Your mail stays yours.
MorningZero touches some of your most sensitive data, so we hold it the way we'd want ours held: minimum access, encrypted, never sold, and gone the moment you say so.
Least-privilege OAuth
Gmail and Outlook connect through Google and Microsoft's own OAuth screens — we never see or store your password for them, and you can revoke MorningZero's access from your provider at any time.
App passwords, for providers without OAuth
Some providers — Yahoo, iCloud, Fastmail and similar — offer no OAuth for mail, only an app-specific password you generate in their settings. Connecting one of those means we hold that password: encrypted with AES-256-GCM under its own encryption secret, separate from the one protecting our OAuth tokens, never logged, never returned by our API, and permanently deleted the moment you disconnect the mailbox. Gmail and Outlook never use this path, and MorningZero will refuse a Gmail or Outlook address here and send you to the OAuth screen instead.
Encrypted in transit and at rest
All traffic is encrypted in transit with TLS. Your OAuth tokens, app passwords, cached message bodies and any message queued for sending are encrypted with AES-256-GCM before they're written, and the storage our database sits on is encrypted at rest by our infrastructure provider. Access to the systems that run your account is restricted to a private network with key-based authentication. Connections to mail servers require TLS too — we never fall back to an unencrypted session.
Never trained on your email
We do not use the content of your mail to train general-purpose AI models. The model providers that process it act as our processors and are contractually bound not to train on it — we pay for the tiers where that's the deal, because some free tiers let the provider learn from what you send. Your corrections tune labeling for your own account.
We don't hoard your inbox
The mail we read from your provider isn't kept: bodies are processed transiently, never written to our database, and the encrypted cache that makes a reopened message instant expires in about ten minutes. What we do store is what the features need — subjects, senders, labels, timestamps, previews, AI summaries and the search vectors built from them, plus the things you create here: drafts, messages queued to send, and your conversations with the assistant. The desktop app also keeps a local copy of recent mail on your own device, protected by your OS rather than encrypted by us.
Delete anytime
Delete a single conversation with the assistant, disconnect a mailbox, or delete your account — all from inside the app. Disconnecting a Google mailbox revokes the grant with Google and purges what we derived from it, including the labeling rules learned from that mailbox; on account deletion we remove your stored mail content and access tokens. You also choose how much history is imported.
No ads. No selling.
Your mail is never sold, never shared with advertisers, and never used for ad targeting. Our use of Google and Microsoft data follows their Limited Use requirements — full stop.
What we access — and why
We ask only for the scopes the features you use actually need. Here's the whole list.
Compliance
MorningZero's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Microsoft mail and calendar data accessed through the Microsoft Graph API is held to the same restrictions.
Wherever you live, you can ask what data we hold, have it corrected, get a copy, or delete it — we extend those rights to every user, not only where a law requires them. Email us to exercise any of them. Full detail lives in our Privacy Policy and Terms.
Found a vulnerability?
We take reports seriously and respond promptly. Email support@morningzero.com with the details and steps to reproduce — please give us a chance to fix it before disclosing publicly.
Get started