Privacy Policy
Effective date: [DATE]
The guiding principle: your code and project data stay on your machine. The cloud only handles account, billing, and AI routing.
What we collect
- Account: email and a hashed password (cloud sign-in only).
- Billing: via Stripe; we store plan, seat count, and Stripe ids — never full card details.
- AI usage metering: per-request token counts, model, cost for cloud-gateway calls (quotas + billing).
- Operational logs: minimal request/error logs; never tokens, secrets, or prompt/code content.
What we do NOT collect
- Your source code, repos, files, or local board data — they never leave your machine.
- Anything if you use Morning locally without signing in (BYO keys = no cloud contact).
AI requests
Cloud AI forwards your prompt to a third-party model provider (e.g. via OpenRouter), returns the response, and meters the call — we do not retain its content. BYO-key requests never touch our servers.
Cookies
The cloud uses one httpOnly session cookie for sign-in. The marketing site sets no tracking cookies.
Third parties
- Paddle (merchant of record; Stripe where offered) — payments.
- AI model provider(s) — inference.
- Hosting/CDN — Cloudflare, Hetzner (app), Neon (database).
Acceptance records
When you accept our Terms of Service (at account creation) or the desktop EULA (in the application), we keep a record of that acceptance — your email address, the document and version accepted, the time, and connection metadata (IP address and browser user-agent). We keep these records to be able to prove the agreement existed (our legitimate interest in contract enforcement); they are retained even if the account is later deleted, and are not used for any other purpose.
Retention & your rights
We keep account + usage records while active and as required for tax/accounting. Request access or deletion at [contact email]. Deleting your account stops cloud processing; local data is yours.
Contact
support@morningdev.ai · Dmytro Sakhno, sole proprietor, Ukraine.