MorphManager legal
Privacy Policy
How MorphManager collects, uses, stores, shares, and protects information.
Effective and last updated: August 12, 2026
Information we collect
We collect account and profile information such as your email address, display name, role, account status, preferences, authentication and session records, and subscription entitlement.
We store information you choose to add to MorphManager, including collection and animal records, husbandry details, care logs, reminders, genetics and lineage information, breeding projects, photos, export files and export history, and forum posts, replies, reports, attachments, and moderation records.
We also collect limited technical and security information needed to operate and protect the service, such as request timestamps, IP-derived anti-abuse signals, session and CSRF tokens, rate-limit events, device or browser information sent with requests, and audit logs. We may collect support communications you send to us.
How we use information
We use information to create and secure accounts; authenticate you through the Nolan Media sign-in service; provide collection, husbandry, genetics, project, photo, export, community, and subscription features; respond to support requests; moderate community content; prevent fraud and abuse; maintain backups; diagnose errors; and improve and operate MorphManager.
Genetics and husbandry records are used privately to provide the features you request. Saving a record or running a calculation does not by itself contribute that data for broader research use. Any broader use requires an explicit optional contribution choice when that capability is available, as explained in the Genetic Data Contribution Notice.
Service providers and disclosures
MorphManager uses Cloudflare to deliver and protect the application, including Workers, D1 database storage, and R2 object storage. Sign-in is handled by the Nolan Media account service (Keycloak) operated by Nolan Media, which holds your sign-in credentials and returns a verified identifier and email address to MorphManager; MorphManager never receives your password. If you choose to sign in using Google or Facebook, that provider confirms your identity to the Nolan Media account service under its own privacy notice, and you can review or revoke that connection with them. AWS Simple Email Service (SES) delivers operational account messages. Stripe processes payments and provides payment and subscription event information to MorphManager; MorphManager does not receive or store full payment-card numbers. Purchases are processed through Stripe Managed Payments, with Link acting as merchant of record. Stripe and Link may collect and process payment, identity, billing, location, and tax-related information directly from purchasers under their own privacy notices. Backblaze B2 may hold access-controlled off-site backup copies.
These providers process information as needed to supply their services. We may also disclose information when reasonably necessary to comply with law, protect users or animals, investigate abuse or security incidents, enforce our terms, or protect MorphManager's rights. We do not sell personal information.
Community content
Forum content you submit may be visible to other users or the public according to the feature's visibility settings. Your display name and relevant timestamps may appear with that content. Reports and moderation records are available to authorized moderators and administrators. Removing content from public view may not immediately remove it from backups, logs, quoted replies, or records retained for safety and enforcement.
Ownership, access, and exports
You retain ownership of your records and user-generated information. MorphManager receives only the limited permission needed to host, process, display, back up, and export that information to provide the service. You may use available export tools to obtain your own records. MorphManager is designed not to intentionally trap user data.
Your photos are private by default and are served only to you through an authenticated request. Photos become reachable to other people only if you choose it, and only for the photos you choose. There are two such choices: ticking "Give this photo a shareable link" when you upload it, and including a photo-links column when you build a CSV export, which asks you to confirm separately before it applies. In either case each of those specific photos is given its own unlisted link, so that another site or service can retrieve them. Anyone holding that link can open the photo without signing in. The link cannot be guessed, it is never published or listed by us, and it applies only to the photos you selected. Camera metadata, including any location your phone or camera recorded in the file, is removed from a photo before it can be downloaded through such a link; the copy held in your account is unchanged. You can stop sharing any of them at any time from your profile, which permanently disables the link; closing your account stops all such sharing as well. Stopping sharing does not remove copies that another site downloaded while the link was active.
To request help accessing, correcting, or deleting account information, contact support@morphmanager.com. We may need to verify the request and may retain limited information when required for security, legal compliance, payment records, dispute resolution, moderation integrity, or backup rotation.
Retention and security
We retain information while your account is active and as reasonably needed to provide the service, maintain backups, resolve disputes, prevent abuse, enforce agreements, and meet legal obligations. Retention periods can differ by data type. Backup copies may remain until their normal rotation expires.
When you ask us to delete your account, we close the account, cancel any active subscription so you are not billed again, and retain your records for six months. During that six-month period you may contact us to reinstate the account, and your collection, husbandry, care log, genetics, project, and photo records will be restored. After six months those records are permanently deleted and cannot be recovered; if you return after that point you will need to create a new account and set it up again.
Content you posted in community areas is anonymised rather than deleted, so that discussions other members took part in remain intact. Your display name is removed from it. We may also retain information beyond the six-month period where reasonably necessary for payment records, security and anti-abuse records, moderation integrity, or legal compliance, and backup copies may persist until their normal rotation expires.
We use measures appropriate to the service, including federated sign-in through the Nolan Media account service, secure sessions, access controls, ownership checks, rate limiting, audit logging, and provider security controls. No internet service can guarantee absolute security. Protect the sign-in methods attached to your Nolan Media account, since they control access to MorphManager.
Children and changes
MorphManager is not directed to children under 13, and we do not knowingly collect personal information from them. We may update this policy as the service changes. Material updates will be posted with a new effective date and, when appropriate, an additional notice.
Contact
For help with your account, your data, or anything else you need assistance with, contact support@morphmanager.com. For general, business, press, or legal inquiries, contact info@morphmanager.com.