Privacy Policy

Last updated: 13 August 2026

Before publishing, make sure the contact address (hello@morro-app.com) points to an inbox you monitor.

This Privacy Policy explains what Morro ("Morro", "we", "us") collects, why, and what choices you have. Morro is a screen-time accountability app that shows your calendar next to your device usage and asks a short hourly question so you can keep an honest record of where your time goes.

We designed Morro to hold as little of your data as possible, and to keep what it does hold tied to your account alone. We do not sell your data, and we do not use it for advertising.

Who we are. Morro is operated by Ka Yan Wan ("we"). If you have any question about this policy or your data, contact us at hello@morro-app.com.

The short version

What we collect and why

Account information

When you sign in (by one-time email code, Apple, or Google), we store your email address. We use it to authenticate you and to send account-related messages. We do not send marketing email unless you opt in. If you use Apple's "Hide My Email", we only ever see the private relay address Apple provides.

Calendar events

If you connect a calendar, your device sends the titles and start/end times of your upcoming events to our backend. We need these on the server so that the hourly check can tell whether an event is happening right now and ask the right question ("Working on '{event}'?" versus "Watching value-added content?"). We store only the next several days of events, and we do not read your full calendar history. Event titles can be personal, so we treat them as sensitive and keep them scoped to your account only.

Your answers

Every time you respond to a prompt (Yes/No, or plus/minus), we store the answer, the time it was asked, the type of prompt, and the related event title if any. This is the core of the product: it builds your productive-versus-wasted history and your daily tally.

Device presence and notifications

To decide when to send a prompt, each of your devices sends a periodic heartbeat (a timestamp saying "I am active"). We store the most recent heartbeat per device, the device platform (iPhone or Mac), and your push notification token so we can deliver notifications through Apple Push Notification service (APNs).

Mac activity (Mac app only)

If you use the Mac app, it samples what you are actively doing and stores, for each block: the app name, the window title, the website URL (when a browser is in front), the start time, and the duration. This is what lets the Mac show real app and site names next to your calendar. This data can reveal what you read and browse, so we treat it as sensitive. It is stored only for your account, it is never sold, and it is never used for advertising. iPhone screen-time data is different: Apple's system keeps it on your device inside a sandbox, so we cannot read, store, or transmit it. It is only ever displayed to you on your own phone.

Settings

We store your preferences: calendar source, your usage threshold, your waking hours, quiet-hours preference, your time zone, and your notification cadence. These control how and when the app behaves.

Subscription status

Morro is a paid subscription. Payment is processed by Apple, not by us. We never see your card number. We do receive, through Apple, your subscription status (active, expired, trial) so we can unlock the paid features.

Information we do NOT collect

We do not collect your contacts, your photos, your precise location, your health records, your browsing history on iPhone, or the contents of your emails or messages. We do not use third-party advertising or tracking SDKs.

How your data is stored and protected

Your data is stored in our backend, hosted on Supabase (Postgres database, authentication, and serverless functions). Every table is protected with row-level security, which means each account can only ever read or write its own rows. Data is encrypted in transit (HTTPS/TLS) and encrypted at rest by our hosting provider.

Who we share data with

We do not sell your data and we do not share it for advertising. We share the minimum necessary with the service providers ("sub-processors") that operate the app on our behalf:

We may also disclose data if required by law, or to protect the rights, safety, and security of our users and our service.

How long we keep your data

We keep your data while your account is active. Upcoming calendar events roll off as they pass. When you delete your account, we delete your data (see below).

Your rights and choices

Depending on where you live (for example the EU/EEA under GDPR, or California under the CCPA/CPRA), you may have additional rights, including the right to access, correct, delete, or restrict processing of your personal data, and the right not to be discriminated against for exercising them. To exercise any of these, contact us at hello@morro-app.com.

Children

Morro is not directed to children under 13 (or the equivalent minimum age in your country), and we do not knowingly collect data from them. If you believe a child has provided us data, contact us and we will delete it.

International users

We operate from Hong Kong and your data may be processed there and in the regions where our service providers operate. By using Morro, you understand your data may be transferred to and processed in those locations.

Changes to this policy

We may update this policy as the app evolves. We will post the new version with an updated date, and for material changes we will notify you in the app.

Contact

Ka Yan Wan
hello@morro-app.com