Morn Privacy Policy
Effective date: 9 September 2026
Applies to: the Morn app for iOS (bundle com.morn.app, including the Morn widget) and the website mornapp.com.
Morn is published by Dumitru Hodan, a sole proprietor established at ul. Chmielna 73B/14, 00-801 Warszawa, Poland ("we", "us", "the developer"). Privacy questions: privacy@mornapp.com. All other questions: support@mornapp.com.
Who we are
| App name | Morn |
| Developer / operating name | Dumitru Hodan (sole proprietor) |
| Legal address | ul. Chmielna 73B/14, 00-801 Warszawa, Poland |
| General and support contact | support@mornapp.com |
| Privacy contact | privacy@mornapp.com |
The developer named above is the data controller for the limited processing described in sections 2, 9 and 10, including visits to the website mornapp.com. There is no separate legal entity behind Morn.
1. The short version
- Morn reads your own mailbox on your device to find the companies that hold your personal data, drafts data-protection requests, sends them from your own mail account, and tracks the replies.
- We operate no servers and hold no user accounts. Your mail, your scan results, your letters and your identity details never reach us. We cannot read them, and we do not want to.
- Morn contains no analytics, advertising, tracking or crash-reporting software of any kind.
- The only things that leave your device are (a) the requests you confirm, sent through your mail provider, (b) the ordinary traffic needed to talk to your mail provider — for Gmail, HTTPS requests to Google's Gmail API, and for every other provider IMAP over implicit TLS on port 993 and SMTP over implicit TLS on port 465 — encrypted from the first byte, never in clear text, never STARTTLS — and (c) a small number of narrowly scoped web requests described in section 5, every one of which is listed there.
- Everything Morn stores lives inside the app's own container and your device's Keychain. Deleting the app deletes all of it.
The rest of this policy exists because Google, Apple and data-protection law require a full account, and because you deserve one. We have written it to be checked against the app itself.
2. Who is responsible for what
Processing that happens on your device. When Morn scans your mailbox, classifies senders, drafts letters and reads replies, that processing is performed by software running on your device, under your control, for your own personal purposes. No copy of that data is transmitted to us. Under the GDPR, the developer is not a controller or processor of data it never receives; you remain in sole possession of it.
Processing we do perform. We process personal data only when you contact us (section 9), when you visit the website mornapp.com (section 9), and, indirectly, through Apple's App Store when you purchase a subscription (section 8). For those limited purposes, the developer named above is the data controller.
Third parties you authorise. Your mail provider, Google (if you connect Gmail), Apple, and each company you send a request to are independent controllers of the data they receive. Their own privacy policies apply to them.
3. What Morn processes on your device
Morn processes the following categories of data. None of it is transmitted to the developer.
Morn has no backend. There is no Morn server, no cloud service, no distributed infrastructure and no external server of any kind that receives, stores, relays or processes your data. The developer has no database of users, no copy of anyone's mailbox and no way to obtain one. Morn never pulls your data from your device to any off-site service, and never sends it to any server or service for sale, distribution, analysis, aggregation or any other purpose. Every category listed below lives only on your device, in the app's own container and your device's Keychain, and leaves it only through the actions you take yourself, described in section 5.
This is a permanent design commitment, not a current setting. Morn is built so that the safety of your personal information does not depend on trusting the developer, a server or a promise: it depends on the fact that nothing exists to receive it. We will not change this architecture. A future version of Morn will not introduce a backend, an account, remote storage or any transfer of your data to the developer or to third parties for sale or distribution.
3.1 Personal data, in the categories reviewers ask about
- Personal data processed (on your device only; nothing here is collected in the App Store sense of being sent off the device): your name (typed by you into Morn, used to sign the requests), your email address (for Gmail, the address Google confirms at sign-in; for other providers, the address you type), and the mailbox data below. Morn does not request a profile picture or basic-profile scope from Google; the only authentication data it receives is your email address. All of this stays on your device.
- Analytics and usage data: Morn contains no analytics SDK, no usage logging and no crash reporter of its own, so it collects no device information, OS version, usage logs or crash reports. If you have turned on Share with App Developers in iOS Settings › Privacy & Security › Analytics & Improvements, Apple may share crash reports and aggregated usage statistics (device model, OS version, launch counts) with us through App Store Connect. Apple anonymises those reports before we see them; they contain no mail content, no addresses and nothing that identifies you, and we use them only to monitor app performance and fix crashes.
- Purpose of processing: authenticating access to the mailboxes you connect, delivering Morn's core functions (finding companies, drafting and sending requests, reading replies), providing customer support when you write to us, and monitoring app performance through the Apple reports described above.
3.2 The full inventory
| Category | What it contains | Why Morn needs it |
|---|---|---|
| Mailbox data | Message headers (sender, recipient, date, subject, List-Unsubscribe and authentication headers) of every inbound message in the mailboxes you connect, and message bodies according to the scan depth you choose in Settings: headers only, bodies for the senders the headers cannot explain (the default), or bodies for every sender. Morn reads the headers of every inbound message so nothing is missed. | To identify which companies hold your personal data, what kind of relationship you have with them, and to recognise their replies to your requests. |
| Derived footprint | The list of companies found, the evidence for each (dates, message subjects, extracted message text), classification results, confidence and reasoning, and the privacy contact address found for each company. | The core product: the board of companies and cases. |
| Letters and case history | Every request Morn drafts or sends, the date it was sent, the statutory deadline, the reply status, and notes you add. Letters sent from a Gmail mailbox also appear in your Gmail Sent folder. Letters sent through Morn's own SMTP connection are not copied to your mailbox's Sent folder, so for those this record is the only copy. | To track each case to completion and to compute deadlines and follow-ups. |
| Requester details | Your name, country and (for US users) state. | Every GDPR request must identify the person making it. |
| Identity Vault (optional) | Values you choose to enter: full name, birth name, date of birth, current and previous address, national identification number (where a country routinely uses one), and any custom field a company asked for. | So you can answer a company's identity check without retyping the same details in every case. You choose whether to fill any of it in. |
| Identity documents (optional) | Scans or imported images/PDFs of a passport, ID card, proof of address or other document, with any redactions you apply. Scanning uses the camera, only while you are scanning and only with your permission. The captured image is stored as the document and nowhere else. | So you can attach a document to a reply when a company lawfully requires one. Attaching is always a separate, deliberate action confirmed with Face ID, Touch ID or your device passcode. |
| Mail credentials | For Gmail: OAuth refresh tokens. For other providers: the app-specific password you enter, and the server settings. | For Gmail, to read your mailbox and send letters through the Gmail API over HTTPS. For other providers, to open your mailbox over IMAP (implicit TLS, port 993) and to send letters over SMTP (implicit TLS, port 465). |
| Preferences and state | Scan depth, notification preferences, which onboarding steps are complete, the on/off state of optional features, and similar settings. | To make the app behave the way you configured it. |
| Purchase status | Whether a Morn Guard subscription or Lifetime purchase is active, verified with Apple's StoreKit on the device. | To unlock paid features. No receipt data leaves the device. |
| Imported mail archives (optional) | An .mbox file you import through the system file picker, a file reference (bookmark) so Morn can reopen it on later launches, and its modification date. | To scan mail without connecting a live mailbox. |
4. Google user data (Gmail)
This section is written to satisfy the Google API Services User Data Policy and applies only if you connect a Gmail or Google Workspace mailbox.
4.1 What Morn asks for
Morn signs you in with Google using the system browser (never an embedded web view), the OAuth 2.0 Authorization Code flow with PKCE, and no client secret. It requests three scopes, each for one purpose:
https://www.googleapis.com/auth/gmail.readonly— read-only access to your mailbox. Morn reads your mail on your device to find the companies that hold your personal data, and later reads the replies those companies send to judge whether your data was actually deleted. This scope cannot change anything in your mailbox.https://www.googleapis.com/auth/gmail.send— permission to send mail from your own address. Morn uses it to send the data-protection requests you individually confirm, so replies come back to you. This scope cannot read, alter or delete mail.https://www.googleapis.com/auth/userinfo.email— your email address, so the mailbox is labelled under the address Google confirms and your requests are sent from the correct account. No profile fields and no profile picture.
Morn requests no other Google scope. In particular it does not request https://mail.google.com/, the scope that would grant full control of a mailbox, and it does not request any scope that can delete, modify, label, archive or draft mail.
4.2 What Morn does with the access
Morn talks to Gmail over HTTPS to the Gmail API (gmail.googleapis.com), authenticated with the OAuth token Google issued for the scopes above. It opens no IMAP or SMTP session to Google. Morn uses Gmail access for exactly two user-facing purposes:
- Reading your mailbox, on your device, to identify the companies that hold your personal data and to recognise their replies to requests you sent.
- Sending the data-protection requests you individually review and confirm, from your own Gmail address, so replies come back to you.
What Morn cannot do in your Google account. Morn cannot delete, move, label, archive, modify or draft any message, because it never asks Google for the permission to do so. Google enforces the scopes on its side, so nothing in the app could delete or alter your mail without first asking you for a new permission on Google's consent screen. The only change Morn ever makes to your Google account is the one you confirm: a request you approved, sent from your address, which then appears in your Gmail Sent folder. Nothing else in the account changes.
For every other provider, which Morn reaches over IMAP, the same limit holds in a different way. The IMAP implementation contains no STORE, APPEND, COPY or EXPUNGE commands, folders are opened for reading only, and the only write is submitting the messages you approve, via SMTP. Those letters are not copied to your Sent folder, so the case record in Morn is the only copy.
4.3 Where Google data goes, and where it does not
- Your refresh token is stored in your device's Keychain. Access tokens are held only in memory while the app runs.
- Message content is processed on your device. Subjects and the extracted text of messages that matter to a case are cached in Morn's local database (section 6). Nothing is uploaded to any server operated by or for the developer.
- Analysis of messages is done by Morn's built-in rules, on your device.
4.4 Google Limited Use disclosure
Google API Disclosure:
"Morn's use and transfer to any other app of information received from Google APIs will adhere to Google API Services User Data Policy, including the Limited Use requirements."
Specifically, in accordance with the Limited Use requirements, Morn:
- only uses Google user data to provide or improve the user-facing features described in section 4.2 (identifying the companies that hold your data, recognising their replies, and sending the requests you confirm), and for no other purpose;
- does not transfer Google user data to anyone, except (a) to your own mail provider, Google, in the course of reading your mailbox and sending the messages you confirmed, (b) to the specific company you address in a request you have individually confirmed, which receives only that request, (c) as necessary to comply with applicable law, or (d) as part of a merger, acquisition or sale of assets, in which case you will be given prior notice of any change in the treatment of your data. Morn has no servers, so no transfer to the developer or to any other party takes place;
- does not sell Google user data, and does not transfer it to data brokers or information resellers, ever;
- does not use or transfer Google user data for serving advertisements, including retargeting, personalised or interest-based advertising;
- does not use Google user data to develop, improve or train any generalised or non-personalised artificial-intelligence or machine-learning model, and does not transfer it to any third party for that purpose;
- does not allow any human to read your email content or any other Google user data. The developer has no technical means to do so, because the data never leaves your device. The only circumstances in which the Limited Use policy would permit human access — your explicit prior consent for a specific message, security purposes such as investigating abuse, compliance with applicable law, or internal operations on aggregated and anonymised data — do not arise in Morn, and no such access exists.
- does not use Google user data to determine creditworthiness or for lending purposes.
4.5 Summary for the Google API Services User Data Policy
- Data access. For authentication, Morn accesses only your email address (the
userinfo.emailscope) — no basic-profile fields and no profile picture. For its core function it reads your mailbox through thehttps://www.googleapis.com/auth/gmail.readonlyscope and sends the requests you confirm through thehttps://www.googleapis.com/auth/gmail.sendscope, exactly as described in sections 4.1 and 4.2, and processes your mail on your device only. It holds no scope that could delete, modify, label, archive or draft mail. - Limited Use. Morn's use and transfer to any other app of information received from Google APIs will adhere to Google API Services User Data Policy, including the Limited Use requirements. Section 4.4 states each requirement and how Morn meets it.
- Data retention. Google account data — your address and the refresh token — is retained on your device for as long as the Gmail mailbox remains connected in Morn. Removing the mailbox in Settings deletes your address, its cached message text and its cases from Morn's database (the list of company names Morn learned remains, without any mail data, until you delete the app); revoking access at myaccount.google.com/permissions invalidates the token; deleting the app removes the token from your device. Nothing is retained by the developer, because nothing reaches the developer.
- Data sharing and sale. Morn never sells personal data to third parties, and shares Google user data with no one except the parties listed in section 5. Morn uses no sub-processors for your data: there is no cloud database, no server and no service provider that receives, stores or processes mail, Google user data or anything else from the app on our behalf. (The website mornapp.com is served by a hosting provider, described in section 9, which never receives anything from the app.)
- AI and machine-learning models. Google Workspace API data is not used to develop, improve or train non-personalised AI or machine-learning models, by Morn or by anyone Morn transfers it to.
4.6 Revoking access
You can revoke Morn's access at any time at myaccount.google.com/permissions. Revoking there invalidates the token Morn holds immediately. Removing the mailbox inside Morn deletes the mailbox and its cases from Morn's database; deleting the app removes the stored token from your device as well. We recommend doing both when you stop using a mailbox.
4.7 Mailboxes connected by pre-release versions
Pre-release versions of Morn reached Gmail over IMAP and SMTP under the broader https://mail.google.com/ scope. No version of Morn requests that scope any more. A mailbox connected by such a version keeps opening over that path, with the grant you gave then, until you connect the same address with Google sign-in again, which moves it to the Gmail API and the three scopes above. To withdraw the earlier, broader grant, revoke Morn at myaccount.google.com/permissions and sign in again.
5. Every network connection Morn makes
This is a complete list. Morn opens no other connections.
| # | Destination | When | What is transmitted | What is never transmitted |
|---|---|---|---|---|
| 1 | Google (accounts.google.com, oauth2.googleapis.com, www.googleapis.com) | Only if you connect Gmail: at sign-in and on token refresh | Client ID, requested scopes, PKCE challenge, the authorization code, your refresh token, and the access token (sent to Google's tokeninfo and userinfo endpoints to confirm the granted scopes and read your address). Google returns tokens and your email address | Mail content |
| 2 | Your mail provider — for Gmail, the Gmail API over HTTPS (gmail.googleapis.com). For every other provider, IMAP on port 993 and SMTP on port 465, implicit TLS only, for example imap.mail.me.com, outlook.office365.com, or the server you enter | During scans and when you send a letter | Your credential (OAuth token or app password), the requests that list and fetch your messages, and, on send, the full text of the letter you confirmed plus any document you chose to attach | Anything to anyone other than your own provider |
| 3 | The companies you write to | Only when you confirm a send, through Morn's own connection to your provider or through your provider's web compose page or your mail app (section 8) | The letter: your name, the email address the company knows you by, the legal citation, and anything you added, plus any Vault document you deliberately attached | Your other companies, your scan results, your credentials |
| 4 | Websites of companies found in your mailbox (the site's front page, /privacy, /privacy.html, /datenschutz, /impressum, /contact, /.well-known/security.txt, /security.txt, /robots.txt and /sitemap.xml, and pages those link to on the same site) | Automatically, at the end of a scan, for companies whose privacy contact is not already in Morn's bundled directory | An ordinary web page request (your IP address, the page path, and the User-Agent Morn/1.0 (+https://mornapp.com/privacy), which identifies Morn to the site). Cookies are disabled, nothing is cached, standard redirects are followed to the page's final location, and there is no crawling. If a policy page is built with JavaScript, Morn may render it off-screen with every request to any domain other than that company's own blocked. | Your email address, your name, any mail content. The company learns only that a Morn user requested its privacy page. |
| 5 | Public DNS (via your device's system resolver) | During the same discovery step | MX, TXT and DMARC record lookups for the sending domains found in your mailbox | Anything else |
| 6 | A sender's one-click unsubscribe endpoint | Only when you tap Unsubscribe on a sender that advertises RFC 8058 one-click unsubscribe over HTTPS | A single POST with the body List-Unsubscribe=One-Click to the URL the sender put in its own email header. That URL usually contains a token identifying your subscription. No redirect is followed and no page opens. | Anything else |
| 7 | Apple (App Store / StoreKit) | When you view plans, purchase, redeem a code or restore purchases | Handled by Apple's StoreKit on the device under Apple's privacy policy | Anything from Morn's database |
Mail protocols. For Gmail, Morn uses the Gmail API over HTTPS and nothing else. For every other provider, Morn reads mail with IMAP over implicit TLS on port 993 and sends with SMTP over implicit TLS on port 465 — encrypted from the first byte, never in clear text, never STARTTLS. Morn deliberately implements no STARTTLS and no unencrypted port (587, 143, 25): a provider that offers only those is reported as unsupported rather than connected insecurely. Web requests use HTTPS only.
Every connection uses TLS with the operating system's certificate validation. Morn has no App Transport Security exceptions and no cleartext or STARTTLS code path.
For (4) and (5): these requests are how Morn finds a company's published privacy contact instead of guessing one. They go only to domains that already sent you mail. Contact discovery runs as the final phase of a scan, including background scans; off-screen page rendering is used only for scans you started in the foreground.
6. Storage and security on your device
| Data | Where | Protection |
|---|---|---|
| Footprint, case history, letters, cached subjects and extracted message text, scan snapshots | One SQLite database in the app's Application Support directory | iOS Data Protection (completeUnlessOpen). Included in iCloud and encrypted local device backups, because your case history is your legal record. |
| Mail credentials (OAuth refresh tokens, app passwords) | Device Keychain, service com.morn.credentials | Keychain encryption; accessible after first unlock so scheduled background scans can run. Keychain items are included in encrypted device backups. |
| Identity Vault field values and the document index | Device Keychain, separate service | WhenUnlockedThisDeviceOnly: never synced to iCloud Keychain and never restored to another device. |
| Identity documents | Encrypted files named by random UUID in the app container | Complete file protection, excluded from all backups, gated by Face ID, Touch ID or your device passcode before display or attachment. |
| Requester name, country, state and preferences | App preferences (UserDefaults) | App-container protection; included in backups. |
| Widget data | A file in the app group group.com.morn.app | Contains counts only (companies guarded, open, done, kept, overdue, new this month, mailboxes connected, last sweep time). No names, addresses or mail content. |
Morn writes no logs containing mail content or credentials, and ships with no crash reporter. Scan snapshots older than 60 days are deleted automatically.
7. Retention and deletion
- Mailbox data and footprint are kept until you remove the mailbox or delete the app. Removing a mailbox deletes its account record, its cached message text, its classifications, its scan history and its cases from Morn's database. The list of company names and their privacy contacts, which is not tied to any one mailbox and contains no mail data, remains until you delete the app. Its stored credential is removed when you delete the app; for Gmail, revoking access at myaccount.google.com/permissions invalidates the token immediately.
- Identity Vault values and documents are kept until you delete them individually in the Vault screen or delete the app.
- Letters and case history are kept until you remove the mailbox they belong to or delete the app.
- Deleting the app removes the database, preferences, documents and Keychain items. Data in an iCloud or local backup you made earlier persists in that backup under Apple's terms until the backup is replaced.
- Google access can be revoked independently at myaccount.google.com/permissions, which invalidates the stored token immediately.
- Support correspondence (section 9) is kept for as long as needed to resolve your request and then deleted, at most 24 months.
Deletion process. Morn has no user account, so there is no account to delete. To delete your data: remove a mailbox in Settings (its cases and cached text go with it), revoke Gmail access at myaccount.google.com/permissions, delete Vault entries and documents in Settings › Your details, or delete the app to remove everything including stored credentials. You can also email privacy@mornapp.com at any time: we will delete anything we hold about you (support correspondence), confirm in writing, and walk you through removing on-device data if you need help.
Because the developer holds no copy of your mail, footprint, letters or identity data, there is nothing for us to delete on your behalf; deletion of that data is entirely in your hands and takes effect immediately.
8. Apple, purchases and notifications
- Purchases (Morn Guard subscription, Lifetime, and offer codes) are processed by Apple through the App Store. Apple sends us aggregated sales reports; we never see your name, payment details or Apple ID. Apple's privacy policy governs that transaction.
- Notifications are local. Morn posts them from the device when a rescan finds something new or a reply arrives, and at most one monthly summary. No push server is involved, so nothing is sent to Apple's notification service. You can hide company names from notification text in Settings.
- Background refresh runs scheduled rescans using the system's Background Tasks framework. It talks only to your mail provider and, for contact discovery, to the destinations in section 5.
- Optional sharing: the "Footprint receipt" image is created only when you tap it and goes only where you choose to send it via the system share sheet. It contains counts for the year and no company names, addresses or mail content. On the broker screen you can also copy a letter to the clipboard (kept on this device only and cleared after five minutes) or hand it to the share sheet.
- Sending through your mail app or webmail: when Morn cannot send a letter itself (for example from an imported archive, or a mailbox with no outgoing server), it opens your provider's web compose page or your mail app with the recipient, subject and letter prefilled, and then asks whether you sent it. The letter travels to your own provider through that page or app instead of through Morn's own connection to your provider. Nothing is sent until you press send there.
9. When you contact us
If you email support@mornapp.com or privacy@mornapp.com, we receive your email address, whatever you write, and any attachment you include (such as a screenshot). We use it only to answer you. Legal basis: our legitimate interest in supporting the app and, where you ask us to, performance of a contract. We do not add you to any mailing list; Morn has none.
The website. mornapp.com is a static site served by Firebase Hosting, a service of Google LLC. Like any web host, it records standard access logs for each request (your IP address, the page requested, the time, and your browser's user-agent string) for security and traffic monitoring, under Google's own retention rules. The site sets no cookies, loads no third-party scripts, fonts or images, and contains no analytics. The app never connects to the website. Legal basis: our legitimate interest in serving the site securely.
10. Your rights
You can request access to your data, an export of it, or deletion of your data at any time, free of charge, by writing to privacy@mornapp.com.
For the data Morn processes on your device, you already have every right in full: you can read, correct, export (via the share sheet and system backups) and delete it directly, without asking anyone.
For data we hold about you (support correspondence), you have the rights the GDPR and UK GDPR give you: access, rectification, erasure, restriction, portability, objection, and the right to lodge a complaint with a supervisory authority, in particular in the EU or UK country where you live. Write to privacy@mornapp.com; we answer within one month.
California residents. Morn does not sell or share personal information and collects none through the app. The CCPA rights of access and deletion apply to support correspondence only.
11. Children
Morn is a tool for exercising your own data-protection rights and is not directed at children. You must be at least 16 years old, or older if the age of digital consent where you live is higher, to use Morn — see section 1 of the Terms of Service. We do not knowingly collect any data from anyone below that age. If you believe a child has contacted us, write to privacy@mornapp.com and we will delete the correspondence.
12. International transfers
The developer transfers no app data across borders because the developer receives none. Website access logs (section 9) are held by Firebase Hosting, which may store them outside your country under Google's standard contractual safeguards. Your mail provider, Google, Apple and the companies you contact may process data in other countries under their own safeguards.
13. Changes to this policy
When this policy changes, the effective date above changes with it, and material changes are announced in the app's release notes and on mornapp.com before they take effect. Earlier versions are available on request.
14. Contact
Privacy: privacy@mornapp.com
Support and security reports: support@mornapp.com (put "security" in the subject; you will get a human answer)
Postal: Dumitru Hodan, ul. Chmielna 73B/14, 00-801 Warszawa, Poland