Privacy
What happens to your data.
Last updated: July 13, 2026
Morthn is a done-for-you automation agency. Our clients are businesses, and we run parts of their operations — answering their phones, working their inbox, chasing their invoices, drafting their proposals. That means we handle data in two distinct roles, and this page is organized around that split: data we collect directly (from visitors to this site and from the business owners who sign up), and data we process on behalf of our clients — their customers’ names, calls, messages, and records, where the client stays the owner and we act as their service provider.
Plain English, no dark patterns. If anything below is unclear, email support@morthn.com and we’ll fix the doc.
Data we collect directly
From you (the business owner or client)
Name, email, business name, phone, billing address, and Stripe payment metadata (we never store card numbers — Stripe does). Plus everything you configure during onboarding: your services, real pricing, business hours, brand voice, approval rules, and the edge cases you tell us about.
From site visitors
Standard web logs: IP address, browser, pages viewed. Whatever you type into a demo, calculator, or intake form. We use PostHog for aggregate product analytics.
Data we process for our clients
When a business hires Morthn, we process their customers’ data as a service provider — only to deliver the modules that business turned on, only on that business’s instructions. Depending on the modules a client runs, that includes:
- Contact and job records. Customer names, phone numbers, emails, appointment and job details, permit and warranty and equipment records, and membership records.
- Call recordings and transcripts. Inbound calls answered by the client’s AI receptionist are recorded and transcribed. Each night, an AI model automatically reviews transcripts for quality — flagging errors and suggesting improvements to the client’s configuration.
- SMS content. Text messages sent and received through the client’s Morthn number, carried by Twilio.
- Email and DM content. If a client connects their inbox (via Unipile), we read incoming messages in that inbox to draft and send replies and payment follow-ups in the client’s name. We do not connect a mailbox without the client doing it themselves.
- Payment and invoice metadata. Invoice amounts, statuses, and payment-link activity through Stripe and the client’s own Square account. We never store card numbers, and by policy we never take card details over the phone.
- Documents. Contracts, RFPs, and similar files a client uploads for analysis or drafting.
How AI processing works
- What the AI touches. Content sent through Morthn — calls, messages, documents, records — is processed by AI models via the Anthropic and OpenAI APIs to generate drafts, transcripts, scores, and analyses.
- No model training on your data. Under those providers’ published API data policies, API inputs and outputs are not used to train their models. We don’t sell your data or anyone else’s.
- Humans in the loop. Where approval flows are configured — the default for anything that touches a customer or a dollar — AI drafts are reviewed by the client and, during supervised periods, by our operators before anything customer-facing sends.
Who we share it with
We use subprocessors to deliver the service. Each one only sees the data it needs to do its job, and each has its own privacy policy linked below.
Vercel
Privacy policy →Hosting — serves the web app and runs API endpoints.
Supabase
Privacy policy →Database — stores accounts, transcripts, customer records, and uploaded documents.
Anthropic
Privacy policy →AI models — generate and review drafts, transcripts, and analyses. API inputs and outputs are not used to train their models under their published API data policies.
OpenAI
Privacy policy →AI models — generate images and some content. API inputs and outputs are not used to train their models under their published API data policies.
Twilio
Privacy policy →Telephony and SMS — connects phone numbers and carries text messages.
Vapi
Privacy policy →Real-time voice infrastructure — handles audio streams during answered calls.
Unipile
Privacy policy →Mailbox and messaging connection — links a client’s email or DM inbox so replies can be drafted and sent in-thread.
Nango
Privacy policy →Integration authentication — securely brokers OAuth connections to third-party tools.
Stripe
Privacy policy →Payments — processes subscription billing and payment links. We never see or store card numbers.
Square
Privacy policy →Client payments — when a client connects their own Square account, we create invoices and payment links through it. Card data stays with Square.
Resend
Privacy policy →Transactional email — sends confirmations, reports, and account emails.
PostHog
Privacy policy →Product analytics — tracks aggregate usage to improve the product.
Connected platforms. If a client connects a Meta, Google, TikTok, or LinkedIn account (for social posting or ad management), Morthn exchanges data with that platform for that client’s connected account only, under that platform’s own terms. If nothing is connected, nothing is shared with them.
We do not sell personal information. We do not rent or trade client or customer data with anyone outside the subprocessors above, except when required by law (subpoenas, court orders, fraud investigations).
SMS / text-messaging consent & mobile data
When you provide your phone number to Morthn or to a business that uses Morthn — by calling, texting, submitting a booking or contact form, or giving your number in person when booking a service — you consent to receive service-related text messages such as missed-call follow-ups, appointment confirmations and reminders, review requests after completed work, and replies to your inquiries. Consent to receive text messages is not a condition of purchasing any goods or services.
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Text-messaging originator opt-in data and consent are not shared with any third parties, excluding sharing with subprocessors strictly as needed to deliver the messages themselves (e.g., our telephony carrier) and with vendors assisting us in customer support. All the above categories exclude text-messaging originator opt-in data and consent; this information will not be shared with or sold to any third parties.
- Opting out. Reply STOP to any message and you will be unsubscribed immediately; no further messages will be sent. Reply START to re-subscribe.
- Help. Reply HELP to any message, or contact support@morthn.com.
- Frequency & rates. Message frequency varies by your service activity. Message and data rates may apply per your carrier plan.
Protections enforced in code
Some protections are policy; these are code — the system enforces them, not a checklist:
- Quiet hours on automated texts. Automated SMS respects TCPA quiet-hour windows; messages queued outside them hold until an allowed time.
- CPNI handling for telecom clients. Account interactions that touch customer proprietary network information require authentication and are audit-logged.
- Review-reply scrubbing. Generated review responses pass through a scrub aligned to the FTC’s rule on consumer reviews before they can be approved.
- Recording consent and AI disclosure. Every answered call opens with a spoken disclosure that the caller is speaking with an automated assistant and that the call may be recorded.
Call recording & consent
Calls answered through Morthn are recorded and transcribed by default — recordings and transcripts are available to the client whose line it is. Many U.S. states (CA, FL, IL, MA, MD, MT, NH, PA, WA, plus others) require all parties to consent to recording. To satisfy the strictest of these everywhere, every answered call opens with a spoken disclosure that the caller is speaking with an automated assistant and that the call may be recorded — the disclosure runs on all calls, not by state. Ultimate responsibility for consent from the client’s own customers sits with the client as the business operator — we provide the controls and defaults to do it right.
HIPAA
Morthn services are not for protected health information (PHI) unless you are enrolled in our HIPAA add-on program, which requires Business Associate Agreements to be executed — with Morthn and with the upstream voice, AI, and telephony providers on your account — before any PHI-bearing line or inbox goes live. We do not claim HIPAA compliance for the standard service, and no line receives PHI on our watch until that paperwork exists for your account. If you are a covered entity or business associate, email aiden@morthn.com before connecting anything.
How long we keep it
- Client and customer data: retained for the duration of the client relationship, plus as long as needed to meet legal obligations (tax, accounting, dispute resolution).
- Deletion on request: email support@morthn.com with a verified request and we delete the data that isn’t legally required to stay.
- After termination: data stays exportable for 30 days, then is deleted except where law requires longer retention.
- Aggregate analytics: kept indefinitely, in de-identified form.
Your rights
If you’re a California resident, the CCPA/CPRA gives you the right to know what personal information we hold about you, to access it, correct it, delete it, and to opt out of its sale or sharing. We don’t sell or share personal information as those terms are defined in the CPRA, so there is nothing to opt out of — and we honor Global Privacy Control signals regardless. Residents of other states and the EU/UK have similar rights under their laws. Email support@morthn.com; we respond within the legally required window and never charge for it. We also don’t discriminate against anyone for exercising these rights.
If you’re a customer of a business that uses Morthn: for that data we act as a service provider — the business controls its own customer records. Send your request to that business first; they instruct us, and we assist them in fulfilling it. If you can’t reach them or they don’t respond in a reasonable time, email us directly and we’ll help route it.
Children
Morthn is a B2B product. We don’t knowingly collect data from anyone under 13. If a client’s business receives a call or message from a minor, that content is treated like any other customer data — same retention, same access restrictions, same subprocessors, nothing more.
Security
Data in transit is encrypted (TLS), and our infrastructure providers encrypt data at rest and in transit on their platforms. Access to production data is restricted to the founder and on-call engineers, and sensitive telecom interactions are audit-logged. We hold no SOC 2, ISO 27001, or HIPAA certification today — when that changes, this page will say so, and not before.
Changes to this policy
If we make a material change (new subprocessor, change in retention, change in how we use data), we’ll email everyone with an active account at least 14 days before it takes effect. Non-material changes (typos, clearer wording) we’ll just push and update the “Last updated” date at the top of this page.
Contact
Morthn, Inc. · Atlanta, GA
Privacy questions: support@morthn.com
Deletion requests: support@morthn.com
Anything else: aiden@morthn.com