Privacy Policy
Last updated August 16, 2026
This policy explains what data MorningZero collects, why, and the choices you have. MorningZero is operated by Serveka Technologies ("Serveka", "we", "us").
We have tried to write this so you can verify it, rather than asking you to take a badge on trust. Where we make a claim about how the product works, it is a claim about something we do — not a legal status we have declared for ourselves.
1. Who we are
MorningZero is an AI email assistant operated by Serveka Technologies, based in Jaipur, Rajasthan, India. It connects to your mail accounts to label, search, answer questions, and draft replies.
For any privacy question, contact us at support@morningzero.com.
2. What we never do
- We never sell your data. Not to data brokers, not to anyone.
- We never use your mail for advertising. We run no ad products and share nothing with ad platforms.
- We never train generalized AI models on your mail. Not us, and not our AI providers. We use paid service tiers with model training disabled, specifically because free tiers of some AI services permit the provider to learn from submitted content.
- We never ask for your Gmail or Outlook password. Those accounts connect through OAuth only, and we refuse password entry for them.
- We never read your mail as a company. Automated systems process it. The four narrow exceptions where a person may see content are listed in Section 9.
- We never keep a copy of the mail we read from your provider. Message bodies we fetch are not written to our database. What is stored is the content you create inside MorningZero — see Section 4, which explains the difference honestly.
3. Information we collect
- Account information — your name, email address, and authentication identifiers when you sign in. If you use our mobile or desktop apps, we issue and store a long-lived token for that device so you stay signed in.
- Mailbox access tokens — OAuth tokens for the mail accounts you connect (e.g. Gmail or Outlook). Tokens are encrypted at rest with AES-256-GCM and used only to access your mail on your behalf.
- App-specific passwords — non-Google, non-Microsoft mailboxes only — Gmail, Google Workspace, Outlook and Microsoft 365 mailboxes always connect through OAuth, and we never ask for, receive or store a password for them; if you enter such an address on the app-password screen we refuse it and send you to the provider's OAuth consent screen instead. Providers that offer no OAuth for mail (for example Yahoo, iCloud, AOL, Fastmail, GMX or Zoho) require an app-specific password that you generate in their own settings. We store it encrypted with AES-256-GCM under a separate encryption secret from the one protecting our OAuth tokens — not merely a different salt — use it only to synchronise your mail and send on your behalf, and delete it immediately and permanently when you disconnect that mailbox. It is never logged, never returned by our API, and never shared. You can revoke it at any time from your provider's settings.
- Email metadata — message subjects, senders, recipients, thread identifiers, labels, timestamps, short previews (snippets), AI-generated summaries, and vector embeddings computed from each message's subject together with its AI summary or preview text. These embeddings are numeric representations that power search and labeling, and they are stored in our database.
- Message bodies — handled as described in Section 4.
- Search queries — the text you type into semantic search is converted into a vector by our embedding provider so it can be matched against your mail (Section 7).
- Attachments — we show the name and type of files attached to a message. When you ask a question that needs an attachment's contents, we fetch that file and extract its text so the assistant can read it; that text exists only in memory for the duration of your request. Attachments you add to a message you schedule for later sending are stored until that message is dispatched (Section 4).
- Your conversations with the assistant — when you ask questions about your mail, we store the conversation: your questions, the assistant's answers, and the intermediate steps it took. Because answers quote and summarize your mail, this history contains message content. It is retained per account so you can return to earlier conversations, and you can delete it.
- Personalization state — counters, signals and learned rules describing how you handle mail from particular senders and threads (for example that you consistently archive a sender, or a labeling correction you made), used to tune labeling and triage for your account only.
- Notifications — in-app notifications and push notifications may include a message's sender, subject and a short preview. We store the device tokens needed to deliver push notifications.
- Calendar data — your events are read from Google Calendar or Microsoft Graph each time you open the calendar, and are not stored on our servers. The one exception is an event you create in MorningZero that could not be written through to your provider: we keep it (title, time, location, description, attendees, recurrence) so the event is not lost, and delete it when you disconnect the mailbox.
- Usage and billing records — logs, device/browser information, feature usage, and a ledger of usage against your plan. If you purchase a paid plan, payments are handled by a third-party payment processor; we do not store full card numbers.
- Feedback — anything you send us through in-app feedback.
4. Message bodies: what we keep and what we don't
This deserves its own section because a single sentence would be misleading.
Mail we read from your provider is not stored in our database. When MorningZero labels, summarizes or answers questions about a message, it fetches the body, processes it, and does not write it to the database. A short-lived encrypted cache holds recently-opened bodies so that reopening a message is instant; entries expire automatically after about ten minutes.
Content you create inside MorningZero is stored, because the feature requires it:
- Drafts — a reply you or the assistant drafts is stored until you send or delete it.
- Scheduled sends — a message you schedule for later, including its subject, body and any attachments, is stored until it is dispatched, then removed.
- Assistant conversations — as described in Section 3.
- Notification text — sender, subject and preview, as described in Section 3.
Things derived from your mail are stored. Subjects, snippets, AI summaries and the vector embeddings computed from them live in our database for as long as the message does. "We don't store bodies" is a statement about the full text of your messages, not about everything derived from them.
On your own devices. If you install our desktop app, it keeps a rolling local copy of recent messages, including full bodies, in a local database file so mail loads instantly and works offline. That file is not separately encrypted by MorningZero; it is protected by your operating system account and any full-disk encryption you have enabled. Uninstalling the app or deleting its data removes the copy.
5. How we use your data
- Provide user-facing features: AI labeling, search, plain-English Q&A over your mail, calendar viewing and scheduling, and reply drafting and sending at your direction.
- Personalize labeling for your account: your in-app actions (such as correcting a label, replying, or archiving) are used as feedback signals to tune how your own mail is labeled. These signals are scoped to your account and are not used to train models that serve other users.
- Improve those same user-facing features, and operate, secure, and debug the service.
- Communicate with you about your account and support requests.
We do not sell your data, we do not use it for advertising or ad targeting, we do not use it to determine creditworthiness or for lending purposes, and we do not use the content of your email to train generalized AI or machine-learning models.
6. Why we are allowed to process each thing
| What we process | Why we are permitted to |
|---|---|
| Mailbox contents, for labeling, search, Q&A, calendar and drafting | Necessary to deliver the service you signed up for and connected your mailbox to |
| Mail content and search queries sent to AI providers for those features | Necessary to deliver the same features; providers act only on our instructions |
| Logs, security and abuse signals, debugging data | Necessary to keep the service running and secure for everyone |
| Cookieless, content-free product analytics | Our legitimate interest in understanding which features are used |
| Billing and usage records | Necessary to take payment and to meet accounting and tax obligations |
| Anything optional you switch on | Your consent, which you can withdraw at any time |
We follow the principles of data minimisation and purpose limitation: we collect what a feature needs, and we use it for that feature.
7. AI processing
To label messages, answer questions, draft replies and power search, relevant content is sent to AI providers acting as our processors. They process it to return a result and are contractually bound not to use it to train their models. We use paid service tiers with model training disabled — free tiers of some AI services permit the provider to use submitted content to improve their products, and we do not use them for your data.
Language models. Google and Anthropic both process email content for labeling, summarization, reply drafting and assistant questions. Which one serves a given request depends on our configuration and availability at the time.
Embeddings. Voyage AI is our sole embedding provider. It converts each message's subject together with its AI summary or preview into a vector, and it also converts the text of any search you type so that query can be matched against your mail. Full message bodies are never sent to the embedding provider. These vectors exist solely to power search and labeling inside your own account and are not used to develop, train, fine-tune or improve generalized AI or machine-learning models.
8. Google API Services
MorningZero's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
What we request, and why
| Scope | What it lets us do | Why we need it |
|---|---|---|
gmail.modify | Read messages, change labels and read/archive state, manage drafts, and send on your behalf | Powers AI labeling, search, Q&A, triage actions, saving drafts to your Gmail account, and sending replies, rules and scheduled sends at your direction |
calendar.events | Read, create, update and respond to events | Showing your daily agenda, creating and editing events, and RSVPing at your direction |
openid, email, profile | Identify your account | Signing you in and associating your connected mailboxes with your MorningZero account |
We request no other Google scopes. We do not request gmail.readonly, gmail.send or gmail.compose separately, because gmail.modify is the single scope that covers the read, label, draft and send operations the product performs; requesting narrower scopes alongside it would not reduce the access granted.
We access your Gmail data and your Google Calendar events only to provide and improve user-facing features within MorningZero. We never use this data for advertising, and we do not transfer or sell it to third parties except as needed to provide those features, for security purposes, to comply with applicable law, or as described in Section 11 (Sharing and subprocessors) and Section 12 (Business transfers).
We do not use Google user data to develop, improve, train or fine-tune generalized AI or machine-learning models.
Note that RSVPs and event changes you make in MorningZero may notify the other attendees of that event.
You can revoke our access at any time by disconnecting the mailbox in MorningZero, or from your Google Account's third-party access settings. When you disconnect, we call Google's token revocation endpoint so the grant is withdrawn at Google's end too.
9. Human access to your data
MorningZero is designed so that your mail is processed by automated systems, not read by people. No Serveka personnel read the content of your messages, attachments or calendar events except in these limited circumstances:
- With your explicit consent — for example, when you ask our support team to look at a specific message or thread to diagnose a problem, and confirm that request.
- For security purposes — investigating a suspected security incident, abuse, or violation of our terms.
- To comply with applicable law — where we are legally required to access or disclose data.
- For internal operations on aggregated data — where data has been aggregated and de-identified, and is handled in line with applicable privacy and legal requirements.
Access under any of these grounds is limited to a small number of authorized personnel and to what the specific purpose requires. Our production servers are reachable only over a private network using key-based authentication, and administrative screens inside the product expose no message content at all — reaching message content requires direct database access on the server. We record authentication events for that server access. We do not maintain a separate audit log of individual message reads, and we would rather say so than imply a control we don't have. These limits mirror the human-access rules in the Google API Services User Data Policy, and we apply them to every connected mailbox regardless of provider.
10. Microsoft API Services
When you connect an Outlook or Microsoft 365 account, we access your Microsoft mail and calendar data through the Microsoft Graph API under the same restrictions that apply to Google data: only to provide and improve user-facing features within MorningZero, never for advertising, never sold, and never used to train generalized AI or machine-learning models. The human-access limits in Section 9 apply equally.
| Permission | Why we need it |
|---|---|
Mail.ReadWrite | Reading messages for labeling, search and Q&A; changing labels and read/archive state; managing drafts |
Mail.Send | Sending replies, rules and scheduled sends at your direction |
Calendars.ReadWrite | Showing your agenda, creating and editing events, and RSVPing at your direction |
openid, email, profile | Identifying your account and signing you in |
offline_access | Keeping your mailbox in sync without asking you to sign in repeatedly |
Microsoft offers no token revocation endpoint equivalent to Google's, so when you disconnect an Outlook or Microsoft 365 account we delete the stored tokens. You can also remove our access from your Microsoft account settings. Our use of Microsoft APIs is subject to Microsoft's applicable terms.
11. Sharing and subprocessors
| Subprocessor | Purpose |
|---|---|
| Oracle Cloud Infrastructure | Compute and storage hosting; our application and database run here |
| Cloudflare | DNS, edge network and the encrypted tunnel through which all traffic reaches our servers; terminates TLS |
| AI model processing for labeling, summarization, drafting and assistant questions (paid tier) | |
| Anthropic | AI model processing for the same features (paid tier) |
| Voyage AI | Embedding generation for messages and search queries (paid tier) |
| PostHog | Product analytics (no message content) |
| Lemon Squeezy | Payment processing |
| Resend | Transactional email |
| Expo, Apple, Google | Push notification delivery — notification text can include a message's sender, subject, and a short preview |
Each is bound by contract to use the data only to provide their service to us, and none is permitted to use it to train their own models. Our agreements with these providers incorporate their standard data protection terms, which include the European Commission's Standard Contractual Clauses for international transfers. We may also disclose data if required by law or to protect rights and safety.
Changes to this list. We will update this page before adding a new subprocessor that processes your mail content, and will notify account holders by email at least 30 days in advance. If you object to a new subprocessor, you may disconnect your mailboxes or delete your account before the change takes effect.
12. Business transfers
If Serveka is involved in a merger, acquisition, or sale of assets, data covered by this policy may be transferred as part of that transaction. Where the data includes information received from Google APIs, any such transfer will be made only with notice to affected users and their consent, as required by the Google API Services User Data Policy. We will post notice on this page and email account holders before any transfer takes effect.
13. Where your data is processed
Serveka Technologies operates from India. Our servers run on Oracle Cloud Infrastructure in the Mumbai region (ap-mumbai-1). Cloudflare operates a global edge network and traffic may pass through a point of presence near you.
Our subprocessors process data in the following regions: Google processes AI requests in the United States and other regions in which it operates, in accordance with its service terms; Anthropic in the United States; Voyage AI in the United States; PostHog in the United States; Resend and Lemon Squeezy in the United States.
Your data may therefore be processed in countries other than the one you live in. We protect data in transit and at rest wherever it is processed (see Section 15), and our subprocessor agreements incorporate Standard Contractual Clauses for cross-border transfers.
14. How long we keep your data
You control how much mail history is imported, and you can delete messages, disconnect a mailbox, or delete your account at any time.
| Data | Retention |
|---|---|
| Mail metadata, snippets, summaries, embeddings | Until you delete the message, disconnect the mailbox, or delete your account |
| Cached message bodies | About ten minutes; expires automatically |
| Drafts | Until you send or delete them |
| Scheduled sends, including attachments | Until dispatched, then removed |
| Assistant conversation history | Until you delete it or delete your account |
| Personalization signals and learned rules | Rules and signals learned from a specific mailbox: until you disconnect that mailbox. Settings and rules you set at the account level: until you delete your account. |
| In-app notifications | Until dismissed or the mailbox is disconnected |
| Push device tokens | Until you delete your account |
| OAuth tokens and app-specific passwords | Deleted immediately on disconnect or account deletion |
| Disconnected mailbox record | When you disconnect a mailbox we keep a minimal record that it was once connected: the mailbox address with a deactivation marker appended, and nothing else. No credentials and no mail data are retained. It is removed when you delete your account. |
| Operational and security logs | Written to standard output and retained only by our container runtime's rotation; we operate no central log store and keep no long-term log archive |
| Infrastructure backups | Automated block-storage snapshots on a daily, weekly and monthly cycle, with monthly snapshots retained up to twelve months. Deleted data persists in these snapshots until the relevant snapshot ages out. |
| Billing and usage records | Deleted with your account. Our payment processor retains invoice records independently, under its own legal obligations. |
| Feedback you send us | Until we have acted on it |
On disconnecting a mailbox. Disconnecting withdraws our access and deletes what we derived from that mailbox — messages, metadata, embeddings, drafts, scheduled sends, notifications, and the labeling and triage rules learned from that specific mailbox. Settings and rules you configured at the account level, which apply to every mailbox you connect, are kept for as long as your account exists so that disconnecting one mailbox does not disrupt the others. Everything is removed when you delete your account.
15. Security
All traffic is encrypted in transit with TLS. Connections to mail servers require TLS and we do not fall back to an unencrypted connection.
At rest, we encrypt your OAuth tokens, app-specific passwords, cached message bodies and scheduled sends with AES-256-GCM before they are written. App-specific passwords are protected by a separate encryption secret from the one used for OAuth tokens. Key material is held in our deployment's secret store rather than in the application database, encrypted values carry a key version so that keys can be rotated without data loss, and we maintain a documented key rotation runbook. The underlying block storage holding our database is encrypted at rest by our infrastructure provider.
Credentials and secrets are excluded from our application logs by an explicit redaction list, and our mail client library runs with its own logging disabled.
Access to production systems is restricted to a small number of authorized personnel over a private network with key-based authentication and, for message content, to the limited circumstances described in Section 9.
Incident response. If a security incident affects your personal data, we will notify you and the relevant authorities promptly — including, where the incident falls within the categories specified by India's CERT-In directions, within six hours of becoming aware of it — and will tell you what happened, what data was involved, and what we are doing about it.
No system is perfectly secure, but we work to protect your data and to respond promptly to incidents.
16. Your choices and rights
We extend the following rights to every MorningZero user, wherever you live — not only where a law requires it:
- Access — ask what personal data we hold about you.
- Correction — have inaccurate data corrected.
- Export — get a copy of your data in a portable format.
- Deletion — delete individual messages, assistant conversations, a whole mailbox, or your entire account, at any time, from inside the app.
- Withdraw consent — turn off any optional feature you previously enabled.
- Object — tell us to stop a particular use of your data, including our product analytics.
To exercise any of these, email support@morningzero.com. We respond within 30 days, and will tell you if a request is complex enough to need longer.
Depending on where you live, local law may give you additional rights, and may give you the right to complain to a data protection authority. Nothing in this policy limits those rights.
17. Grievance redressal
If you are not satisfied with how we have handled your data or your request, you can escalate to our Grievance Officer:
Grievance Officer: Manisha Prajapat
Email: manisha@morningzero.com
Address: Daulatpura, Jaipur, Rajasthan 303805, India
We acknowledge grievances within 7 days and aim to resolve them within 30 days.
18. Cookies and analytics
We use strictly necessary cookies to keep you signed in and to operate the app. For product analytics we use PostHog, configured so that it sets no cookies and no browser storage at all, with autocapture and session recording disabled, your IP address discarded on receipt, and no access to your mail. It records which features are used — counts, types and page visits — never message content. We serve our fonts from our own servers rather than a third-party font CDN.
We do not run advertising or marketing trackers on this site, and we share nothing with advertising platforms. Your mail is never used for advertising or ad targeting.
19. Children
MorningZero is not intended for anyone under 18, and we do not knowingly collect data from children. If we learn that we have collected data from someone under 18, we will delete it. If you believe a child has created an account, contact us at support@morningzero.com.
20. Who this service is offered to
MorningZero is operated from India and is offered in English, with pricing in US dollars. It is not directed at, or marketed to, individuals in the European Economic Area or the United Kingdom, and we do not target those markets.
21. Changes to this policy
We may update this policy from time to time. Material changes will be reflected by updating the "Last updated" date above and, where appropriate, by notifying you by email. Changes that expand how we use data received from Google APIs will be notified in advance.
22. Contact
Questions about this policy or your data? Email us at support@morningzero.com.