Privacy Policy
Last updated: 16 September 2026
Morpha, operated by Difflex Ltd ("Morpha", "we", "us"), is the video editor at morphareels.ai. This policy explains what we collect, how we use it, and the choices you have — including how we handle data from social accounts you connect for publishing.
Questions: hello@morphareels.ai.
- Account information. When you sign in with Google or with an email and password, we receive your email address and, from Google, your name and profile picture.
- Content you create. The projects you build in the editor — layers, text, animations, and settings — and the media you upload, such as video clips and images.
- Transcripts and text in your media. When you upload a video clip, our servers copy its audio track, where its format allows, into a separate file stored beside the clip. The speech in that audio is transcribed, and text that appears in a clip's frames or in an image is recognised, by models that run in your browser, or on the computer running Morpha's software development kit. Those models are downloaded from Morpha's own storage, and neither task sends your media to an outside service. The transcript and the recognised text are stored beside the clip or image.
- Connected social accounts. When you connect Instagram or TikTok, we receive and store the OAuth access and refresh tokens those platforms issue, along with basic profile details (your username and avatar, and, for TikTok, your account's allowed posting options). We use these solely to publish the content you schedule.
- Payment information. Subscriptions are processed by Stripe. We receive your subscription status and billing metadata; we do not store your full card number.
- Assistant prompts. Text you send to Morpha's AI prompt panel, so we can generate the requested edits.
- AI assistants you connect. When you sign in to Morpha from an AI assistant, such as Claude, ChatGPT, Codex or another Model Context Protocol (MCP) client, we create an API key for that assistant. The key carries the name the assistant gives itself, has no expiry date, and works until you revoke it in Settings under Connected agents. We email you when a key is created and when one is revoked. The assistant receives what Morpha returns to its requests, which can include project names, layer text, filenames, transcripts, text recognised in your media, the email addresses of the people who own projects and Collection items in your workspaces, and download links for server renders.
- Anonymous accounts. An AI assistant can create an anonymous Morpha account before anyone has signed in. We take no email address, name or password for it. When a person opens its claim link and signs in, its projects move into that person's own account and the anonymous account is deleted. To limit how many anonymous accounts one network address can create, a counter named after the request's IP address records that address's recent attempts.
- Server renders. When you or an assistant asks Morpha to render a video on our servers, we store the finished MP4 with its project. Anyone who has its download link can download it, without signing in, until the file is deleted. We keep a record of each server render: the account that asked for it, the project, the video's length and scale, and, while the file exists, the amount charged and the download link.
- Workspaces. Members of a workspace can see each other's names and email addresses, and the email address of the owner of each project and Collection item in the workspace.
- Web addresses you give us. When you or an assistant asks Morpha to import an image, audio file or video from a web address, our servers download it and identify themselves to that site as Morpha. The site receives the request from Morpha's servers, not from your device.
- Usage and device data. Standard server logs (IP address, request metadata) and a session cookie that keeps you signed in.
- AI usage and activity records. For each signed-in account, we keep a daily log of its AI use for each model: the number of requests, the tokens used and the cost. We also record each day on which a signed-in account uses Morpha, together with the country and city its requests came from and the language its browser prefers. For a guest session, we record only the days on which it was used.
- To provide and operate the editor: rendering, storing, and serving your projects and media.
- To publish to your connected Instagram or TikTok accounts when you explicitly schedule or post a video.
- To process subscriptions and prevent abuse.
- To provide support, secure the service, and improve the product.
- To understand how Morpha is used: how many people use it each day, where they are, which languages their browsers prefer, and which sites or campaigns brought them to Morpha.
This section covers data we receive through the Instagram and TikTok APIs.
- We access these platforms only with your authorization, and only to publish the specific videos you schedule or post from Morpha. We never post on your behalf without an action you take.
- Access and refresh tokens are stored securely and used solely to publish your content and to keep the connection working. We do not share them with anyone.
- The Instagram/TikTok profile data we read (username, avatar, and TikTok's allowed privacy and interaction settings) is used only to show you which account you're posting as and to build a compliant post request.
- You can disconnect at any time in the editor (Share → Post → Disconnect), which deletes the stored tokens. You can also revoke Morpha's access from your Instagram or TikTok account settings.
- Our use of Instagram data complies with the Meta Platform Terms and Developer Policies; our use of TikTok data complies with the TikTok Developer Terms of Service.
We do not sell your personal information. We share data only with service providers who help us run Morpha, and only as needed:
- Cloudflare hosts Morpha, stores your projects and media, runs server renders, delivers content, sends account email, and runs its Turnstile bot check when you sign up, reset a password or start a guest session.
- Stripe processes subscription payments.
- Google provides Google sign-in and Google Analytics (see Cookies), serves the fonts on some of our pages and many of the fonts you can use in your projects, and runs the Gemini models. When you ask the assistant to look at, edit or create an image, the image or your description of it goes to Gemini.
- OpenRouter runs the assistant's language models. It receives your prompts and the project information the assistant reads, and passes each request to a host for the model in use. For the DeepSeek models, the preferred hosts are DeepInfra, StreamLake, GMICloud, Baidu, DigitalOcean and Fireworks, and OpenRouter can use another of its hosts when none of those is available. The Gemini models run at Google.
- Openverse receives the words of an image search that Morpha's assistant or software development kit runs from your device.
- Bunny Fonts, Fontshare and jsDelivr serve some of the fonts you can use in your projects, so your browser requests a font from one of them when a project uses it.
- Meta / Instagram and TikTok receive the content you schedule, to publish it.
- AI assistants you connect receive what Morpha returns to their requests. The company that provides the assistant, such as Anthropic for Claude or OpenAI for ChatGPT and Codex, handles that information under its own privacy policy.
We may also disclose information if required by law or to protect the rights, safety, and security of Morpha and its users.
Data retention and deletion
We keep your account data and projects while your account is active. Disconnecting a social account deletes its stored tokens immediately. Deleting your account removes your projects, uploaded media, and connected-account tokens. It also removes your API keys, your scheduled posts and your AI usage log, and it cancels any subscription you have. Stripe keeps its own records of you as a customer and of your payments, under Stripe's privacy policy. A project you have shared with other people by email, or allowed to be embedded on a website, is kept when you delete your account, so the people using it keep access. You can delete your account yourself in Settings, under Danger zone, or email hello@morphareels.ai and we will delete it for you. Step-by-step instructions, including what happens when you remove Morpha from Instagram's or TikTok's own settings, are on Delete your data.
Deleting your account does not remove your daily activity records or your server render records, which are deleted on the schedule below. It also leaves your membership of any workspace in place, with your name, email address and role there. A workspace's owner or an admin can remove a member, and its owner can delete the workspace.
Transcripts and recognised text stay beside their clip or image until you delete its project or your account. These records are kept for a fixed period:
- An anonymous account that nobody claims is deleted 30 days after it was created.
- The counter that limits anonymous account creation from an IP address is deleted after 2 days with no attempt from that address.
- A server render's MP4 is deleted 7 days after the render finishes. Its record is deleted 37 days after the file is deleted, or 37 days after the render fails.
- Each day's entry in the AI usage log is deleted 90 days after that day's last AI request.
- Each daily activity record is deleted 540 days after the day it records.
- An API key created for an AI assistant does not expire. It lasts until you revoke it or delete your account.
Each plan includes a storage allowance for the clips, images, audio and project data you keep with us (the figure for your plan is shown on the pricing page and in your account settings). When an account is at its allowance, new uploads are declined until you free space or move to a plan with more; nothing you have already stored is deleted for being over the allowance. An upload that starts but never completes is removed after 24 hours.
Your rights
Depending on where you live, you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing (including rights under the GDPR and CCPA). You can exercise these rights in the app or by emailing hello@morphareels.ai. We will not discriminate against you for exercising them.
Security
We protect your data with encryption in transit, scoped access to storage, and signed, expiring credentials for media access. No method of transmission or storage is perfectly secure, but we work to protect your information and to respond promptly to any incident.
Cookies
We use a cookie that keeps you signed in, or keeps your guest session when you use Morpha without an account, and a short-lived cookie that protects Google sign-in. We do not use advertising cookies.
On morphareels.ai, Google Analytics sets cookies that help us understand how Morpha is used. If you are in the European Economic Area, the United Kingdom or Switzerland, it sets them only after you choose Allow in the consent banner, and until then it still counts page visits without cookies. Everywhere else, it is on when the page loads.
Your browser's local storage keeps your consent choice, your conversation with the editor's assistant for each project, and a record of how you first arrived at Morpha: the referring site, any campaign tag in the link, and the page you landed on. When you create an account, we save that first-visit record with it.
Children
Morpha is not directed to children under 13 (or the minimum age in your country), and we do not knowingly collect their data.
International transfers
Morpha is operated using infrastructure that may process data in countries other than yours. Where required, we rely on appropriate safeguards for such transfers.
Changes to this policy
We may update this policy from time to time. Material changes will be reflected by a new "Last updated" date at the top of this page.
Questions or requests: hello@morphareels.ai.