Privacy Policy

Last Updated: June 2026

MorningHQ, Inc. (“MorningHQ,” “we,” “our,” or “us”) provides an AI-powered context layer for product teams. We connect to tools like Gmail, Slack, Jira, Confluence, GitHub, Google Calendar, HubSpot, and Zoom to produce a morning brief, meeting prep, response-gap tracking, and AI agents (called Dawn) that handle research-heavy work like PRDs, churn reports, and competitive analysis.

This Privacy Policy explains how we collect, use, and protect personal information when you use our website, dashboard, or any other service that references this policy (collectively, the “Services”).

1. The Short Version

  • We collect what we need to run the product, keep it safe, and bill you. Nothing more.
  • We do not train AI models on your data.
  • We do not sell your data or share it for advertising.
  • Your connected accounts, emails, messages, and meeting context are processed to power features you enable. You can disconnect any integration at any time.
  • In production, AI requests are processed through Amazon Bedrock using Anthropic models, under enterprise terms that prohibit training on your content.
  • SOC 2 Type 1 is in progress, targeted within 90 days. Encryption in transit and at rest, today.
  • Questions: support@morninghq.ai

2. Information We Collect

Information you provide directly

  • Account and profile information. Name, work email, company, role, timezone, workspace, and onboarding preferences. Authentication (including credentials) is handled by our authentication provider, Clerk; MorningHQ stores only the account and profile information needed to operate the product.
  • Billing information. Payments are processed by Lemon Squeezy. MorningHQ stores billing records associated with your account (such as plan, status, and invoices); your payment instrument is handled by Lemon Squeezy under its own privacy practices.
  • Workspace content. Anything you type into MorningHQ — queries to Dawn, notes, tags, saved views, agent instructions, and feedback.
  • Support correspondence. Messages you send us via email, chat, or in-product feedback.

Information from connected integrations

When you connect an integration, MorningHQ ingests the records you authorize it to access. Depending on which integrations you enable, this can include:

  • Gmail. Email messages, threads, attachments, sender and recipient data, labels.
  • Slack. Messages in channels and DMs you grant access to, user profiles, channel metadata.
  • Google Calendar. Events, attendees, meeting links, descriptions.
  • Jira. Issues, comments, status changes, assignees, projects.
  • Confluence. Pages, comments, and spaces you authorize.
  • GitHub. Repositories, issues, pull requests, and comments within scopes you grant.
  • HubSpot. Contacts, companies, deals, and activity history.
  • Zoom. Meeting metadata and bounded meeting context (such as summaries or excerpts) where you've connected Zoom and granted access.

You control which integrations are connected and can disconnect any of them at any time from Settings → Integrations. Disconnecting an integration revokes our access and stops new ingestion. Deletion of previously ingested content can be requested at support@morninghq.ai; see Section 7 for our retention practices.

Information about other people

By design, the data you connect contains information about other people — your colleagues, customers, prospects, and meeting participants. You are responsible for ensuring you have the right to share this information with MorningHQ under your organization's policies and applicable law (including, where relevant, all-party consent for call recordings, transcripts, or AI note-taking). MorningHQ processes this information solely to provide the Services to you.

Information collected automatically

  • Usage data. Pages viewed, features used, query history, session duration, agent runs.
  • Device data. Browser type, OS, IP address, device identifiers.
  • Cookies and similar technologies. Authentication, preference, and product-analytics cookies (or similar technologies). We do not use advertising cookies. Specific analytics tooling depends on environment configuration.

3. How We Use Information

We use the information described above to:

  • Operate, maintain, and secure the Services.
  • Ingest content from your connected tools and synthesize it into briefs, drafts, meeting prep, and agent outputs.
  • Authenticate you (via Clerk), bill you (via Lemon Squeezy), and provide customer support.
  • Send product updates, security alerts, and — where you've opted in or where permitted by law — marketing emails.
  • Improve the Services: debug issues, monitor performance, develop new features.
  • Comply with legal obligations and enforce our terms.

What we do NOT use your data for

  • We do not train foundation models on your content. In production, AI requests are processed via Amazon Bedrock using Anthropic models, under enterprise terms that prohibit using your content to train models.
  • We do not sell personal information.
  • We do not share your data with advertisers or use it for cross-context behavioral advertising.
  • We do not use your content to improve service for other customers without aggregation and de-identification.

4. How We Share Information

We share information only in these situations:

  • AI processing. In production, MorningHQ processes AI requests through Amazon Bedrock using Anthropic models. Relevant context from your workspace and connected integrations is sent to Bedrock to generate outputs. Bedrock and the underlying models operate under enterprise terms with no-training commitments and bounded retention; counsel may request the specific contractual terms in effect.
  • Service providers. Companies that help us run MorningHQ, including:
    • Amazon Web Services (AWS) — cloud hosting and infrastructure.
    • Amazon Bedrock — production AI model access (with Anthropic models).
    • Clerk — authentication.
    • Nango — integrations infrastructure.
    • Lemon Squeezy — payments and billing.
    Product analytics, observability/tracing, and web-search providers may be used depending on environment configuration. A current list of active subprocessors is available on request at support@morninghq.ai.

Each provider is bound by confidentiality and data protection obligations.

  • Your workspace. Content you create can be visible to other members of your MorningHQ workspace based on the roles and permissions you set.
  • Legal and safety. When required by law, valid legal process, or to protect the rights, property, or safety of MorningHQ, our users, or others.
  • Business transfers. If MorningHQ is involved in a merger, acquisition, or asset sale, your information may be transferred. We will notify you before your information becomes subject to a different privacy policy.

5. AI Processing & Agent Outputs

Dawn and other MorningHQ agents use large language models to read your context and produce outputs — briefs, drafts, summaries, reports, and follow-ups.

  • Outputs are generated from the inputs you connect and the prompts you provide.
  • Agent actions that send messages, modify external records, or share content require your explicit approval before they execute.
  • Outputs may include, reflect, or infer information from the inputs. They can be wrong. Review before acting on them.
  • For Deep Work, the “public” and “private” labels control which sources may be used to produce a report (e.g., public web sources versus your private workspace and connected integrations). They do not create a public link or make the report visible to your workspace unless a sharing feature is explicitly used.

6. Meetings, Calls, and Recordings

If you connect Zoom (or similar meeting tools), MorningHQ may process meeting metadata and bounded meeting context — such as summaries or excerpts derived from meetings you've granted access to. A few things to know:

  • We process this data only for meetings where you've granted MorningHQ access.
  • Many U.S. states and most non-U.S. jurisdictions require all-party consent before a call is recorded or transcribed (including by AI note-takers). You are responsible for obtaining the consents your jurisdiction requires.
  • Meeting context is used to power meeting prep, response-gap detection, and Deep Work agents within your workspace.
  • To request deletion of meeting-derived data, contact support@morninghq.ai.

7. Data Retention

  • Account data is retained while your account is active.
  • Connected integration data is retained while the integration is connected. After disconnection, we stop new ingestion immediately. Previously ingested content is retained according to environment-specific retention schedules; deletion of specific content can be requested at support@morninghq.ai.
  • Agent outputs (briefs, reports, drafts) are retained while your workspace exists, unless you delete them.
  • Backups and logs are retained according to environment-specific retention schedules and deleted or overwritten according to those schedules.

When you request account deletion, we will work with you to identify and remove personal information across the systems described above, subject to retention required for legal obligations, dispute resolution, billing records, and security purposes. Contact support@morninghq.ai to initiate a deletion request.

8. Security

  • Encryption in transit (TLS 1.2+) and at rest.
  • Scoped access controls — each user sees only the workspace and integrations they're authorized for.
  • Authentication delegated to Clerk; AI processing isolated through Amazon Bedrock.
  • Audit logging for sensitive operations.
  • Regular security reviews and dependency scanning.
  • SOC 2 Type 1 in progress, targeted within 90 days. SOC 2 Type 2 to follow.

No system is perfectly secure. If we become aware of a security incident affecting your personal information, we will notify you as required by applicable law.

9. Your Rights and Choices

Depending on where you live, you may have the right to:

  • Access the personal information we hold about you.
  • Correct inaccurate information.
  • Delete your personal information.
  • Export your data in a portable format.
  • Object to or restrict certain processing.
  • Withdraw consent where processing is based on consent.
  • Lodge a complaint with your local data protection authority.

To exercise any of these rights, email support@morninghq.ai. We will respond within the timeframe required by applicable law (typically 30 days). We may need to verify your identity before fulfilling the request.

Marketing emails. You can unsubscribe at any time via the link at the bottom of each message. We will still send essential service emails (security alerts, billing, account changes).

10. International Transfers

MorningHQ is based in the United States. If you access the Services from outside the U.S., your information will be transferred to, stored in, and processed in the U.S. and other countries where our service providers operate. Where required, we use Standard Contractual Clauses or other approved mechanisms to safeguard international transfers.

11. Children

The Services are not directed to children under 16. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact support@morninghq.ai and we will delete it.

12. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email (if you have an account) or by posting a notice on our website at least 14 days before the changes take effect. The “Last Updated” date at the top reflects the most recent revision.

13. Contact Us

MorningHQ, Inc.
San Francisco, California
Email: support@morninghq.ai

For questions about this policy, data requests, or privacy concerns, email us and we'll respond promptly.

← Back to MorningHQ