Privacy

What happens to your data.

Last updated: July 13, 2026

Morthn is a done-for-you automation agency. Our clients are businesses, and we run parts of their operations — answering their phones, working their inbox, chasing their invoices, drafting their proposals. That means we handle data in two distinct roles, and this page is organized around that split: data we collect directly (from visitors to this site and from the business owners who sign up), and data we process on behalf of our clients — their customers’ names, calls, messages, and records, where the client stays the owner and we act as their service provider.

Plain English, no dark patterns. If anything below is unclear, email support@morthn.com and we’ll fix the doc.

Data we collect directly

From you (the business owner or client)

Name, email, business name, phone, billing address, and Stripe payment metadata (we never store card numbers — Stripe does). Plus everything you configure during onboarding: your services, real pricing, business hours, brand voice, approval rules, and the edge cases you tell us about.

From site visitors

Standard web logs: IP address, browser, pages viewed. Whatever you type into a demo, calculator, or intake form. We use PostHog for aggregate product analytics.

Data we process for our clients

When a business hires Morthn, we process their customers’ data as a service provider — only to deliver the modules that business turned on, only on that business’s instructions. Depending on the modules a client runs, that includes:

How AI processing works

Who we share it with

We use subprocessors to deliver the service. Each one only sees the data it needs to do its job, and each has its own privacy policy linked below.

Hosting — serves the web app and runs API endpoints.

Database — stores accounts, transcripts, customer records, and uploaded documents.

AI models — generate and review drafts, transcripts, and analyses. API inputs and outputs are not used to train their models under their published API data policies.

AI models — generate images and some content. API inputs and outputs are not used to train their models under their published API data policies.

Telephony and SMS — connects phone numbers and carries text messages.

Real-time voice infrastructure — handles audio streams during answered calls.

Mailbox and messaging connection — links a client’s email or DM inbox so replies can be drafted and sent in-thread.

Integration authentication — securely brokers OAuth connections to third-party tools.

Payments — processes subscription billing and payment links. We never see or store card numbers.

Client payments — when a client connects their own Square account, we create invoices and payment links through it. Card data stays with Square.

Transactional email — sends confirmations, reports, and account emails.

Product analytics — tracks aggregate usage to improve the product.

Connected platforms. If a client connects a Meta, Google, TikTok, or LinkedIn account (for social posting or ad management), Morthn exchanges data with that platform for that client’s connected account only, under that platform’s own terms. If nothing is connected, nothing is shared with them.

We do not sell personal information. We do not rent or trade client or customer data with anyone outside the subprocessors above, except when required by law (subpoenas, court orders, fraud investigations).

Protections enforced in code

Some protections are policy; these are code — the system enforces them, not a checklist:

Call recording & consent

Calls answered through Morthn are recorded and transcribed by default — recordings and transcripts are available to the client whose line it is. Many U.S. states (CA, FL, IL, MA, MD, MT, NH, PA, WA, plus others) require all parties to consent to recording. To satisfy the strictest of these everywhere, every answered call opens with a spoken disclosure that the caller is speaking with an automated assistant and that the call may be recorded — the disclosure runs on all calls, not by state. Ultimate responsibility for consent from the client’s own customers sits with the client as the business operator — we provide the controls and defaults to do it right.

HIPAA

Morthn services are not for protected health information (PHI) unless you are enrolled in our HIPAA add-on program, which requires Business Associate Agreements to be executed — with Morthn and with the upstream voice, AI, and telephony providers on your account — before any PHI-bearing line or inbox goes live. We do not claim HIPAA compliance for the standard service, and no line receives PHI on our watch until that paperwork exists for your account. If you are a covered entity or business associate, email aiden@morthn.com before connecting anything.

How long we keep it

Your rights

If you’re a California resident, the CCPA/CPRA gives you the right to know what personal information we hold about you, to access it, correct it, delete it, and to opt out of its sale or sharing. We don’t sell or share personal information as those terms are defined in the CPRA, so there is nothing to opt out of — and we honor Global Privacy Control signals regardless. Residents of other states and the EU/UK have similar rights under their laws. Email support@morthn.com; we respond within the legally required window and never charge for it. We also don’t discriminate against anyone for exercising these rights.

If you’re a customer of a business that uses Morthn: for that data we act as a service provider — the business controls its own customer records. Send your request to that business first; they instruct us, and we assist them in fulfilling it. If you can’t reach them or they don’t respond in a reasonable time, email us directly and we’ll help route it.

Children

Morthn is a B2B product. We don’t knowingly collect data from anyone under 13. If a client’s business receives a call or message from a minor, that content is treated like any other customer data — same retention, same access restrictions, same subprocessors, nothing more.

Security

Data in transit is encrypted (TLS), and our infrastructure providers encrypt data at rest and in transit on their platforms. Access to production data is restricted to the founder and on-call engineers, and sensitive telecom interactions are audit-logged. We hold no SOC 2, ISO 27001, or HIPAA certification today — when that changes, this page will say so, and not before.

Changes to this policy

If we make a material change (new subprocessor, change in retention, change in how we use data), we’ll email everyone with an active account at least 14 days before it takes effect. Non-material changes (typos, clearer wording) we’ll just push and update the “Last updated” date at the top of this page.

Contact

Morthn, Inc. · Atlanta, GA

Privacy questions: support@morthn.com
Deletion requests: support@morthn.com
Anything else: aiden@morthn.com