Morph Policy

Morph Privacy Policy

This product-specific policy explains how Morph handles account, AI prompts, mobile, support, and app-assessment access data.

Plain-language summary

Morph handles AI prompts and user data only to provide creative content generation, automation, safety, and operational reliability. It does not sell your AI prompt data.

1. Scope and Application

This Privacy Policy applies exclusively to Morph, an AI Studio platform operated by WMTAN. It governs the collection, use, and protection of data processed through the Morph web application, API integrations, automated workflows, and related support channels.

By using Morph, you acknowledge that you are interacting with an AI-driven service. This policy supplements the baseline WMTAN Master Privacy Policy by establishing specific guidelines for how we handle AI prompts, uploaded files, and generated content.

2. Information We Collect

We collect information necessary to operate your Morph account, such as your email address, profile details, and authentication credentials. Crucially, we collect the AI prompts you enter, the files or images you upload for analysis, and the resulting AI-generated content (AIGC).

We also collect standard device metadata (such as IP address, browser type, and operating system) and app activity logs to ensure platform security, troubleshoot performance issues, and prevent abuse.

3. How We Use Your Data

Your data, including AI prompts and uploaded files, is used strictly to provide the requested AI capabilities. We use this information to generate responses, maintain your workflow history, and support account safety.

WMTAN does not sell your AI prompts, generated content, or account details to any data brokers, advertisers, or other third parties.

4. Third-Party AI Models and Processors

To provide advanced AI capabilities, Morph integrates with industry-leading third-party AI foundation models (such as Google Gemini, OpenAI, or Anthropic). When you submit a prompt, the necessary data is securely transmitted to these providers solely for the purpose of generating a response.

These providers act strictly as data processors. They are bound by enterprise agreements that prohibit them from using your prompts for their own advertising or profiling purposes.

5. AI Training and Data Opt-Outs

WMTAN operates on a strict 'opt-in for training' philosophy. We DO NOT use your personal data, uploaded files, or private AI prompts to train or fine-tune our underlying foundation AI models without your explicit consent.

Likewise, our enterprise agreements with third-party AI providers strictly prohibit them from using your Morph inputs to train their public-facing models. Your data remains siloed and is used solely to fulfill your immediate requests.

6. Security Measures and Sensitive Data

WMTAN employs industry-standard security protocols to protect your data. All data transmitted between your device and Morph servers is encrypted in transit using TLS/HTTPS, and data stored on our infrastructure is encrypted at rest.

Despite these protections, you must exercise caution. You should NEVER input highly sensitive personal information—such as passwords, full credit card numbers, or protected health information—into AI prompts, as AI outputs can occasionally reproduce inputs unpredictably.

7. User Rights (GDPR & Global Standards)

Users residing in the EU/EEA and other applicable jurisdictions possess specific rights regarding their personal data. You have the right to access, rectify, restrict, or object to the processing of your data.

Morph provides tools for you to export your data and request permanent erasure. If our processing relies on your consent, you may withdraw that consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.

8. Data Retention and Account Deletion

We retain your Morph data, including prompt history and saved workflows, for as long as your account remains active. You can manually delete specific workflows or prompts directly within the application.

If you initiate a full account deletion request, your personal data and prompt history will be permanently purged from our active production databases within 30 days, and from encrypted backups within 90 days, barring any legal obligations that require extended retention.

CategoryExamplesPurposeControls
Account dataEmail address, profile name, account ID, authentication status, account settings.Create and secure the account, sync records across sessions, provide support, and process deletion requests.Users may update account information where supported and request account deletion.
AI Prompts and ContentUser prompts, uploaded files for AI analysis, generated text/images, and history.Provide requested AI generation, workflow automation, and history access.Users control what they enter and may request export or deletion of eligible records.
Device and app dataDevice identifiers, app version, operating system, diagnostics, crash data, notification tokens.Operate notifications, troubleshoot reliability, improve security, and maintain app performance.Users can manage notification permissions and device-level permissions through system settings.
Support contentMessages, screenshots, issue descriptions, account verification details, support history.Respond to user requests, investigate safety or account issues, and document support outcomes.Support records may be retained for audit, abuse prevention, and legal compliance where needed.

User controls and assessment information

  • The privacy policy is publicly accessible without signing in.
  • The policy identifies product-specific Morph practices and supplements the baseline WMTAN policy.
  • Users can request deletion through the public Morph data deletion page.
  • Sensitive requests may require account-ownership verification before disclosure, export, or deletion.
  • Permissions are described by purpose and can be managed through device settings.

Data Safety and permission alignment

  • If Morph collects or transmits data off device through the app, WebView, SDKs, or service providers, that behavior must be reflected in the Play Console Data safety form.
  • AI Prompts, files/photos, notifications, diagnostics, and support records should be declared accurately if the app or SDKs actually process them.
  • Morph does not sell personal data or AI prompts.
  • Android permissions must match this policy, the manifest, runtime permission flows, and the live feature set.
  • Export, deletion, or disclosure requests involving sensitive data may require account-ownership verification before processing.
  • If new analytics, AI, crash reporting, payment, notification, or storage SDKs are added, this policy and the Data safety form should be checked before release.

Contact

For privacy questions, data export requests, account deletion requests, or safety concerns, contact support@wmtan.com. Last updated: June 13, 2026.