Privacy policy

Last updated: 18 September 2026

This policy covers MoriDeck, Photomori, Vectormori, Pixelmori, Documori, Slidemori, Flipmori, Wavemori and Videomori, including the MoriDeck account and cloud services. MoriDeck is an Australian business. “We” means the operator of MoriDeck.

Editing on your device

Opening and editing a local file normally happens in your browser. It does not upload the file to MoriDeck. If you choose cloud storage, connected storage or an online AI tool, the information needed for that feature leaves your device.

AppFeatureExternal processing
PhotomoriSelect Subject / Remove BackgroundProfessional AI mode sends an image of the content being processed to an external service. On-device modes do not upload the image.

When you use an online AI tool, the content needed for your request—such as an image, prompt or selected area—is sent to fal.ai[8] or Runpod[9] for processing. We also keep operational records needed to deliver results, manage credits and prevent abuse. MoriDeck does not use your content to train AI models.

Cookies and browser storage

The apps use cookies and browser storage for the purposes below. The exact storage used varies by app and browser.

What we storeWhere it is stored and when it leaves your device
App preferencesSettings such as language, theme and panel layout are generally kept in your browser’s local storage (localStorage). They stay on your device unless you are signed in and cloud preference syncing is active. Only supported settings sync to your account; device-specific settings and other local choices can remain local.
Document recoveryApps keep recovery copies or editing checkpoints in browser storage, usually a browser database (IndexedDB), to help recover work after a crash. The recovery feature does not upload this data, even for documents opened from cloud storage. Saving or sharing a recovered document is a separate action. Recovery does not replace saving your work.
Fonts and other librariesDownloaded fonts and imported resources, such as brushes and presets, are generally kept in a browser database (IndexedDB) for reuse. These local libraries are not automatically uploaded when you sign in. Downloading a font or other resource does contact its hosting service.
Offline app filesThe browser’s cache stores app code, images and other downloaded resources so apps can load faster and work offline. These copies stay on your device; fetching or updating them contacts our servers or resource providers.
Sign-in and session dataThe account service uses cookies to keep you signed in and help secure your session. Unlike local editing data, these cookies are sent to the account service when needed. Short-lived editor sign-in tokens are kept in memory rather than saved in local storage.

You can remove local data through the app’s storage controls, where available, or your browser settings. Clearing browser data can remove preferences, recovery copies and unsaved work, and may sign you out. It does not delete cloud files or settings already synced to your account.

Accounts and cloud features

If you create an account, we handle your email address, sign-in details and account settings. A sign-in provider may give us your identity and profile details. Cloud features also handle the files you save, file names and versions, connected-storage permissions, and settings you sync. We use this information to provide those features and manage your account. You can disable cloud features for an individual app from that app’s Preferences. While they are disabled, the app will not connect to MoriDeck account or cloud services. Disabling them does not delete information already stored in the cloud.

Sign-in providerInformation received
GoogleAccount ID, email address and basic profile details; email verification status and Workspace domain, if supplied.
GitHubAccount ID, email address and basic profile details.
MicrosoftAccount ID, email address and basic profile details.

We keep the provider name and account ID to link your sign-in, and use your email address for your MoriDeck account. Additional profile details and provider access tokens are not saved. We do not receive your provider password. Connecting cloud storage is separate and has its own permissions.

Information inside your files

Files you upload or share can contain personal information, including information about other people. They may also contain hidden details, such as author names or the location where a photo was taken. These details can travel with the file when you upload or share it. If you upload or save a file to MoriDeck Cloud, the file and any personal information or metadata it contains is sent to and stored by the cloud services described below.

Connected storage

If you connect storage such as Google Drive[5], Dropbox[6] or Microsoft OneDrive[7], MoriDeck handles file listings and transfers through its servers and stores encrypted connection credentials. The permissions you grant may cover more than the file you open; Google Drive[5] connections request broad Drive access so we can browse existing files. A storage manager can disconnect the service in the account’s storage connection settings. You can also withdraw access through the provider. Disconnecting does not delete files already copied into MoriDeck or files held by the provider.

Sharing and team accounts

Files in a team account are accessible according to that account’s permissions, which its managers control. If you create a sharing link, people who receive or are forwarded the link may access the shared file, subject to the link’s restrictions. Revoking a link or removing someone’s access cannot remove copies they have already downloaded.

Payments

Stripe[3] processes payments. Payment details you enter at checkout go to Stripe[3]; MoriDeck does not receive your full card number. We receive billing and transaction information needed to manage purchases, subscriptions, credits and refunds, and to keep required business records.

Visits, analytics and advertising

We use Cloudflare[4] Web Analytics to understand visits and site performance. It does not use analytics cookies or fingerprint visitors. Separately, servers and service providers process technical information such as IP addresses, request times and errors to deliver and protect the services. We have not appointed a third-party advertising provider. If that changes, we will update this policy before introducing it.

Who else handles information

The main services that handle information for MoriDeck are listed below. If you connect an external storage or sign-in service, that service also handles the information needed for your connection. We may disclose information where required by law or needed to investigate abuse and protect the service. Your information may be stored or processed outside Australia, including in the United States. Other processing locations depend on the provider and the feature you use.

ServicePurposeInformation handled
DigitalOceanApplication hosting and temporary storageAccount data, server records and data temporarily held while a hosted service processes a request; hosted in the United States.
PostmarkAccount and service emailsRecipient email addresses, message contents and delivery information.
StripePaymentsPayment details, billing information and transaction records.
CloudflareWebsite analytics and cloud storageTechnical visit and performance information, plus cloud files and related storage metadata where Cloudflare R2 is used.
Google DriveOptional connected storageAccount identifier, connection permissions, file and folder details, and files you choose to access or save through MoriDeck.
DropboxOptional connected storageAccount identifier, connection permissions, file and folder details, and files you choose to access or save through MoriDeck.
Microsoft OneDriveOptional connected storageAccount identifier, connection permissions, file and folder details, and files you choose to access or save through MoriDeck.
fal.aiOptional AI processingContent submitted to an online AI feature and related request data.
RunpodOptional AI processingContent submitted to an online AI feature and related request data.

Protecting your information

We use HTTPS to protect information in transit and store connected-storage credentials in encrypted form. Access to cloud features is checked against account permissions. Cloud storage is not end-to-end encrypted: our servers and service providers process files as needed to deliver the features you use.

Keeping and deleting information

Local data stays on your device until you or your browser remove it. Cloud files may include previous versions and items in the trash; moving a file to the trash is not the same as permanently deleting it. Retention depends on the type of information and whether it is needed to provide your account and files, resolve support or security issues, or meet legal and accounting requirements. We have not yet set fixed automatic deletion periods for account records, logs and backups. Contact us to request deletion or ask what we still hold. Some information may need to be kept for legal, accounting or security reasons, and deletion from backups may take longer than deletion from the live service.

Your choices and privacy questions

You can use local editing without an account. Online features need the information described above to work. To ask what personal information we hold about you, request access, correction or deletion, or make a privacy complaint, email [email protected]. We may need to verify your identity. We will respond within a reasonable time and may refuse or limit a request where permitted or required by law.

Changes to this policy

We will update this page when our practices change and show the updated date. For significant changes affecting your information, we will also give notice through the website, apps or email where appropriate.

Email MoriDeck about privacy