Privacy Policy
Your code stays on your machine. Here is everything else.
Last updated 10 August 2026
The short version
Your app's source code stays on your Mac. Morello does not upload your projects, store copies of them, or read them. We hold the minimum needed to sign you in, meter your credits, and take your money: an email address, a balance, and a log of how many tokens each build used.
What we collect
Account
Your email address, and a user ID. If you sign in with Google, we receive your email address and name from Google; we do not receive your Google password. Authentication is handled by Supabase.
Billing
Your plan, your credit balance, and your payment history. Card numbers are handled entirely by Stripe and never reach our servers.
Usage
For each generation request we record the number of tokens used, the model, the cost in cents, and a timestamp. We do this to meter credits accurately. We do not store the contents of your prompts or the code that was generated.
What we do not collect
- Your project source code. It is written to your own disk and never uploaded.
- Screenshots of your running apps. These are captured locally on your Mac.
- Advertising identifiers, cross-site trackers, or third-party analytics profiles.
Where your prompts go
To build an app, Morello sends your description, any reference images you attach, the code being written, and screenshots of the running app to Anthropic's API, which is what generates the app. This is unavoidable: it is the service doing the work.
Anthropic processes this data under their commercial terms and does not train models on API inputs or outputs. Data sent through the API is retained by Anthropic for up to 30 days for abuse monitoring. If you select Fable 5, a 30-day retention period is mandatory and cannot be shortened.
Morello passes this data through and keeps no copy of it.
Who else is involved
- Anthropic — generates the apps. Receives prompts, code, and screenshots.
- Supabase — accounts and the credit ledger. Holds your email and balance.
- Stripe — payments. Holds your billing details; we never see your card.
- Cloudflare — hosting and the API proxy. Sees request metadata such as IP address.
- Google — only if you choose to sign in with Google.
We do not sell your data, and we do not share it with anyone beyond the services above.
How long we keep it
Account and billing records are kept while your account is open, and for as long afterwards as tax and accounting law requires. Usage records are kept for 24 months. Delete your account and we remove your profile and balance; usage rows are anonymised rather than deleted so our books still balance.
Your rights
You can ask us for a copy of your data, ask us to correct it, or ask us to delete your account and everything attached to it. Email support@morello.app and we will action it within 30 days.
If you are in the UK, EU, or California, you have additional statutory rights, including the right to object to processing and the right to lodge a complaint with your data protection authority. We will not discriminate against you for exercising any of them.
Children
Morello is not intended for anyone under 13, and we do not knowingly collect data from them. Paid plans require you to be 18 or older, or to have a parent or guardian agree on your behalf.
Security
Traffic is encrypted in transit. Your API credentials are held server-side and never shipped to the app. Sessions are stored in the macOS Keychain. No system is perfect, and we will tell you promptly if we ever discover a breach affecting your data.
Changes
If we change this policy in a way that materially affects you, we will email you before it takes effect.