Privacy Policy
What Morello collects, how that information is used, and who else processes it.
Last updated 13 August 2026
Overview
Morello builds your app on our servers. Your description and the code Morello writes for you are processed there, because that is where the app is generated, built, checked, and served to your browser. We do not train on them and we do not sell them. Everything else we hold is the minimum needed to sign you in, meter your credits, and process your payments: an email address, a balance, and a log of how many tokens each build used. Apps built with Morello for Mac are written to your own disk and are never uploaded.
Information We Collect
Account Information
We collect your email address and a user ID. If you sign in with Google, we receive your email address and name from Google; we do not receive your Google password. Authentication is handled by Supabase.
Billing Information
We hold your plan, your credit balance, and your payment history. Card numbers are handled entirely by Stripe and never reach our servers.
Usage Records
For each generation request we record the number of tokens used, the model, the cost in cents, and a timestamp. We do this to meter credits accurately. This usage log holds numbers, not the text of your prompts or the code that was generated.
Projects and Generated Code
When you build on the web, the code Morello writes for you is held on our servers, along with the screenshots Morello takes of your app to check its own work. This is required by the way the product works: our servers are where your app is built and where the preview you open is served from. We do not train on it, we do not sell it, and we do not share it beyond the service providers listed below. Projects built with Morello for Mac are written to your own disk instead.
Two points about preview links are worth noting. Anyone who has the link can open your running app, because that is what makes it shareable, so treat the link as public and do not put anything private into an app you are not ready to show people. The source code behind it is not public: downloading it requires signing in to the account that built it.
Information We Do Not Collect
- Morello for Mac project source code. It is written to your own disk and never uploaded.
- Morello for Mac screenshots. Those are captured locally on your Mac.
- Advertising identifiers, cross-site trackers, or third-party analytics profiles.
How We Use Information
We use the information described above for a limited set of purposes:
- To create your account and sign you in.
- To generate, build, check, and serve the apps you ask for.
- To meter your credits accurately.
- To process your payments and maintain your billing history.
We do not train models on your prompts or your code, and we do not sell your data.
How Your Prompts Are Processed
To build an app, Morello sends your description, any reference images you attach, the code being written, and screenshots of the running app to Anthropic's API, which is the service that generates the app. This transfer is unavoidable, because that API is what does the work.
Anthropic processes this data under their commercial terms and does not train models on API inputs or outputs. Data sent through the API is retained by Anthropic for up to 30 days for abuse monitoring. If you select Fable 5, a 30-day retention period is mandatory and cannot be shortened.
Your description is stored with the project it created, so that we can label the project for you and so that you have a record of what you asked for. Reference images are passed straight through and no separate copy is kept. The code and screenshots that come back are held with your project, as described above.
Service Providers
We share information with a small number of providers, each for a specific purpose:
- Anthropic. Generates the apps. Receives prompts, code, and screenshots.
- Supabase. Accounts and the credit ledger. Holds your email and balance.
- Stripe. Payments. Holds your billing details; we never see your card.
- Cloudflare. Hosting and the API proxy. Sees request metadata such as IP address.
- Google. Only if you choose to sign in with Google.
We do not sell your data, and we do not share it with anyone beyond the providers above.
Data Retention
Account and billing records are kept while your account is open, and for as long afterwards as tax and accounting law requires. Usage records are kept for 24 months. Projects you build on the web are kept while your account is open, so that you can come back to them and keep changing them; ask us to remove one and we will. If you delete your account, we remove your profile, your balance, and your projects. Usage records are anonymized rather than deleted, so that our accounting records remain complete.
Your Rights
You can ask us for a copy of your data, ask us to correct it, or ask us to delete your account and everything attached to it. Email [email protected] and we will act on your request within 30 days.
If you are in the UK, EU, or California, you have additional statutory rights, including the right to object to processing and the right to lodge a complaint with your data protection authority. We will not discriminate against you for exercising any of them.
International Transfers
Morello is operated from the United States, and the providers we rely on process data there. Anthropic, Supabase, Stripe, and Cloudflare all handle information in the United States. If you use Morello from outside the United States, your information is transferred to and processed in the United States, where data protection law may differ from the law where you live.
For transfers from the UK or the European Economic Area, we rely on the standard contractual clauses offered by these providers as the safeguard for that transfer.
Security
Traffic is encrypted in transit. Your API credentials are held server-side and never shipped to the app. Web sessions are held in your browser and cleared when you sign out. Mac app sessions are stored in the macOS Keychain. No system can be made completely secure. If we discover a breach affecting your data, we will tell you promptly.
Children's Privacy
Morello is not intended for anyone under 13, and we do not knowingly collect data from them. Paid plans require you to be 18 or older, or to have a parent or guardian agree on your behalf.
Changes to This Policy
If we change this policy in a way that materially affects you, we will email you before it takes effect.
Contact
Questions about this policy can be sent to [email protected].