morphto

Privacy Policy

Last updated: 19 July 2026

MorphTo (“we”, “us”) operates morphto.app. This policy explains what data we collect when you visit the site, morph a file, or contact us, and how we handle it.

Current status

The morphto website is a file-anatomy explorer. Dropping a file on it morphs the file inside your browser: the bytes are read into browser memory, parsed there, and never sent anywhere. There is no user account and no file-upload form. The contact form is the only place you send us anything, and it sends only what you type into it. This policy also describes how we will handle data once accounts and the hosted conversion service go live, so it stays accurate as we ship.

Morphing a file

Morphing happens entirely inside your browser. Your file is read into browser memory, parsed there, and the tree you explore is built from that memory. No request carries the file's bytes, its name or its contents to us or anyone else, and nothing about the file is stored. Exports are assembled locally and handed to your browser as an object URL. Reload the page, or press Reset, and the bytes are gone.

Contacting us

If you email us or use the contact form, we receive your email address and message content through our mailbox provider. We use this only to respond and do not add you to any marketing list without a further opt-in.

File conversions (once live)

When the conversion API and app are live, files you upload for conversion are processed transiently: they are held only for the duration of the conversion job and are deleted immediately afterwards. We do not use uploaded files to train models, and we do not share file contents with third parties other than the infrastructure subprocessors below strictly necessary to perform the conversion. We will update this section with concrete retention windows before the conversion API accepts real traffic, and will not change this no-retention commitment without prominent notice on this page.

Accounts and authentication

Account sign-in (planned via Google OAuth and email/password) will be handled by Clerk, our authentication provider. Clerk processes your email address, name (if provided), and authentication metadata under its own privacy policy, available at clerk.com/legal/privacy.

Subprocessors

We use the following subprocessors to run MorphTo:

Your rights under UK/EU GDPR

You have the right to access, correct, export, or delete personal data we hold about you. Once accounts launch, account deletion and data export will be available directly from your account settings. Until then, or for any request today, email [email protected] and we'll action it promptly.

Data retention

Files you morph in the browser are never sent to us, so there is nothing for us to retain. Emails you send us are kept only as long as needed to respond to you. Files uploaded to the hosted conversion API are never retained beyond the job. Account data (once launched) is kept for as long as your account is active, and deleted on request or account closure, subject to any legal retention obligations.

International transfers

Our subprocessors may process data outside your home country (Vercel operates a global edge network; Nhost's primary region for MorphTo is Frankfurt, Germany). Where data leaves the UK/EEA, we rely on the subprocessor's own adequacy mechanisms (e.g. Standard Contractual Clauses).

Changes to this policy

We'll update this page as MorphTo's features ship, and update the “last updated” date above whenever we make a material change.

Contact

Questions about this policy or your data: [email protected].