Morn Support
Morn is an iPhone app that reads the mailbox you connect, on the phone, finds the companies that hold your personal data, writes the data-protection letter each one is owed under the GDPR, sends it from your own address and reads the reply. It is made by one developer in Warsaw and has no server behind it. Everything on this page is also true inside the app.
1. What Morn is
You connect a mailbox. Morn lists every sender, decides which are companies that hold your data, and shows you the list before anything is judged. You mark the ones you still use as Kept, and Morn never writes to them. For the rest, Morn drafts the right letter, an access request under Article 15 or an erasure request under Article 17, names the regulator you would complain to, and sends it from your own account when you press send. Then it waits the month the law gives the company, reads the reply when it arrives, and files the case under the right status. Silence, a refusal, an identity check and a confirmed deletion each land somewhere different.
The Brokers tab lists the credit bureaus, people-search sites and contact sellers active in your country, each with a dossier: what they hold, where they got it, what they will ask you to prove, and how they have behaved before. The Vault holds the details a company may ask for before it answers, behind Face ID, and blacks out the parts of an ID scan the request did not ask for.
2. Connecting a mailbox
Morn connects to Gmail by signing in with Google, and to every other provider over IMAP, the standard mail protocol, using an app password. That is a separate password your provider generates for one app, and it is not your account password. Nearly every provider requires two-factor authentication to be switched on first. The app password goes into your iPhone's Keychain and to your mail server, and nowhere else.
- Gmail — Sign in with Google. No password is given to Morn. Morn asks Google only for permission to read your mail and to send from your address, never to delete, move, label or archive anything, so it cannot. Revoke it at any time at myaccount.google.com/permissions.
- iCloud — This is not your Apple Account password — it is a separate app-specific one, generated for Morn alone and revocable at any time. Create the app password.
- Outlook — Microsoft stopped accepting app passwords for Outlook.com, Hotmail and Live in September 2024 and now requires a Microsoft sign-in that Morn does not offer yet. Morn cannot connect this mailbox for now. Any other mailbox you have works as usual.
- Yahoo — This is not your Yahoo password — generate a separate one under Account Security. Create the app password.
- Fastmail — Generate one with Mail access. It is separate from your Fastmail password and revocable at any time. Create the app password.
- GMX — IMAP has to be enabled in GMX settings before it works.
- web.de — IMAP has to be enabled in web.de settings before it works.
- Zoho — Zoho needs an application-specific password.
- Wirtualna Polska
- o2
- Interia
- Onet
- Orange
- Free
- Libero
- Seznam
- Yandex — Yandex needs an app password.
- Proton Mail — Morn can read this mailbox but not send from it, so it finds the companies and you send the letters yourself. Proton only speaks IMAP through Proton Bridge, which runs on a desktop and is not available on iPhone.
If your provider is not in the list, Morn will try the usual server names for your domain. If it cannot find them, the app asks for the incoming and outgoing server addresses, which your provider's help pages list under "IMAP settings".
3. What Morn does not do
- It does not reach public registers, a credit bureau's own files, tracking inside apps, or copies of your data a company has already sold on. It closes the pathway at its origin, the companies that have your address.
- It does not remove you from a broker's database itself. It writes the letter the law entitles you to, sends it from you, and reads what comes back. Whether the company complies is up to the company, and Morn tells you plainly when a broker is known to refuse.
- It does not send anything automatically. Every letter goes out when you press send, after you have seen the recipient and the full text.
- It does not delete, move, label or archive your mail. With Gmail it holds no permission that could, and with every other provider it opens folders for reading only.
- It does not file a complaint with your regulator for you. It prepares the file, the letters, the dates, the reply or the silence, and opens the regulator's own complaint page. You file.
- It does not read your mail on any server, use any model, or collect any analytics. There is nothing to opt out of because nothing is collected.
- It does not work on Android, the web, or a Mac.
4. Your data
Everything Morn knows lives in one database file on your iPhone, protected by the same encryption as your Mail and Messages. Mail passwords live in the Keychain, on this device only. Vault details and document scans are stored with the strongest file protection iOS offers and are left out of iCloud backup.
Removing a mailbox in Mailboxes deletes its account record, its cases, its cached message text and its password. Deleting the app deletes everything. There is no account to close because there is no account.
The full text is in the privacy policy, including the complete list of every network connection the app makes.
5. The free version and Morn Guard
The free version scans every mailbox message, sorts on-device, reads every reply, keeps every deadline, re-scans on its own and unsubscribes without limit. It takes five companies and two brokers from letter to done, from one mailbox. Morn Guard takes every company and every broker, in one press, from every mailbox, for €29.99 a year with a first year at €14.99. Morn Lifetime is €69 once and can be shared with your family.
Purchases are made through Apple. Restore purchases is in Settings under Plan and on the plan screen. A promo code is redeemed through Apple's own redemption page, reached from Settings, and unlocks Lifetime. Refunds are handled by Apple at reportaproblem.apple.com.
6. When something goes wrong
- "Sign-in refused" when connecting. Almost always the account password was entered instead of an app password, or two-factor authentication is not on yet. Generate a fresh app password and paste it whole.
- A scan stops or a mailbox shows "reconnect". Providers sometimes revoke app passwords after a security event. Generate a new one and reconnect in Mailboxes. Your cases and letters are kept.
- A company's reply landed under the wrong status. Open the case, read the reply Morn read, and set the status yourself. Morn only marks a case done on a confirmed deletion, never on boilerplate, so a wrong call is usually too cautious rather than too generous.
- The app crashed. Morn records crashes on the device only, through Apple's MetricKit. Nothing is sent anywhere. If you write to us about a crash, we will tell you how to attach that record.
7. Contact
Support: support@mornapp.com. Privacy questions: privacy@mornapp.com. One person reads both, so please allow a few days. Include your provider and the screen you were on. Never include an app password in an email.
Morn is published by Dumitru Hodan, a sole proprietor, ul. Chmielna 73B/14, 00-801 Warszawa, Poland.