-09-15
The guiding principle: your code and project data stay on your machine. The cloud only handles account, billing, and AI routing.
Data Controller and Legal Bases for Processing
Polina Ostapenko, Sole Proprietor, registered and operating under the laws of Ukraine, acts as the Data Controller for the personal data collected through the Service. We process your personal data under the following legal bases:
- Performance of a Contract: To provide cloud functionality, manage accounts, and process subscriptions (Art. 6(1)(b) GDPR / Art. 11 of the Law of Ukraine "On Personal Data Protection").
- Legitimate Interest: To validate licenses, prevent fraud, record compliance consent, and secure the Service (Art. 6(1)(f) GDPR).
- Legal Obligation: To comply with mandatory tax, accounting, and corporate reporting regulations in Ukraine and payment processor jurisdictions (Art. 6(1)(c) GDPR).
What we collect
- Account: email and a hashed password (cloud sign-in only).
- Billing: via Stripe; we store plan, seat count, and Stripe ids — never full card details.
- AI usage metering: per-request token counts, model, cost for cloud-gateway calls (quotas + billing).
- Operational logs: minimal request/error logs; never tokens, secrets, or prompt/code content.
What we do NOT collect
- Your source code, repos, files, or local board data — they never leave your machine.
- Anything if you use Morning locally without signing in (BYO keys = no cloud contact).
AI requests
Cloud AI forwards your prompt to a third-party model provider (e.g. via OpenRouter), returns the response, and meters the call — we do not retain its content. BYO-key requests never touch our servers.
Cookies
The cloud uses one httpOnly session cookie for sign-in. The marketing site sets no tracking cookies.
Third parties
- Paddle (merchant of record; Stripe where offered) — payments.
- AI model provider(s) — inference.
- Hosting/CDN — Cloudflare, Hetzner (app), Neon (database).
International Data Transfers
As a Sole Proprietor based in Ukraine utilizing hosting infrastructure located within the European Union (Hetzner) and cloud-managed databases (Neon), your data will be transferred across national borders. We ensure that all cross-border data transfers comply with applicable data protection laws. Where personal data is transferred outside the European Economic Area (EEA) or Ukraine to jurisdictions not deemed to provide an adequate level of data protection, we utilize Standard Contractual Clauses (SCCs) or verify that recipients maintain appropriate technical and organizational safeguards.
Acceptance records
When you accept our Terms of Service (at account creation) or the desktop EULA (in the application), we keep a record of that acceptance — your email address, the document and version accepted, the time, and connection metadata (IP address and browser user-agent). We keep these records to be able to prove the agreement existed (our legitimate interest in contract enforcement); they are retained even if the account is later deleted, and are not used for any other purpose.
Retention & your rights
We keep account + usage records while active and as required for tax/accounting.
Data Retention Period
Account validation records and metadata connected to financial transactions through Paddle/Stripe will be securely retained for a minimum period of 36 months (3 years) following the end of the applicable fiscal year. This retention is strictly maintained to satisfy mandatory legal, accounting, and tax performance obligations under the Tax Code of Ukraine.
Your Data Protection Rights
Under applicable data protection laws, including the Law of Ukraine "On Personal Data Protection" and the General Data Protection Regulation (GDPR), you have the following rights:
- The right to access, update, or request the deletion of your personal data;
- The right to rectify inaccurate, incomplete, or outdated information;
- The right to object to or restrict our processing of your data under specific conditions;
- The right to data portability (requesting a copy of your structured dataset);
- The right to withdraw your consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal.
To exercise any of these rights, you may submit a request to support@morningdev.ai. Deleting your account terminates cloud processing immediately, while your local application data remains exclusively yours. Furthermore, you maintain the right to lodge an official complaint with a supervising authority. In Ukraine, you may contact the Ukrainian Parliament Commissioner for Human Rights (Ombudsman).
Security Measures
We implement reasonable administrative, technical, and organizational measures designed to protect information processed by us against unauthorized access, loss, or alteration. However, no method of electronic transmission, storage, or processing can be guaranteed to be completely secure, and we cannot guarantee absolute security.
Contact
support@morningdev.ai · Polina Ostapenko, sole proprietor, Ukraine.