Morrow privacy policy

Effective 27 September 2026. Morrow is an assistant for iPhone, Android and web browsers. The seller and personal-data operator is the self-employed individual Селиванова Александра Александровна (Aleksandra Aleksandrovna Selivanova), INN 644108324497, 37 Lvova Street, Volsk, Russia. Contact: support@nevastack.com, +7 985 159-02-24. Existing invitations and memberships keep their stated access terms; paid access is governed by the public offer.

Legal grounds and processing

Data is processed to conclude and perform the service agreement, comply with applicable legal duties, and provide optional AI processing after your separate permission. We use automated collection, recording, storage, retrieval, updating, transfer to disclosed providers and deletion for the purposes below. Declining optional AI permission does not prevent access to saved content or deletion. You may request access, correction, blocking or deletion and withdraw consent through the contacts above. We review requests within applicable legal deadlines and explain any lawful retention requirement.

What we collect and why

We store your chats, selected files, generated images, saved memories, preferences, and technical records needed to deliver and recover responses. Apple and Google sign-in supply identifiers; we store their hashes to associate you with your account. Morrow never receives your provider password. Google email and profile claims and ordinary provider tokens are discarded after verification. We do not request your Apple name or email. Link another provider explicitly in account settings; email never merges accounts. The owner may assign a name or label to your invitation or membership. Approved Telegram bot users can optionally provide a recipient name, Telegram username, phone number and email for access administration. These details move from the invitation to the member record at enrollment; they are not used to verify sign-in identity or sent to AI models.

On iPhone, access credentials and pending browser sign-in proof are stored in Keychain and ordinary chats are cached on the device for continuity. Android Keystore encryption protects the backend session, pending sign-in proof, ordinary chats, drafts and pending-request recovery in app-private storage excluded from backup and device transfer. In the browser, secure HttpOnly cookies hold the session and sign-in security values; JavaScript cannot read them. The server stores hashed session tokens. Invitation, expiry, and revocation records enforce access periods. Public web registration creates an account without paid access. We record the time and version of your privacy-policy acknowledgement.

The browser keeps bounded, account-bound ordinary drafts and pending-request recovery details, including selected attachment references, in session storage within the browser tab for refresh recovery. It does not store a full chat-history cache. Display and conversation preferences are stored separately in browser local storage, along with AI-processing consent for each account and a non-secret pending-sign-out marker when needed. Temporary-chat content is excluded from the iPhone and Android durable conversation caches and browser storage; temporary chats cannot read or write persistent memory.

When you open Android media, including temporary-chat media, presentation files are app-private and excluded from backup but are not additionally encrypted with the account key. Unshared files are removed on dismissal; active or shared files have a 30-minute lifetime and are removed on account change or task disposal. Process death may leave private bytes until the next presentation-service initialization; prior-process grants cannot reopen them. Immediate physical erasure is not guaranteed. Exported copies and external file descriptors already opened by another app cannot be recalled.

AI and other service providers

After you explicitly allow AI processing, Morrow sends your messages, relevant chat history, selected files, and enabled memories to AI models hosted by Microsoft Azure, including Azure OpenAI. These services generate answers, images and edits, retrieve relevant memories, and preserve context in long chats. AI answers can be inaccurate; verify important information.

If web search is enabled, the model may send search queries to Microsoft’s search service. When Morrow reads a source, that website receives an ordinary request from our server, including the page address and server IP. On iPhone, dictation uses Apple speech recognition and may send audio to Apple; microphone and Photos access require your separate iOS permission. Android uses Photo Picker and Storage Access Framework for files you select, without broad storage permission. Dictation requests microphone permission when used; the installed Android speech service may process audio under its provider’s terms and privacy policy and is not guaranteed to work offline. Where supported in a browser, dictation uses the browser’s speech-recognition provider and may send audio to that provider under its terms and privacy policy. Browser microphone permission is requested when you use dictation.

Microsoft Azure hosts our account database and private file storage outside Russia. The account database is in Sweden Central (Sweden). Google handles Google sign-in. Apple handles Apple sign-in, App Store delivery and crash diagnostics, and TestFlight delivery and feedback for beta builds. Operational logs may contain request identifiers, technical errors, timestamps and network information. We do not sell your information, use advertising trackers, or share one member’s chats with other members. The operator can access service data for maintenance, security and support.

Microsoft, Apple and Google process data under their applicable service terms and privacy protections. Processing may take place outside your country. See Microsoft’s privacy statement and Apple’s privacy policy and Google’s privacy policy. Morrow does not use your content to train its own models.

Live voice has a separate confirmation before microphone use. During a call, microphone audio goes to Microsoft Azure for speech processing and responses. Relevant chat history and enabled memories provide context, and spoken requests can invoke the same Morrow tools as text. Morrow does not save raw call recordings. Completed speech transcripts and tool results are saved in the current chat and follow its ordinary or temporary retention rules. An interrupted answer can be marked as interrupted because exact spoken-word playback alignment is unavailable. Owner analytics contain call duration, platform, turn counts, interruptions, tool counts, token usage, estimated costs and bounded technical failures, without audio or transcript content. Muting disables microphone transmission; ending a call, leaving the chat, backgrounding the app, signing out or withdrawing AI permission stops the local call and requests server cleanup.

Your choices

You may decline AI processing and still read and delete saved content. On iPhone, withdraw permission in Settings → Data & privacy. On Android, open Account → Settings → Privacy and AI and turn off Allow AI processing. In the browser, use Account menu → Withdraw AI permission, also available in Account menu → Settings. This blocks new AI requests and requests cancellation of active responses. It cannot undo processing already performed. You can turn off web search, pause or delete memories, delete chats, and manage iOS microphone and Photos permissions or Android/browser microphone permission. Signing out clears this iPhone’s Morrow cache and drafts, Android’s encrypted account state and telemetry queue through Settings → Sign out, or the browser’s private drafts and recovery state across open Morrow tabs; it does not delete your server account. Android presentation files follow the cleanup boundary above. Browser preferences and account-specific consent are stored separately. Files you export or save to Photos remain under your control.

Retention and deletion

Ordinary chats, files and memories remain until you delete them or your account. Temporary chats expire after 24 hours and are removed by periodic cleanup. Expiring or revoking access does not itself delete your history. Technical service logs are retained for up to 30 days.

Owner-only operational analytics record account-attributed request and output counts, provider models, token usage, estimated cost, timings and bounded error categories. The iPhone, Android and browser clients can send content-free connection, replay, retry, lifecycle and operation events with app version, operation timings and a platform label (android, ios or web), with optional bounded numeric operating-system version metadata. Older records without a platform label remain unknown. Platform describes client activity and does not attribute inference spending. These records exclude messages, filenames, file contents, raw exceptions, Apple or Google credentials and usable session tokens. Android keeps at most 100 queued events in memory for five minutes and discards them on account change or signout. It may save one encrypted content-free managed-exception breadcrumb, consumed at next repository initialization and submitted only while less than five minutes old after verification of the same account and session epoch; this does not cover native crashes or system process termination. Pre-sign-in errors are not submitted. Granular request and client events are retained for 90 days; daily summaries and minimal invitation, membership and session audit history for 13 months. Invitation audit history records issuance, redemption, expiry, revocation and issuer identity when available. Account deletion removes attributable analytics and access history. Azure resource costs are reported separately and may include shared services.

On iPhone, open Settings and choose Delete account in the Account section. In the browser, use Account menu → Settings → Delete account. On Android, use Settings → Delete account. Confirm with Apple if Apple is linked, otherwise with Google. The server disables access, stops responses, revokes the confirming provider authorization, and deletes your chats, files, images, memories, linked identities, sign-in sessions and membership. Apple-confirmed deletion of an account linked to both providers does not revoke Google’s external consent grant; you can remove that grant in your Google account. That grant alone cannot recover a deleted Morrow account. Deletion normally completes within a few minutes; temporary service outages are retried automatically. Clients show the pending state and confirm completion. Contact support if it is still pending after 24 hours.

Telegram processes messages and invitation codes sent through the optional bot under its privacy policy. Bot drafts expire after 24 hours of inactivity and are removed by periodic cleanup. Unused invitation details are removed after revocation or the seven-day expiry; redeemed details are removed with the member account. Deleting Morrow data does not erase messages already held in Telegram; those can be deleted in Telegram.

Optional access requests store the bot ID, numeric Telegram buyer ID, optional username, chosen language, plan, quoted price, status, timestamps and delivery metadata. Access requests, navigation sessions, delivery jobs and sales events are retained for 30 days; arbitrary messages and payment details are not retained. Pending orders expire after 24 hours and codes must be activated within seven days. Redemption receipts remain through the granted expiry plus 30 days, or until account deletion. Account deletion removes redemption receipts and account associations; independent Telegram buyer/order metadata follows its own retention. For bot data access or deletion requests contact @xyz0x1991. See bot privacy for details.

Deleted content can remain in restricted database backups and soft-deleted file copies for up to seven days. Completed server deletion receipts, containing a one-way session-token or browser-receipt hash and deletion status, remain for seven days so your device can confirm completion; they contain no chat content or Apple identifier. The browser’s HttpOnly deletion-receipt cookie lasts 30 days and is cleared by a successful later sign-in; it does not extend the server receipt’s seven-day retention. Closed invitations retain an anonymous request marker to prevent reuse. A deleted owner account retains a non-identifying disabled marker to prevent the original installation credential from recreating it. Copies held by Apple or Microsoft for their own legal or security obligations follow their policies.

Native apps keep access credentials in protected device storage. Browser-based native authorization keeps encrypted proof and recovery material for five minutes, including a recoverable Morrow session credential. It is removed by periodic cleanup. Pseudonymous hashes of deleted provider identifiers also remain for five minutes to block authorizations already in flight, then are removed by periodic cleanup. These deletion markers contain no account reference, content or provider token.

Contact and changes

For access, correction, deletion or privacy questions, contact support@nevastack.com. We update this page when our practices change and request fresh consent before materially expanding AI sharing. Morrow is not directed to children.

Payment data

For a purchase, Morrow stores the order reference, account association, plan, amount, duration, offer version, acceptance time and payment confirmation state to perform the contract, grant access, provide support, account for payments and prevent duplicate grants. The payment provider identified before payment processes bank details and receipt contacts on its hosted page; Morrow does not receive card numbers or security codes. Account deletion removes the account association; anonymous payment and processing records remain for accounting and deduplication.