DATA & PRIVACY

Your company context remains your company context.

This page is a plain-language explanation of how Morrow handles information. It complements, but does not replace, the formal Privacy Policy. Where this page and the Privacy Policy differ on a legal question, the Privacy Policy controls.

What Morrow processes
Categories of information.
  • Account information — name, email, authentication identifiers.
  • Company content — products, offers, customers, evidence, experiments, decisions, and other information a member adds.
  • Uploaded and imported content — files, notes, and imported conversation context provided by a member.
  • Product usage information — actions taken in the app, used to operate and improve the service.
  • Billing information — plan, subscription state, invoices; payment card details are processed by Stripe and not stored by Morrow.
  • Communications — support, feedback, and email interactions.
  • Technical and device information — such as IP address, browser, and coarse device details for security and operation.
  • Referral and attribution information — where a visitor arrived from, for approved referral and affiliate flows.
Why it is processed
To operate the decision workspace.

Company information is processed to produce the analyses, experiments, and decisions inside that company's workspace, to secure access, to support billing, to send transactional email, and to operate and improve the service.

Ownership
Founders retain ownership of their company content.

Members retain ownership of the company content they provide. Morrow uses that content under a limited license to operate the service, as described in the Terms of Use.

How AI processing works
Providers process content to return responses.

When AI features run, relevant company content is sent to one or more configured model providers through Morrow's AI gateway so the provider can produce the response returned to the workspace. Which provider handles a given request may change over time. Whether provider training on customer inputs is disabled depends on the applicable provider's contract and configuration and is not guaranteed for every provider.

Team access
Only invited members see company content.

Company content is visible only to authorized members of that company. Adding or removing members, and the roles they hold, is controlled by the company's owner and admins.

Shared Decision Memos
Sharing is explicit and revocable.

Decision Memos are private by default. A member with rights may create a private link or a public snapshot. Shared links can expire and can be revoked. Public snapshots exclude sensitive company identifiers where supported.

Integrations
Only what a member connects.

Third-party integrations run only when a member connects them, and process only the data required to perform the connected function.

Analytics and cookies
Limited to what the service needs.

Cookies and similar technologies are used for authentication, session state, and basic product analytics needed to operate and improve the service. Morrow does not sell personal information.

Billing and email
Stripe and transactional email.

Billing is processed by Stripe. Transactional email (authentication, invitations, decision sharing, billing status, account communications) is sent through Morrow's managed email infrastructure using a Morrow sender domain.

Referral and affiliate information
Attribution supports approved programs.

Where a visitor arrives through a referral or invitation link, Morrow may record attribution to support the referral or affiliate program. Attribution is limited to what those programs require.

Retention
Tied to the account lifecycle.

Company content is retained while the company exists in Morrow and while needed to provide the service. Archived companies remain accessible to authorized members. On deletion, content is removed from active systems on an ongoing basis; residual copies may persist in backups or logs for a limited period, subject to legal and operational constraints.

Founder controls
Export, archive, and deletion.

Authorized members can export company records, archive companies, and request deletion. Requests are handled through the app and through support@meetmorrow.ai.

Authorized access
Support and operational access is limited.

A limited number of authorized Morrow personnel may access company content when necessary for support, security, abuse prevention, legal compliance, or service operation. Broad routine access to company content by staff is not part of normal operation.

Subprocessors
Service providers that support Morrow.

Morrow relies on service providers for hosting and database, authentication, storage, email delivery, payments (Stripe), analytics, and AI model access. Providers may change as the product evolves. See the Privacy Policy for the current category-level list.

Privacy requests
How to reach us.

Submit privacy requests — access, correction, export, or deletion — to support@meetmorrow.ai. Morrow verifies requests before acting on them.

Page details
Version
Last updated
July 22, 2026
Canonical URL
https://meetmorrow.ai/data-privacy