1Who is responsible
The controller under Art. 4(7) GDPR for the app and this website is:
Morning AI E-mail: support@morning-ai.app
For anything about your data, write to this address. We have not appointed a data protection officer.
2The short version
- Audio stays on your iPhone. Meetings, Day Record and imported phone recordings are recorded and transcribed on the device. There is no upload path for audio in the app.
- Text goes to our server when a feature needs it. Meeting and Day Record transcripts (unless you use Closed Room), the sources you connect for your briefing (calendar, email, health summary, location) and your settings are processed on our server in Frankfurt am Main, Germany.
- AI providers process that text for us: Google Gemini, with Anthropic Claude as a fallback if Gemini is unavailable.
- The free plan shows ads (Google AdMob). Health, email, calendar, meeting and location data are never used for advertising.
- You can export or delete everything in the app: Settings › Account › Export my data / Delete account.
3What stays on your iPhone
The following is processed only on your device and is not sent to us or to any provider:
- Recorded audio of meetings, voice notes and Day Record. Speech is turned into text on the device (Apple's on-device speech recognition and the WhisperKit model). Meeting recordings are kept on the phone for 30 days so you can play them back (you can turn this off in Settings or delete them earlier). Day Record keeps a rolling 48-hour audio archive and the audio of each conversation for 7 days.
- Closed Room (iOS 26, supported iPhones with Apple Intelligence): the meeting or Day Record analysis is done by Apple's on-device Foundation Models. The text and the result stay on the phone; Day Record text there is deleted after 90 days.
- Imported phone recordings (files you choose, e.g. from iOS Local Capture) and their transcripts stay on the device and are not added to briefings automatically.
- Voice recognition of known speakers (off by default; not offered in Illinois): a voiceprint — a numeric summary of how a voice sounds — and a short sample are kept only on the device, excluded from iCloud backup, and deleted when you remove them, withdraw consent, or after 12 months in which that voice was not heard. We only receive the date and version of your acceptance of the notice and a count of automatic deletions.
- Night sound detection (snoring, coughing) with Apple's Sound Analysis. Short clips stay on the phone for 7 days. Your sleep score is calculated on the device.
- Home pause zone for Day Record (optional): if you turn it on, iOS watches one 150 m region around your home with "Always" location permission so Day Record pauses there. The coordinate stays on the device; no location history is created.
- On-device voice for the evening review (Supertonic) and the word timing of your briefing (WhisperKit).
Two exceptions where Apple, not we, may process audio: voice input to the in-app assistant and the spoken alarm task use iOS speech recognition, which may send the audio to Apple depending on your device and settings (Apple's privacy policy). Speech models (WhisperKit) are downloaded from Hugging Face, which sees your IP address during the download.
4What we process on our servers
Depending on what you use, our server (hosted by Render in Frankfurt am Main) processes:
- Account: name, e-mail address, sign-in identifier (Sign in with Apple, Google, or e-mail with a hashed password), language, time zone, subscription tier.
- Settings and alarms: alarm times, briefing sections and their order, voices, news topics and sources, sports teams, birthdays you enter, your zodiac sign if you use that section (your birth date is not stored), prayer times and religious content if you turn them on, home and work addresses if you enter them.
- Location: the coordinates of your phone, sent while you use the app (or that you pick by hand), for weather, prayer times, your news edition and travel times. Only the latest position is kept. Home, work and meeting addresses are sent to Google Maps only to calculate a route.
- Calendar and reminders (only if you turn the source on): from your iPhone, today's and tomorrow's events (title, time, location, attendee names) and open reminders, sent as one snapshot that each sync replaces. From Google Calendar (if connected) the same, read through Google's API. Events or reminders are only created when you confirm them.
- E-mail (only if you connect a mailbox): sender, subject and a preview of recent messages from Gmail (read-only; draft creation only if you grant it — drafts are never sent), Microsoft Outlook (Mail.Read, User.Read, offline_access; where offered) or an IMAP mailbox. Access tokens and IMAP credentials are stored encrypted.
- Apple Health (read-only, only if you allow it): a summary of sleep stages, heart rate, heart-rate variability, blood oxygen, respiratory rate, steps, active energy and workouts for your briefing and evening review, and — if you use sleep tracking — the measurements of each night. We never write to Apple Health.
- Meetings: the transcript text (never the audio), speaker names you assign, and the results: summary, decisions, action items, suggested events and drafts; questions you ask about a meeting.
- Day Record (Gün Kaydı, Tagesaufnahme): the text of each conversation of the day and its analysis, unless you use Closed Room; plus technical health figures of the recording (running time, pauses, battery — no content). With "Only my voice in calls" (off by default) only your own side of a phone call is written; the other party's audio is never available to the app.
- Briefings and evening reviews: the texts we generate from your sources, the audio we synthesise from them, listening events (played, skipped, alarm dismissed or snoozed), saved moments, open items you carry to tomorrow.
- Assistant and memory: questions you send to the assistant (we store only the time of each message for rate limits, not its content) and memory notes you keep in Settings › Memory.
- Notion (optional): action items you choose to send to your Notion workspace, and the access token for it.
- Notifications: your device's push token.
- Subscriptions: via RevenueCat — product, transaction IDs, start and expiry dates, trial and renewal status. We never see your payment details.
- Support and e-mails we send: messages you write to us; transactional e-mails (sign-in codes, password reset, welcome, data export link).
5AI processing
Briefings, evening reviews, meeting and Day Record summaries, the assistant, sleep insights and article ranking are written by large language models. The text needed for each task — for example a transcript, your calendar events, e-mail previews, a health summary or your location's weather — is sent from our server to Google Gemini (Google's Gemini API). If Gemini fails, the same request goes to Anthropic Claude. Briefing audio is synthesised by Gemini text-to-speech from the briefing text.
We use the Gemini API on a paid (billed) Google Cloud project. Under Google's terms for paid Gemini API services, Google does not use our prompts or responses to improve its products; it may keep them for a limited time to detect abuse. Under Anthropic's commercial terms, API inputs and outputs are not used to train its models by default.
AI output can be wrong or incomplete. It is not used to make decisions about you that have legal or similarly significant effects (Art. 22 GDPR). Personalisation — which news, which order, what to remind you of — is based on your settings and listening events.
6Analytics, crash reports and ads
- Firebase Analytics (Google): screen views and app events (e.g. briefing played, alarm dismissed), linked to your account ID and an app-instance ID, to understand which features work. Data is kept according to the Google Analytics retention setting of our Firebase project.
- Sentry (EU data region, Germany): crash reports and performance traces of the app and the server (about 10 % of sessions are traced). Personal data is not attached by default, screenshots are off; your account ID is attached so a crash can be matched to a support request.
- Google AdMob (free plan only): rewarded ads you choose to watch. In the EEA, the UK and Switzerland Google's consent form asks whether ads may be personalised; on iOS the App Tracking Transparency prompt asks whether the advertising identifier (IDFA) may be used. Without your consent ads are not personalised, but AdMob still processes device information, IP address and ad interactions to deliver ads, limit frequency and prevent fraud. Paid plans show no ads.
7Purposes and legal bases
| Purpose | Data | Legal basis |
|---|---|---|
| Account, alarms, briefings, meetings, evening review, sync | account, settings, the sources you turn on, transcripts | Art. 6(1)(b) GDPR — providing the service you asked for |
| Optional sources and features you switch on (location, calendar, e-mail, Notion, Day Record, cloud analysis of meetings) | as described above | Art. 6(1)(a) GDPR — your consent in the app or the iOS permission; access to your device under § 25(1) TDDDG; withdrawable at any time |
| Health data, prayer and religious-content choices | health summary, sleep measurements; preference that can reveal religious belief | Art. 9(2)(a) GDPR — explicit consent by turning the source on and granting access |
| Other people's words in your recordings, e-mails and calendar | transcript text, names | Art. 6(1)(f) GDPR — your legitimate interest in keeping notes of your own conversations and appointments (see below) |
| Crash reports, security, abuse prevention, server logs | diagnostics, IP address, account ID | Art. 6(1)(f) GDPR — a stable and secure service |
| Product analytics (Firebase Analytics) | app events, account and app-instance ID | Art. 6(1)(f) GDPR — improving the app; you can object at any time (Art. 21) |
| Personalised ads (free plan) | advertising ID, device data | Art. 6(1)(a) GDPR and § 25(1) TDDDG — consent via Google's form / ATT |
| Non-personalised ads (free plan) | device data, IP address | Art. 6(1)(f) GDPR — financing the free plan |
| Billing and accounting records | subscription and transaction data | Art. 6(1)(c) GDPR — statutory retention duties |
| Transactional e-mails and support | e-mail address, your message | Art. 6(1)(b) GDPR |
8Service providers we use
These providers process personal data on our behalf (Art. 28 GDPR) or, where stated, as independent controllers:
| Provider | What for | Data | Location |
|---|---|---|---|
| Render Services, Inc. | hosting of our API server | all server-side data above | Frankfurt am Main, Germany (US company) |
| Neon, Inc. | managed PostgreSQL database | all stored server-side data | Frankfurt am Main, Germany (US company) |
| Cloudflare, Inc. (R2) | storage of generated audio and data-export files | briefing / review audio, export file | Cloudflare network (US company) |
| Google (Gemini API) | text generation, analysis, text-to-speech | the text of each AI task | USA / global |
| Anthropic PBC (Claude API) | fallback when Gemini is unavailable | the text of each AI task | USA |
| Google (Maps Platform: Directions, Places, Geocoding) | routes, travel times, address search | addresses, coordinates, search text | USA / global |
| Google (Firebase Cloud Messaging, Firebase Analytics) | push notifications, analytics | push token, app events, IDs | USA / global |
| Google (Sign-In, Gmail API, Calendar API) | sign-in and the sources you connect | per your authorisation | USA / global |
| Microsoft (Graph API) | Outlook mailbox you connect | mail metadata and previews | USA / global |
| Notion Labs, Inc. | action items you send to Notion | item text, workspace token | USA |
| RevenueCat, Inc. | subscription status and receipts | account ID, App Store transactions | USA |
| Google (AdMob) | ads in the free plan (own controller for personalised ads) | device data, IDFA with consent | USA / global |
| Functional Software, Inc. (Sentry) | crash and performance reports | diagnostics, account ID | EU (Germany) |
| Resend, Inc. | sending transactional e-mails | e-mail address, e-mail content | USA |
| Apple | App Store purchases, Sign in with Apple, push delivery, speech recognition (see above) | under your Apple account | Apple acts as independent controller |
| Vercel Inc. | hosting this website | IP address, request data | USA / global edge |
Public data sources are queried by our server without your account data, only with the place, station or topic needed: Open-Meteo (weather), Deutsche Bahn timetable via transport.rest, Diyanet and the adhan library (prayer times), news publishers' RSS feeds and Google News, CoinGecko, Yahoo Finance, football-data.org, Wikimedia and religious-text APIs.
9Transfers outside the EU
Several providers are based in the USA or may process data there. Transfers rely on the EU–U.S. Data Privacy Framework where the provider is certified under it (Art. 45 GDPR), and otherwise on the EU Commission's standard contractual clauses (Art. 46(2)(c) GDPR). You can ask us for a copy of the safeguards.
10How long data is kept
On our server, deletion runs automatically every night. Deleting your account removes everything listed here at once.
| Data | Kept for |
|---|---|
| Account, settings, addresses, memory notes, connected-account tokens, consent records | until you delete them, disconnect the source, or delete your account |
| Location | only the latest position; replaced on every update |
| Calendar, reminder and health snapshot | one snapshot, replaced at every sync and removed when you turn the source off; used only while less than 36 hours old |
| Briefing texts (history) | while your account exists; failed briefings 14 days |
| Briefing audio | 7 days (90 days if you saved a moment from it) |
| Saved moments | 365 days |
| Drive briefings (text and audio) | 7 days |
| Meeting transcripts, summaries, action items, speaker names | 365 days after the meeting |
| Day Record conversation text and analysis | 90 days |
| Evening reviews (day reports) and their audio | 365 days |
| Open items carried between days | 90 days after the last change |
| Sleep sessions (incl. heart rate, HRV, oxygen, breathing) | 365 days after the night |
| Listening and alarm events | 180 days |
| Assistant message times (no content) | 90 days |
| Morning history / streak days | 730 days / 400 days |
| Data export file | link valid 7 days; the file is deleted afterwards |
| Billing records | after account deletion kept without your identity, as long as accounting law requires |
| Crash reports (Sentry), analytics (Firebase) | per the retention setting of our Sentry plan and Firebase project |
On your iPhone: meeting audio 30 days; Day Record archive 48 hours, conversation audio 7 days, Closed Room Day Record text 90 days; night-sound clips 7 days; voiceprints until deleted or 12 months unheard; imported phone recordings and Closed Room meeting notes until you delete them. Deleting the app removes all of it.
11Your rights
You have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and to object (Art. 21) — in particular to processing based on legitimate interests. You can withdraw any consent at any time with effect for the future (Art. 7(3)), for example by turning a source off, disconnecting an account, or in iOS Settings.
- Export: Settings › Account › Export my data. We e-mail you a link to a JSON file with your data; the link works for 7 days.
- Delete: Settings › Account › Delete account. Your account and its server-side data are deleted at once; stored audio files follow through a deletion job shortly after, and connected Google access is revoked. Apple and RevenueCat keep their own purchase records. In Day Record you can also forget all of today's recording or the last 10 minutes. Cancel a subscription separately in your Apple ID settings.
- Anything else: write to support@morning-ai.app.
You also have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR), in particular in the EU member state where you live or work. You can also contact the competent data protection supervisory authority in Germany.
12People in your recordings, e-mails and calendar
Recordings, e-mails and calendar entries contain other people's names and words. We process them only to provide your notes, briefing and reminders, keep them for the periods above, and never use them for advertising or to build profiles of those people. If you record people, you must tell them where the law requires it — see our terms. People who appear in a user's data can exercise their rights with us at the address above (Art. 14 GDPR).
13Do you have to provide data?
An account (name or e-mail) is needed to use the app, because briefings and notes are tied to it. Everything else — location, calendar, e-mail, health, microphone, notifications, ads consent — is optional; without it the related feature does not work or works with less information.
14Children
Morning AI is not directed at children. You must be at least 16 years old to use it. We do not knowingly process data of children; if you believe a child has given us data, write to us and we will delete it.
15Security
Connections use TLS. Mail tokens and IMAP credentials are encrypted on our server. On the iPhone, recordings live in the app's private storage protected by iOS Data Protection. No system is perfectly secure; if a breach affects you, we will inform you as the law requires.
16This website
morning-ai.app is hosted by Vercel. When you visit, Vercel processes your IP address, the page requested, time, browser and referrer in server logs to deliver the site and keep it secure (Art. 6(1)(f) GDPR). The site sets one cookie, NEXT_LOCALE, to remember the language you chose (one year). There is no analytics, no tracking and no advertising on the website; fonts are served from our own domain.
17Changes
We update this policy when the app changes. The date at the top shows the current version; important changes are announced in the app.