Privacy Policy
Last updated: July 17, 2026
1. Overview
This policy describes what Morrowset(the “Service”), operated by its individual owner (the “Operator”), collects about you and how it is used. The Service is an invite-only beta for event planners and designers; this policy aims to reflect what the product actually does today, not boilerplate.
2. What we collect
- Account information — your email address, display name, and a hashed version of your password (the password itself is never stored).
- Content you create — images you upload, the projects, events, looks, and lookbooks you assemble, the design descriptions you write, and the AI-generated mockup images produced for you.
- Usage data — product analytics about how the Service is used (pages visited, features used, and basic device/browser information).
- Technical logs — request metadata such as IP address and error details, used for security (e.g. rate limiting) and debugging.
3. How we use it
Your data is used to operate the Service (generate mockups, assemble and serve lookbooks), to secure it (abuse prevention, rate limiting), to improve it (aggregate usage analytics), and to send you transactional account email such as password resets. There is no advertising and your data is never sold.
4. AI image generation
When you generate a mockup, your written description, the images you selected for that look — including any images you uploaded — and the names you gave those uploads are transmitted to a third-party AI image service (Google Gemini or OpenAI) to produce the mockup. These processors handle that data under their own terms to fulfill the request. The generated images are stored in the Service’s media storage as part of your account.
5. Third-party processors
The Service runs on the following third-party processors:
- Google (Gemini) and OpenAI— AI image generation, as described above. Gemini also computes the text embeddings behind asset suggestions: short text derived from your event’s theme, style, and notes is sent to Google’s embedding API to find matching catalog assets.
- Render — application hosting; Neon — database hosting; Cloudflare R2 — media (image) storage.
- PostHog — product analytics.
- Postmark — transactional email delivery. Postmark retains message metadata and full message content for about 45 days, including any links those emails contain; account-security links (such as password resets) are short-lived and single-use, so a retained link expires long before that window ends.
- GitHub— in-app feedback handling. When you submit feedback through the Service, your message is filed in the Operator’s private issue tracker along with your name, email address, and technical context (the page you were on, browser details, recent errors) so the Operator can follow up.
6. Cookies
The Service uses essential cookies to keep you signed in, plus a scoped cookie to serve images for password-protected shared lookbooks. Usage analytics are collected server-side (PostHog) — the Service places no analytics or advertising cookies in your browser.
7. Sharing
Your content is private to your account. It leaves the Service only through the processors listed above and through the lookbook share links you create yourself — anyone with a share link (and its password, if you set one) can view that lookbook. Data may also be disclosed if required by law.
8. Retention and deletion
Your content is retained while your account is active. There is no self-serve deletion yet: to delete your account or specific content, contact the Operator (see Contact below) and the deletion will be handled for you. Routine database backups exist for disaster recovery, so deleted data may persist in backups for a limited period before aging out.
9. Security
Passwords are stored only as strong one-way hashes, media access is authenticated (uploads and mockups are never public files), and lookbook share links are private URLs with optional passwords. No online service can guarantee perfect security, but the Service is built so that your content is only reachable through your account or the share links you create.
10. Children
The Service is a professional tool and is not directed at children under 16. Do not use the Service if you are under 16.
11. Changes to this policy
This policy will be updated as the product changes — for example when a processor is added or replaced. Material changes will be communicated through the Service.
12. Contact
Privacy questions and deletion requests: use the in-app feedback tool, or reply to the invitation email you received for the beta.