Skip to content
Morrowhelm
PrivacyTermsSupport
LAST UPDATED: 25 AUGUST 2026

Privacy Policy

Morrowhelm is a local-first planning service. We do collect and process limited personal data when you create an account, sync a workspace, use an optional AI feature, subscribe, contact support or connect to our web services. This policy explains what happens across the mobile app, web app and related services.

Draft — do not publish: legal identity or product/operational evidence is incomplete. The production check blocks release until these fields are supplied: NEXT_PUBLIC_LEGAL_NAME, NEXT_PUBLIC_LEGAL_ADDRESS, NEXT_PUBLIC_LEGAL_COUNTRY, NEXT_PUBLIC_PRIVACY_EMAIL veya NEXT_PUBLIC_SUPPORT_EMAIL, LEGAL_TERMS_VERSION, LEGAL_TERMS_SHA256_TR, LEGAL_TERMS_SHA256_EN, LEGAL_AI_PERMISSION_READY, LEGAL_AI_SAFETY_READY, LEGAL_REGIONAL_SUBSCRIPTION_READY, LEGAL_VENDOR_PRIVACY_VERIFIED, LEGAL_SENSITIVE_DATA_CONTROLS_READY, LEGAL_RETENTION_DELETION_READY, LEGAL_TERMS_ACCEPTANCE_READY, PUBLIC_RELEASE_ENABLED.

Türkçe Gizlilik Politikası · Türkiye KVKK Notice · Terms of Use

  • Your workspace starts on your device. After you sign in and link the phone data to your account, cloud sync runs automatically.
  • AI is optional. Only the relevant planning context for an action you start is sent after a separate transfer permission.
  • The current version has no advertising network, product-analytics SDK, session replay or third-party crash-reporting SDK.
  • Your workspace is not public; the current version has no file, photo, audio, location, contacts or calendar access.

1. Who is responsible for your data?

[YASAL İŞLETME UNVANI / LEGAL BUSINESS NAME] is the controller of Morrowhelm account and service data.
[TEBLİGAT VE İŞLETME ADRESİ / POSTAL AND BUSINESS ADDRESS]
[ÜLKE / COUNTRY]
Privacy contact: [GİZLİLİK E-POSTASI / PRIVACY EMAIL]

2. Data we collect, sources and purposes

CategorySourceWhy we use it
Email address, account/user/session identifiers and authentication/security eventsYou and our identity provider, ClerkCreate and secure your account, authenticate sessions and make your workspace available on supported devices
Areas; tasks and recurrence rules; projects, backlogs and checklists; routines; client names and quotas; receivable/payable amounts, currencies and due dates; day/week records, energy, mood and unusual-day/illness selections; free-text notes and accepted AI resultsContent you enterProvide the local workspace and, after you sign in and link it to your account, its automatically synced cloud copy
Planning context submitted to AI: a selected note; project name, goal, description, milestone and due date; or the visible/editable weekly aggregate (including task totals, up to four client names and needs, total receivables/payables and near-due counts); app language, formatting locale, time zone and local date; and the generated responseOnly an AI action you initiate and the context presented for that actionGenerate the task, checklist, project breakdown or weekly narrative you requested, after a separate product permission for the third-party AI transfer
AI mode/model, success, latency, token and character/item counts, plan and installation/user identifiers; content-free safety direction, action, reason code and match countTechnical result of an AI requestEnforce quotas, investigate faults and abuse, operate safety controls, and control service cost
AI-result report: opaque report, client-report and AI-response identifiers; account identifier; AI mode; selected category; queue status; and creation, update and expiry timestamps. It contains no raw prompt, raw response, excerpt, content fingerprint or free-form text.Your choice to report an AI result and the opaque response identifier issued by the serverQueue harmful, unsafe, privacy-related or incorrect AI results for safety review, prevent duplicate reports and manage review status
AI transfer choices and legal/transaction evidence: provider, data category, purpose, notice version and hash, allow/decline/revoke choice, surface, language, installation/account identifier and times; for web purchases, the Terms version/hash, affirmative selection of an initially unchecked box, country, offer snapshot and timeYour choices and the purchase flowApply your choice to future transfers, support withdrawal, and demonstrate the transaction and compliance record
Plan, subscription status, period end, storefront, provider customer/subscription/event identifiers and one-way account hashes used for RevenueCat ownership/transfer security; for web sales, price, amount, currency and billing countryApple, RevenueCat or StripeVerify purchases, grant Pro access and administer cancellations, refunds, disputes and required records
Support message, category, account email and case statusYouRespond to the request, troubleshoot and resolve disputes
IP address, user-agent, device/app/browser version, request, error and security logs; authentication/session cookies and language, time-zone and appearance preference cookiesYour device and our hosting/identity providersDeliver communications, keep you signed in, localise the interface, detect faults and attacks, and secure the service
Device-only records: 18+ eligibility choice and version (not date of birth), onboarding progress, language/appearance preferences, local-notification times and interactions, recovery acknowledgement, installation identifier and sync checkpointYour in-app choices and deviceApply age eligibility and preferences, schedule local reminders, support offline use and prevent sync conflicts; unless stated otherwise, these records are not sent to Morrowhelm servers

We do not receive your full card or bank account number. Apple or Stripe operates the payment interface. Free-text workspace content, energy/mood scales, exercise routines, illness selections and finance fields can reveal sensitive, health-related or financial information depending on their content and context. We do not use sensitive characteristics for advertising or unrelated profiling. If you link a workspace to your account, its entire supported workspace copy is synced; the current sync layer does not classify each free-text field by sensitivity. Only the planning context disclosed for an AI action is analysed to produce the response you requested. The consumer edition is not offered to process special-category data with AI; AI flows do not launch without controls to block or redact known sensitive patterns. Automated detection is not perfect. A flow involving special-category data does not launch in Türkiye until a separate Article 6 processing condition and additional safeguards are documented; the service contract alone is not treated as sufficient for that data.

3. Local storage and cloud sync

The mobile workspace is first stored in a SQLite database on your device and can work offline. After you sign in and link the phone workspace to your account, an account-linked copy is stored in Neon Postgres and later changes sync automatically so supported devices and the web app can access it. Synced content is not end-to-end encrypted: our servers must process it to sync, export and delete it. We use HTTPS/TLS in transit and provider access controls at rest. Workspaces belonging to different signed-in accounts are kept separate.

4. Optional AI processing and third-party transfer

In production, Morrowhelm uses Gemini models through Google Cloud Vertex AI only after you initiate an AI action. Before the relevant note, project context or visible weekly aggregate is sent to Google, the product identifies the recipient, purpose and data categories and asks for explicit product permission under Apple’s rules. Declining does not block manual planning features. You can withdraw permission for future transfers in Account/Privacy; withdrawal does not invalidate earlier lawful processing. A material change to the provider, data or purpose requires a new choice. This product permission is separate from this notice and from any legal consent or international-transfer safeguard that local law may require.

Morrowhelm’s AI usage and safety logs do not retain the raw prompt or raw model response; they retain only the limited technical measures and content-free safety events described above. Raw content passes through Morrowhelm’s API memory and Google’s service while the request is processed. A result you accept into the workspace becomes ordinary user content. Google Cloud’s Service Specific Terms state that Google will not use Customer Data to train or fine-tune an AI/ML model without prior permission or instruction. Morrowhelm gives no such permission or instruction and does not use model tuning.

Production AI requests are processed in Google’s eu multi-region. Morrowhelm has disabled Google’s default project-isolated Gemini in-memory cache for its production project and does not use Grounding with Google Search/Maps, Live API session resumption, explicit context caching, fine-tuning or optional BigQuery request-response logging. Google may, however, store a prompt detected by its automated systems as potentially abusive for up to 90 days in the selected region, solely to investigate a possible policy violation; authorised Google personnel may review it. Google states that this record is not used to train models. We therefore do not claim zero data retention. See Google’s abuse-monitoring explanation.

AI output may be inaccurate, biased, inappropriate or harmful and is not medical, legal, financial or emergency advice. Important decisions need independent verification. Safety filtering and reporting are product controls; this paragraph is not a substitute for them. You can choose a category to report an AI result and receive an on-screen acknowledgement. The report record contains only the metadata listed in Section 2; no prompt, response, excerpt, fingerprint or free-form explanation is submitted with the report.

5. Cookies, device preferences and notifications

The web app uses Clerk’s essential authentication cookies to create and protect a signed-in session. The personal_os_language, personal_os_time_zone and personal_os_theme cookies remember interface language, browser time zone and appearance for up to one year. Time zone is read automatically from the browser so dates display correctly. You can delete these cookies in browser settings; blocking essential session cookies may break signed-in features. The current version uses no advertising or analytics cookie.

Mobile reminders are scheduled locally through the device operating system. Notification permission, times, frequency and snooze/dismiss interactions stay on the device; Morrowhelm does not create or store a server push token. You can turn off notification access in device settings. The app may read dark-mode, reduced-motion, reduced-transparency and contrast state to adapt its interface, but does not send those system settings to the server.

6. Service providers and recipients

ProviderRole and main data
ClerkIdentity and authentication: email, user/session identifiers and security events
VercelWeb/API hosting: IP, request, user-agent, error and security logs
NeonCloud database: account-linked workspace and service records
Google Cloud Vertex AI (Gemini)Optional AI processing: the note/project/weekly aggregate context described in Section 2, language/time settings and technical request information; limited abuse monitoring for suspicious prompts
Apple and RevenueCatApp Store subscription, purchase verification and entitlement mapping
StripeWeb payment and subscription management: customer, payment-status and subscription records

Providers receive only data needed for the defined service. For providers acting as our processors, we require appropriate confidentiality, security, instruction, subprocessor and deletion terms. The related flow does not launch until those terms and the actual production settings have been verified. Apple and Stripe may act as independent controllers for storefront, payment, fraud, tax or other processing they determine under their own legal duties and policies. That distinction does not remove our responsibility for processing we control. We may also disclose narrowly necessary data to professional advisers, courts or authorities where law requires it or to establish, exercise or defend legal claims. We do not sell personal data, rent mailing lists, provide data to brokers, or share it for cross-context behavioural advertising.

7. International transfers

Providers may process data in Türkiye, the United Kingdom, the European Economic Area, the United States and other countries listed in their current subprocessor documentation. Where required, transfers rely on an adequacy decision, EU Standard Contractual Clauses, the UK IDTA/Addendum, a Turkish KVKK standard contract, or another lawful safeguard. For the Türkiye AI flow in which Morrowhelm is the controller and Google is the processor, the intended appropriate safeguard is Turkish KVKK Standard Contract 2 (controller to processor). Routine transfers do not begin until valid signatures are complete and the contract is notified to the Authority within five business days after signature. A copy or description of the relevant safeguard can be requested from the privacy contact, subject to lawful redactions.

8. Uploads and public access

The current version has no photo, audio, video or file-upload feature and no public storage bucket for user uploads. Free-text workspace content is not public. Any future upload feature must use private-by-default storage, account/tenant authorisation, short-lived signed access and deletion of the original and derivatives; this policy and the App Store privacy disclosure must be updated before that feature is enabled.

9. Retention, export and deletion

  • Account and synced workspace data is kept while the account is open or as needed to provide the service.
  • Account-linked AI usage and transfer-permission records are removed from active Morrowhelm systems on account deletion. Safety data is stored only as hourly aggregate counters without an account or installation identifier or raw content, kept for no more than 30 days, removed by a daily automated retention job and not used for another purpose.
  • Account-linked AI-result reports are metadata-only records kept for no more than 90 days and removed by the daily automated retention job; they are deleted from active systems earlier if the account is deleted.
  • An ordinary Google Cloud AI prompt/output is not stored outside the Customer Account longer than reasonably necessary to generate the output; Morrowhelm keeps provider caching and optional request-response logging disabled. A prompt flagged by Google’s systems may be kept for abuse monitoring for up to 90 days. Unless applicable law requires longer storage, the contractual outside limit for carrying out a deletion instruction under Google’s CDPA is 180 days.
  • Support cases are removed on account deletion; a narrowly scoped record may be kept separately if needed for a specific dispute or legal duty.
  • Payment providers may retain tax, accounting, chargeback and fraud records for their own legal obligations.
  • One-way ownership hashes that prevent a RevenueCat subscription from being transferred to the wrong account are retained indefinitely in the current implementation and are not used for another purpose.
  • Language, time-zone and appearance preference cookies last for up to one year and can be deleted earlier in the browser.
  • Deleted data in isolated backups is put beyond ordinary use until overwritten through each provider’s documented backup cycle and is not used for another purpose; current cycle information can be requested from the privacy contact.

Account settings let you export a JSON copy of server-side account, workspace, entitlement, AI usage/transfer-permission, AI-result report metadata, web-purchase evidence and support records, then delete the account without contacting support. Device-only preferences that were not sent to the server are outside this server export. Deletion removes the active Morrowhelm cloud workspace, account-linked AI usage/permission records and AI-result reports, support cases, entitlement records, Clerk account and RevenueCat customer profile. A Stripe web subscription is cancelled during deletion. Apple subscriptions are controlled by Apple and are not cancelled merely by deleting Morrowhelm; they must be managed separately in Apple settings.

To permanently prevent a late or replayed billing webhook from recreating a deleted account, a limited deletion-protection record consisting only of a one-way hash of the account identifier and deletion timestamps is retained indefinitely; it contains no raw account ID or email and is not used for another purpose. The workspace and account-linked AI transfer permission are cleared from the phone that starts deletion. The 18+ eligibility choice, appearance/language, local-notification and recovery preferences may remain as account-independent device settings until you remove the app data. A protected local copy on another offline device must be removed from that device.

10. Your rights and choices

Subject to local law and applicable exceptions, you may ask to access, copy, correct or delete personal data; restrict or object to processing; receive portable data; withdraw consent prospectively; and challenge a significant decision based solely on automated processing. Morrowhelm suggestions do not by themselves make a legal or similarly significant decision. We may verify identity proportionately to protect the account. We do not discriminate because you exercise a privacy right.

  • UK/EEA: our contract is the basis for account, workspace, requested AI and subscription functions; legitimate interests support proportionate security, abuse, fault and claim records; legal obligations support required financial records. You may complain to your local authority, including the UK ICO.
  • Türkiye: the KVKK Notice lists Article 11 rights, processing conditions and the application method. Information and any explicit consent are kept separate.
  • Canada: you may ask about access, accuracy, consent choices, retention and foreign processing and escalate an unresolved privacy complaint to the OPC or the relevant provincial authority.
  • Australia: you may request access/correction or make a privacy complaint; if unresolved, you may contact the OAIC where the Privacy Act applies.

11. California notice at collection

Depending on how you use Morrowhelm, the categories collected in the preceding 12 months are identifiers; customer-record information; commercial/subscription information; internet or electronic activity; other financial information entered into planning fields; user content and support communications; and planning inferences embodied in an AI response you request. Sources, purposes and recipients are described in Sections 2 and 6. We do not sell or share these categories for cross-context behavioural advertising and do not use sensitive data to infer characteristics. If the CCPA/CPRA applies to us, California residents may request access to categories and specific pieces, correction, deletion and portability, and may use an authorised agent. Since no sale/share occurs, there is currently no sale/share opt-out transaction to process.

We use no advertising network that tracks you across unrelated services. A browser “Do Not Track” signal therefore does not change our present practice. If a legally recognised opt-out signal such as Global Privacy Control becomes relevant to a future sale/share practice, it will be honoured and this policy will be updated before that practice begins.

12. Security and incidents

We use account separation, access controls, TLS, secret management, rate limits and auditable deletion steps appropriate to the service. No system is absolutely secure. If an incident requires notice, we will notify affected people and authorities within the periods required by applicable law.

13. Children

Morrowhelm consumer accounts are not directed to people under 18. At mobile entry, only an “I am 18 or over” or “I am under 18” choice, notice version, language and timestamps are stored on the device; date of birth is not collected. If you believe we processed a child’s data, contact us; after appropriate verification we will delete the account/data or take another step required by local law.

14. Changes and contact

We will give advance in-app or account-channel notice of a material change when appropriate. A new purpose requiring consent will not be inferred from silence. For questions or rights requests, use Support or email [GİZLİLİK E-POSTASI / PRIVACY EMAIL].

© 2026 MorrowhelmHome