Legal
Privacy Policy
Last updated: October 2026
This policy explains what information Morphis ("we", "us") collects when you use getmorphis.com, the dashboard, the SDK and the generation API (the "Service"), and how we use it.
Information we collect
- Account data: your email address and a salted hash of your password. We never store your password in readable form.
- Workspace data: workspace name, team members, API key hashes (we cannot see your keys after creation), support tickets you submit.
- Request data: the intent and contextData you send to the generation API, and the generated output, while the request is processed.
- Usage data: timestamps, token counts and whether a request was served by AI or fallback, used for quota metering and reliability.
- Technical data: IP address and request metadata, used for security and rate limiting.
How we use it
- To provide, secure and improve the Service, including sign-in verification codes and password resets by email.
- To enforce usage limits and prevent abuse.
- To communicate with you about your account and support requests.
We do not sell personal data.
AI model providers
To generate a component, your intent and contextData are sent to third-party AI model providers (currently Groq, NVIDIA and OpenRouter). Do not send secrets, passwords, payment card numbers or other highly sensitive personal data in these fields. Those providers process the data under their own terms and privacy policies.
Service providers
We use the following processors to run the Service:
- Vercel — website and API hosting
- Supabase — database hosting
- Render — generation engine hosting
- Resend — transactional email
- Stripe — payment processing, when billing is enabled
Retention
We keep account and workspace data while your account is active. Sign-in codes expire after 10 minutes. You can ask us to delete your account and associated data at any time.
Security
Data is encrypted in transit (HTTPS). Passwords are hashed, API keys are stored only as hashes, sessions use secure HTTP-only cookies, and sign-in requires an emailed one-time code. No system is perfectly secure; see our Security page for details and how to report a vulnerability.
Your rights
Depending on where you live, you may have the right to access, correct, export or delete your personal data, and to object to or restrict certain processing. Contact us to exercise these rights.
Cookies
We use only essential cookies: a session cookie to keep you signed in and a short-lived cookie during email verification. We do not use advertising cookies.
Contact
Questions or requests: ibrahim@getmorphis.com.