Morrow

Privacy Policy

Last updated 22.09.2026

Morrow reads the accounts you choose to connect and turns them into one reading a day. This policy explains exactly what it reads, what it keeps, how long, and how to make it forget. Morrow is operated by Morrow (“we”).

The short version

  • You choose each source. Nothing is read until you connect it, and you can disconnect it at any time.
  • Raw data from your sources is deleted within 24 hours. Morrow keeps only a distilled summary.
  • Morrow never reads or predicts about health, pregnancy, death, money trouble or relationship breakdown.
  • We don't sell your data, show you ads, or use your data to train AI models.
  • You can see everything Morrow knows about you, forget any single fact, or forget everything.

What we collect

Your account. When you sign in with Google we receive your name, email address and profile picture. We also store your time zone so your reading starts at the right hour.

Google Calendar (read only, if you connect it). From the calendars in your account we read events from the last 90 days and the next 30: start and end times, title, a short plain-text excerpt of the description, location, organizer, attendees and their responses, and the calendar's name. We never read attachments or video-call details, and we don't keep titles or details of events you're not part of.

Spotify (if you connect it). Your recently played tracks and your top artists and tracks.

Gmail (read only, if you connect it). Messages from the last few weeks, excluding spam, trash, chats, promotions, social and forum mail: sender and recipients, subject, date, labels and the plain text of the message without quoted replies. We never read attachments.

What you tell Morrow. The questions you ask in your daily reading and Morrow's answers.

Technical data. A session cookie to keep you signed in and a short-lived cookie that records your time zone at sign-in. Our hosting provider keeps standard server logs. We don't use advertising or analytics trackers.

How we use it

We use your data only to provide Morrow to you:

  • to build your dossier — a short set of patterns about your days, such as rhythms, pursuits and the people you meet;
  • to write your daily reading and answer your questions;
  • to check whether a prophecy has come true, by watching the sources it depends on;
  • to keep the service secure and working.

Morrow's readings are generated by AI. Parts of your dossier, your questions and, for Gmail, short excerpts of recent threads are sent to our AI provider to produce each reading. Sensitive topics are filtered out before anything is sent.

Google user data

Morrow's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

  • We use Google data only to provide and improve the features you see in Morrow.
  • We don't transfer it to others except to run the service (the processors listed below), to comply with the law, or with your permission.
  • We don't use it for advertising, sell it, or use it to train general AI models.
  • No person reads it unless you ask us to, it's needed for security, or the law requires it.

How long we keep it

  • Raw source data (events, plays, messages as fetched): deleted within 24 hours.
  • Your dossier and the summaries built from your sources: kept while the source stays connected, rebuilt as new data arrives. Mail summaries (who, when, a one-line note per thread — never message bodies) are kept for up to 180 days.
  • Readings, your questions and prophecies: kept until you delete them, so Morrow can remember past readings.
  • Your account (name, email, time zone): kept until you choose Forget everything, which deletes it along with everything else.

Who processes it

We use a small number of providers to run Morrow. They process data on our behalf and only as needed:

  • Vercel — hosting, and access to AI models through Vercel AI Gateway.
  • Anthropic — the Claude models that write readings and answers.
  • Neon — our database.
  • Google and Spotify — the sources you connect, under their own privacy policies.

Your data may be processed in the United States and other countries where these providers operate.

Security

Data is encrypted in transit. The tokens that let Morrow read your connected accounts are encrypted at rest, and access is read only. No system is perfectly secure; if something goes wrong that affects your data, we will tell you.

Your choices

  • See what Morrow knows: Sources → View dossier.
  • Forget one fact: in your dossier, choose Forget this.
  • Disconnect a source: Sources. This deletes that source's raw data and rebuilds your dossier without it.
  • Forget everything: Sources → Forget everything permanently deletes your account — your dossier, readings, questions, prophecies and all source data — disconnects every source, revokes Morrow's Google access and signs you out. It can't be undone.
  • You can also remove Morrow's access at any time from your Google account or Spotify account.

Depending on where you live you may have further rights, such as to access, correct, export or delete your data, or to object to how it's used. Write to me@renzhi.co and we'll respond within 30 days.

Children

Morrow is not for anyone under 16, and we don't knowingly collect data from children.

Changes

If we change this policy we'll update the date above, and tell you in the app before any change that affects how your data is used.

Contact

Questions or requests: me@renzhi.co. See also our Terms of Service.