Privacy policy
Last updated: 18 September 2026
This policy covers MoriDeck, Photomori, Vectormori, Pixelmori, Documori, Slidemori, Flipmori, Wavemori and Videomori, including the MoriDeck account and cloud services. MoriDeck is an Australian business. “We” means the operator of MoriDeck.
Editing on your device
Opening and editing a local file normally happens in your browser. It does not upload the file to MoriDeck. If you choose cloud storage, connected storage or an online AI tool, the information needed for that feature leaves your device.
| App | Feature | External processing |
|---|---|---|
| Photomori | Select Subject / Remove Background | Professional AI mode sends an image of the content being processed to an external service. On-device modes do not upload the image. |
When you use an online AI tool, the content needed for your request—such as an image, prompt or selected area—is sent to fal.ai[8] or Runpod[9] for processing. We also keep operational records needed to deliver results, manage credits and prevent abuse. MoriDeck does not use your content to train AI models.
Cookies and browser storage
The apps use cookies and browser storage for the purposes below. The exact storage used varies by app and browser.
| What we store | Where it is stored and when it leaves your device |
|---|---|
| App preferences | Settings such as language, theme and panel layout are generally kept in your browser’s local storage (localStorage). They stay on your device unless you are signed in and cloud preference syncing is active. Only supported settings sync to your account; device-specific settings and other local choices can remain local. |
| Document recovery | Apps keep recovery copies or editing checkpoints in browser storage, usually a browser database (IndexedDB), to help recover work after a crash. The recovery feature does not upload this data, even for documents opened from cloud storage. Saving or sharing a recovered document is a separate action. Recovery does not replace saving your work. |
| Fonts and other libraries | Downloaded fonts and imported resources, such as brushes and presets, are generally kept in a browser database (IndexedDB) for reuse. These local libraries are not automatically uploaded when you sign in. Downloading a font or other resource does contact its hosting service. |
| Offline app files | The browser’s cache stores app code, images and other downloaded resources so apps can load faster and work offline. These copies stay on your device; fetching or updating them contacts our servers or resource providers. |
| Sign-in and session data | The account service uses cookies to keep you signed in and help secure your session. Unlike local editing data, these cookies are sent to the account service when needed. Short-lived editor sign-in tokens are kept in memory rather than saved in local storage. |
You can remove local data through the app’s storage controls, where available, or your browser settings. Clearing browser data can remove preferences, recovery copies and unsaved work, and may sign you out. It does not delete cloud files or settings already synced to your account.
Accounts and cloud features
If you create an account, we handle your email address, sign-in details and account settings. A sign-in provider may give us your identity and profile details. Cloud features also handle the files you save, file names and versions, connected-storage permissions, and settings you sync. We use this information to provide those features and manage your account. You can disable cloud features for an individual app from that app’s Preferences. While they are disabled, the app will not connect to MoriDeck account or cloud services. Disabling them does not delete information already stored in the cloud.
| Sign-in provider | Information received |
|---|---|
| Account ID, email address and basic profile details; email verification status and Workspace domain, if supplied. | |
| GitHub | Account ID, email address and basic profile details. |
| Microsoft | Account ID, email address and basic profile details. |
We keep the provider name and account ID to link your sign-in, and use your email address for your MoriDeck account. Additional profile details and provider access tokens are not saved. We do not receive your provider password. Connecting cloud storage is separate and has its own permissions.
Information inside your files
Files you upload or share can contain personal information, including information about other people. They may also contain hidden details, such as author names or the location where a photo was taken. These details can travel with the file when you upload or share it. If you upload or save a file to MoriDeck Cloud, the file and any personal information or metadata it contains is sent to and stored by the cloud services described below.
Connected storage
If you connect storage such as Google Drive[5], Dropbox[6] or Microsoft OneDrive[7], MoriDeck handles file listings and transfers through its servers and stores encrypted connection credentials. The permissions you grant may cover more than the file you open; Google Drive[5] connections request broad Drive access so we can browse existing files. A storage manager can disconnect the service in the account’s storage connection settings. You can also withdraw access through the provider. Disconnecting does not delete files already copied into MoriDeck or files held by the provider.
Sharing and team accounts
Files in a team account are accessible according to that account’s permissions, which its managers control. If you create a sharing link, people who receive or are forwarded the link may access the shared file, subject to the link’s restrictions. Revoking a link or removing someone’s access cannot remove copies they have already downloaded.
Payments
Stripe[3] processes payments. Payment details you enter at checkout go to Stripe[3]; MoriDeck does not receive your full card number. We receive billing and transaction information needed to manage purchases, subscriptions, credits and refunds, and to keep required business records.
Visits, analytics and advertising
We use Cloudflare[4] Web Analytics to understand visits and site performance. It does not use analytics cookies or fingerprint visitors. Separately, servers and service providers process technical information such as IP addresses, request times and errors to deliver and protect the services. We have not appointed a third-party advertising provider. If that changes, we will update this policy before introducing it.
Who else handles information
The main services that handle information for MoriDeck are listed below. If you connect an external storage or sign-in service, that service also handles the information needed for your connection. We may disclose information where required by law or needed to investigate abuse and protect the service. Your information may be stored or processed outside Australia, including in the United States. Other processing locations depend on the provider and the feature you use.
| Service | Purpose | Information handled |
|---|---|---|
| DigitalOcean | Application hosting and temporary storage | Account data, server records and data temporarily held while a hosted service processes a request; hosted in the United States. |
| Postmark | Account and service emails | Recipient email addresses, message contents and delivery information. |
| Stripe | Payments | Payment details, billing information and transaction records. |
| Cloudflare | Website analytics and cloud storage | Technical visit and performance information, plus cloud files and related storage metadata where Cloudflare R2 is used. |
| Google Drive | Optional connected storage | Account identifier, connection permissions, file and folder details, and files you choose to access or save through MoriDeck. |
| Dropbox | Optional connected storage | Account identifier, connection permissions, file and folder details, and files you choose to access or save through MoriDeck. |
| Microsoft OneDrive | Optional connected storage | Account identifier, connection permissions, file and folder details, and files you choose to access or save through MoriDeck. |
| fal.ai | Optional AI processing | Content submitted to an online AI feature and related request data. |
| Runpod | Optional AI processing | Content submitted to an online AI feature and related request data. |
Protecting your information
We use HTTPS to protect information in transit and store connected-storage credentials in encrypted form. Access to cloud features is checked against account permissions. Cloud storage is not end-to-end encrypted: our servers and service providers process files as needed to deliver the features you use.
Keeping and deleting information
Local data stays on your device until you or your browser remove it. Cloud files may include previous versions and items in the trash; moving a file to the trash is not the same as permanently deleting it. Retention depends on the type of information and whether it is needed to provide your account and files, resolve support or security issues, or meet legal and accounting requirements. We have not yet set fixed automatic deletion periods for account records, logs and backups. Contact us to request deletion or ask what we still hold. Some information may need to be kept for legal, accounting or security reasons, and deletion from backups may take longer than deletion from the live service.
Your choices and privacy questions
You can use local editing without an account. Online features need the information described above to work. To ask what personal information we hold about you, request access, correction or deletion, or make a privacy complaint, email [email protected]. We may need to verify your identity. We will respond within a reasonable time and may refuse or limit a request where permitted or required by law.
Changes to this policy
We will update this page when our practices change and show the updated date. For significant changes affecting your information, we will also give notice through the website, apps or email where appropriate.