← Morning

Privacy Policy

Effective date: September 15, 2026 · Version 2026-09-15

The guiding principle: your code and project data stay on your machine. The cloud only handles account, billing, and AI routing.

Data Controller and Legal Bases for Processing

Polina Ostapenko, Sole Proprietor, registered and operating under the laws of Ukraine, acts as the Data Controller for the personal data collected through the Service. We process your personal data under the following legal bases:

What we collect

What we do NOT collect

AI requests

Cloud AI forwards your prompt to a third-party model provider (e.g. via OpenRouter), returns the response, and meters the call — we do not retain its content. BYO-key requests never touch our servers.

Cookies

The cloud uses one httpOnly session cookie for sign-in. The marketing site sets no tracking cookies.

Third parties

International Data Transfers

As a Sole Proprietor based in Ukraine utilizing hosting infrastructure located within the European Union (Hetzner) and cloud-managed databases (Neon), your data will be transferred across national borders. We ensure that all cross-border data transfers comply with applicable data protection laws. Where personal data is transferred outside the European Economic Area (EEA) or Ukraine to jurisdictions not deemed to provide an adequate level of data protection, we utilize Standard Contractual Clauses (SCCs) or verify that recipients maintain appropriate technical and organizational safeguards.

Acceptance records

When you accept our Terms of Service (at account creation) or the desktop EULA (in the application), we keep a record of that acceptance — your email address, the document and version accepted, the time, and connection metadata (IP address and browser user-agent). We keep these records to be able to prove the agreement existed (our legitimate interest in contract enforcement); they are retained even if the account is later deleted, and are not used for any other purpose.

Retention & your rights

We keep account + usage records while active and as required for tax/accounting.

Data Retention Period

Account validation records and metadata connected to financial transactions through Paddle/Stripe will be securely retained for a minimum period of 36 months (3 years) following the end of the applicable fiscal year. This retention is strictly maintained to satisfy mandatory legal, accounting, and tax performance obligations under the Tax Code of Ukraine.

Your Data Protection Rights

Under applicable data protection laws, including the Law of Ukraine "On Personal Data Protection" and the General Data Protection Regulation (GDPR), you have the following rights:

To exercise any of these rights, you may submit a request to support@morningdev.ai. Deleting your account terminates cloud processing immediately, while your local application data remains exclusively yours. Furthermore, you maintain the right to lodge an official complaint with a supervising authority. In Ukraine, you may contact the Ukrainian Parliament Commissioner for Human Rights (Ombudsman).

Security Measures

We implement reasonable administrative, technical, and organizational measures designed to protect information processed by us against unauthorized access, loss, or alteration. However, no method of electronic transmission, storage, or processing can be guaranteed to be completely secure, and we cannot guarantee absolute security.

Contact

support@morningdev.ai · Polina Ostapenko, sole proprietor, Ukraine.