Privacy Policy
Morse is operated by DIGITAL VIRALIST SRL, Razoare 200A/20, Florești, Cluj, Romania, 407280 (VAT RO37630978, Trade Register J2017002897123), the data controller for the processing described here ("we", "us"). Morse connects marketing data sources such as Google Analytics, Google Search Console and LinkedIn to AI assistants through the Model Context Protocol (MCP), and provides related reporting features. This policy explains what data we process when you use the service at heymorse.com.
1. Data we collect
- Account data. Your email address, used to sign you in with a one-time code and to identify your workspace.
- Connected accounts. When you link a Google or LinkedIn account, we receive OAuth tokens that let us read data from that platform on your behalf, together with the account's email address or member id and the list of properties, sites, pages or ad accounts it can access. Tokens are encrypted at rest.
- Marketing data. Analytics, search, page and advertising statistics are retrieved live from the connected platform when you or your AI assistant ask for them. We do not build a copy of your platform data; results are returned to the requesting client and are not retained by us beyond transient processing and operational logs.
- Client registrations. Identifiers of the MCP clients (for example Claude) that you authorise to access your workspace, and the tokens issued to them.
- Technical data. Standard server logs (IP address, user agent, request path, timestamps, errors) kept by our hosting provider for security and troubleshooting.
2. How we use data
- To authenticate you and the clients you authorise.
- To retrieve the marketing data you request from the platforms you connected, and return it to your client.
- To operate, secure, debug and improve the service, and to contact you about it.
We do not sell personal data, use it for advertising, or share it with third parties except as described below. Data is processed only as needed to provide the features you use.
3. Google user data
Morse's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We request read-only access to Google Analytics and Search Console. Google data is used only to provide the functionality you request; it is not used to develop, improve or train generalised AI or machine-learning models, and no human reads it except with your permission, for security purposes, or as required by law.
4. LinkedIn data
We request access to LinkedIn pages you administer and advertising accounts you can use, in order to retrieve their statistics on your behalf. LinkedIn data is retrieved on demand, is not stored beyond transient processing, and is used only to provide the functionality you request, in accordance with LinkedIn's API terms. You can revoke access at any time from your LinkedIn settings.
5. Sharing and processors
We rely on the following providers to run the service; each processes data only on our instructions:
- Vercel: application hosting and request logs.
- Supabase: database and authentication (workspace records, encrypted tokens, one-time codes), hosted in the EU.
- Resend: delivery of sign-in and service emails.
- Google and LinkedIn: the platforms whose APIs we call with your authorisation.
Data you request through an AI assistant is sent to that assistant's provider (for example Anthropic for Claude) under their own terms.
6. Retention and deletion
Account data and connected-account tokens are kept while your workspace is active. Sign-in codes expire within an hour; access tokens issued to clients expire within an hour and refresh tokens within 30 days. You can disconnect a platform by revoking Morse in your Google or LinkedIn account settings, and you can request deletion of your workspace and all associated data by emailing privacy@heymorse.com. We delete it within 30 days.
7. Security
All traffic is encrypted in transit (HTTPS). OAuth tokens are encrypted at rest with keys held separately from the database. Access to production systems is restricted to the operators of the service.
8. Your rights
Under the GDPR you have the right to access, correct, export or delete your personal data, to object to or restrict its processing, and to withdraw consent at any time. Contact us at privacy@heymorse.com to exercise these rights. You may also lodge a complaint with the Romanian supervisory authority (ANSPDCP, dataprotection.ro) or the authority in your country of residence.
9. Changes
We may update this policy as the service evolves. The date above indicates the latest revision; material changes will be announced on this page.
10. Contact
DIGITAL VIRALIST SRL, Razoare 200A/20, Florești, Cluj, Romania, 407280. Questions about this policy: privacy@heymorse.com. Legal representative: Andrei Temneanu, Administrator. See also the legal notice.