Skip to content

Privacy Policy

Morse records what is said in a meeting, and the video too where recording is switched on, and writes it down. That is an unusual amount of trust, so this page is specific about what we collect, who we send it to, and what you can ask us to delete. It describes what the product actually does today, not what it might do later.

In effect from 8 October 2026.

Who we are

Morse is made by Unified Machines, which is the data controller for everything described on this page. You can reach us about anything here at hello@onmorse.com.

If you signed in with a work account, your employer administers that account. They decide who at your organisation may use Morse, and an administrator there can see the meetings held on it under the limits in section 5.

What we collect

There are two ways to have an account, and they collect different things.

If you sign in with Google, we ask Google for three things: your name, your email address and your profile picture. We also keep the identifier Google uses for your account so we recognise you next time. We never see your Google password.

If you sign up with an email address instead, we keep your name and that address. Your password is not kept by Morse: it goes to Amazon Cognito, which stores it and answers one question for us, whether a password matches an address. Where Cognito is not configured, the password is stored as an Argon2 hash instead, which cannot be turned back into the password. Either way nobody at Morse can read it, and we cannot tell it to you if you forget it. We send a six-digit code to your address to confirm it is yours; what we keep is a keyed hash of that code, not the code.

If you connect your calendar, that is a separate decision you make on a separate Google screen. Granting it lets Morse read the meetings on your calendar and put Morse links on them. You can disconnect it at any time in Settings, and revoke it outright from your Google account.

From the meetings themselves:

  • Audio and video while the meeting is running. Where recording is switched on for the server, and unless the host turns it off for a meeting, the meeting is also recorded: one video file per stretch of the call, everyone's cameras side by side, with a shared screen taking the stage while someone is sharing. Everyone in the meeting is told while a recording is running.
  • The transcript. Audio is transcribed as people speak, and the text is stored against the meeting.
  • The notes: the summary, key points and action items a language model writes from that transcript.
  • Anything drawn on the whiteboard, and voice notes you record.
  • Files you upload to a knowledge folder, and the text taken from them.
  • Who joined, when, and the name a guest typed at the door.

And the ordinary operational records: a sign-in cookie that keeps you signed in, server logs, and, if you are on a paid plan, the subscription record. Card details go straight to Stripe and never reach us.

Why we use it, and on what basis

To run the meeting, to transcribe it, to write the notes, to show you your history, to email the people you ask us to email, and to bill you if you pay us. That is the whole list.

If you are in the UK or the European Economic Area, the law asks us to name a lawful basis for each of those. Ours are:

  • Performing our contract with you: holding the meeting, transcribing it, writing the notes, keeping your history, and taking payment for a paid plan.
  • Your consent: connecting your calendar, which is a separate choice on a separate screen, and which you can withdraw whenever you like.
  • Our legitimate interests: keeping Morse secure, preventing abuse of it, and repairing it when it breaks. We have weighed those against your interests, and they are why we use the least data that answers the question.
  • A legal obligation: the billing records tax law requires us to keep.

We do not sell personal information, we do not share it for cross-context behavioural advertising, and we do not use the contents of your meetings to build or train models of our own.

Who we send it to

Morse is not built entirely by us. These are every outside service that touches your data, what reaches them, and why. There are no others.

ServiceWhat reaches themWhy
GoogleYour name, email and profile picture; your calendar if you connect itSigning you in, and calendar events
Amazon CognitoYour email address and your password, if you did not sign in with GoogleKeeping the password, and checking it
LiveKitMeeting audio and video, while the meeting runsCarrying the call between participants, and making the recording
DeepgramMeeting audioTurning speech into text
Fireworks AIThe transcriptWriting the summary and the action items
HeliumText from your knowledge filesBuilding documents from what Morse knows
Amazon Web ServicesMeeting recordings, profile photos, voice notes, knowledge filesStoring them
BrevoEmail addresses, and the notes when you email themSending mail
StripeYour email, and your card details directlyTaking payment on paid plans
Vercel and HostingerTraffic to the site and the APIHosting Morse

We engage each of them to process your data for the purpose in that row and for nothing else. What we will not do is warrant another company's terms on their behalf: if you need certainty about what one of them may do with data, for a security review or for a contract of your own, write to us and we will tell you what our agreement with them says.

Three of them (Deepgram, Fireworks AI and Helium) are AI services, so it is worth being exact about what does and does not reach them. They receive what was said in your meetings, the notes written from it, and the files you put in a knowledge folder. They do not receive anything Morse reads from your Google account. Your calendar is read to show you your own meetings and written to keep their events current; that data is never placed in a prompt or sent to a model.

The use of raw or derived user data received from Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements. We do not use, transfer or sell it to create, train or improve generalised AI or machine-learning models, and we do not pass it to anyone else who would.

This list changes as Morse is built. When it does, it changes here, and the date at the top of this page changes with it.

Beyond this list, we disclose data only where the law requires it of us, and we will tell you when that happens, unless we are forbidden to.

Who can see it inside Morse

The boundaries below are enforced by the product, not by policy:

  • The full transcript of a meeting is visible to its host, and to nobody else.
  • The notes are visible to the colleagues who attended or were invited. Guests never see them.
  • A meeting link shows a plain card to whoever opens it, never the meeting's title.
  • An administrator at your organisation can open a meeting's record, but must give a reason first. That access expires by itself, and every use of it is written to an audit log your organisation can read.

On our side, access to production data is limited to the people who keep Morse running, and is used to operate and repair the service, not to read your meetings.

How long we keep it

Plainly: your meetings, transcripts, notes and files are kept until you or your administrator delete them, or until you ask us to close your account. Morse does not currently expire them on a timer, and we would rather say so than describe a schedule we do not run.

Two things do expire on their own. A voice note you delete has its audio destroyed thirty days later. An administrator's access to a meeting record lapses shortly after it is granted.

When a retention schedule ships, this section is where it will be written down, and we will date the change.

Where it is processed

Morse is used from many countries, and several of the services in section 4 are based in the United States. So using Morse involves your data being processed outside the country you are in, and for people in the UK and the European Economic Area that means outside it.

Where the law requires a transfer mechanism for that (standard contractual clauses, or an adequacy decision), we rely on the one our agreement with that provider puts in place. Write to hello@onmorse.com and we will tell you which one applies to a particular provider.

What you can ask for

Whoever you are and wherever you are, you can ask us to:

  • Tell you what we hold about you, and give you a copy of it.
  • Correct it where it is wrong.
  • Delete it, and close your account with it.
  • Hand it over in a form a machine can read, either to you or to somebody else.
  • Stop or narrow a particular use of it, including where we have relied on our legitimate interests above.
  • Withdraw a consent you gave (your calendar is the one that matters here) without that unpicking what we did while it stood.

Write to hello@onmorse.com. We will answer within thirty days, and asking will never cost you money, service or standing with us.

Deleting an account is handled by us rather than by a button in the product today. Ask, and we will remove the account and the meetings it owns.

Some of it you can do yourself: delete a meeting or a voice note from your history, disconnect your calendar in Settings, and revoke Morse's access from your Google account at any time.

If you are in California: we have not sold or shared personal information in the past twelve months and we do not intend to, so there is no opt-out here for you to exercise. The list above is what the CCPA gives you, and we will not discriminate against you for using it.

If you are in the UK or the European Economic Area and we have handled this badly, you may complain to your data protection authority. We would rather you came to us first, but it is your right either way, and you do not have to.

Keeping it safe

Traffic to Morse is encrypted in transit. Files live in private buckets that cannot be read from the open internet. Each one is served through a link that expires. Passwords are not kept in Morse's own database: they are held by Amazon Cognito, or, where that is not configured, as an Argon2 hash that cannot be reversed. Signing in with Google means there is no password here at all. The credentials for your calendar are encrypted at rest under their own key, separately from everything else. Backups are taken regularly, and reaching them is limited to the people who run the service.

No service can promise this perfectly, and we are not going to.

If there is a breach that affects your data, we will tell you without undue delay, and the relevant supervisory authority within 72 hours where the law requires it. We will tell you what happened and what we did about it, rather than a sentence of reassurance.

Children

Morse is a tool for work and is not intended for anyone under 16. We do not knowingly collect their data, and will delete it if we find we have.

Changes to this page

When this policy changes, the date at the top changes with it. If a change materially affects what happens to your data, we will tell the people it affects rather than quietly editing the page.