LegalEmail
Privacy Policy
Last updated July 23, 2026
Studio Mori (“we,” “us”) makes Mori, a desktop AI agent, Mori Link, its iPhone/iPad companion app, and Mori Chrome, a browser extension. This policy explains exactly what data we collect, how we collect it, what it’s used for, and who it’s shared with.
What we collect, and how
- Account info: provided by you. If you create an account, we store your email address through our authentication provider (Supabase).
- Chat content: provided by you. The messages, tasks, and files/images you send to Mori. If you’re signed in, conversations sync to your account so they follow you across devices; signed out, they stay on your device.
- Mori Link traffic: provided by you and generated in use. When you pair the phone app with your own computer, your commands, Mori’s replies, status updates, and any screenshots of your own machine that you request are relayed between your devices over an encrypted realtime channel hosted by Supabase. Pairing uses a short-lived 6-digit code; only your confirmed device can send commands.
- Subscription & usage data: collected automatically. If you subscribe, we store your plan tier and metered usage of managed AI (session/daily/monthly totals and reset times) so we can enforce fair limits and show you honest meters.
- Payment records: from our payment processors. Card payments are handled by Stripe; iOS purchases by Apple (we verify Apple’s signed transaction and link it to your account id). We never see full card numbers.
How AI processing works (who sees your prompts)
- With your own API keys (BYOK): requests go from your machine to the provider you chose (Anthropic, OpenAI, OpenRouter, or others) using your key. Your keys are stored on your device and are never sent to us.
- With a subscription (managed mode): your messages are forwarded through Studio Mori’s servers to our AI providers, Anthropic and OpenRouter (and the model providers OpenRouter routes to), to generate the response. We relay and meter this traffic; we don’t use your conversations for advertising or sell them.
- Mori Link without a paired computer uses managed mode above; with a paired computer, your commands run on your own machine and its configured providers.
- Our AI providers process this data under their API terms, which provide protections equivalent to ours, including that API inputs and outputs are not used to train their models.
What we use data for
- Providing the product: generating AI responses, syncing your content, running tasks on your paired machine.
- Billing and subscription management; enforcing usage limits with honest meters.
- Security and abuse prevention.
- We do not sell your data, run ads, use third-party ad trackers, or use your conversations to train models.
Third-party services
- Supabase: authentication, synced storage, and the encrypted realtime channel that connects your own devices.
- Anthropic & OpenRouter: AI processing in managed mode (or your configured provider with BYOK), governed by their API privacy terms (no training on API data).
- Stripe: card payments. Apple: iOS in-app purchases.
- Vercel: hosts our website, downloads, and the managed-mode relay.
We send transactional emails, such as your sign-up confirmation code, from noreply@studiomori.ai. We don’t send marketing email.
Your choices & deletion
- Use Mori entirely without an account. Your content stays on your machine (BYOK requests go only to your chosen provider).
- Delete your account and its data in-app: Mori Link → Settings → Delete account, which permanently removes your account and synced data from our systems. You can also email support@studiomori.ai.
- Local data on your own devices stays yours. Deleting the apps removes it.
Children
Mori is not directed to children under 13, and we don’t knowingly collect their data.
Changes
We’ll update this page if our practices change and revise the date above.
Contact
Questions about privacy? Email support@studiomori.ai.