Morph Privacy Notice

Morph is an iPhone and iPad Safari extension from Kaizōsha. This notice describes the current privacy design of the Morph app, Safari extension, and optional Mac companion while Morph is in development. Kaizōsha's marketing website has a separate privacy policy.

Last updated: August 20, 2026

PRIVACY OVERVIEW

The current Morph app and extension do not include advertising, analytics, tracking, crash-report upload, cloud sync, or a Kaizōsha-operated account service. Their Apple privacy manifests declare no collected data and no tracking.

That does not mean every AI request always stays on the device. Morph sends your instruction to the provider you choose. When page context is enabled, it may also send that provider a bounded, sanitized description of the open webpage. The destination depends on whether you choose Apple Intelligence, Codex Bridge, a local model, or a cloud provider.

PAGE CONTEXT

Morph uses page context only to help a plan provider target the change you request. You can turn page context off; when it is off, the provider receives your instruction without the page description.

The sanitized page description excludes cookies, authentication headers, session tokens, localStorage, sessionStorage, IndexedDB, Cache Storage, scripts, inline event-handler source, form values, password or payment fields, selected files, clipboard contents, query strings, hidden form metadata, other tabs, and browsing history.

Sensitive-value redaction is always enabled. Page text is treated as untrusted input in provider instructions.

PROVIDER ROUTES

Apple IntelligenceWhen supported, enabled, and ready, Apple's Foundation Models process the request on the device. Page context stays on the device for this route.
Codex BridgeYour instruction and any enabled sanitized page context travel to the authenticated Morph companion on the trusted Mac you configure. The companion uses the Mac's existing Codex login.
Local modelYour instruction and any enabled sanitized page context travel to the OpenAI-compatible private-network endpoint you configure, such as Ollama or LM Studio.
Cloud providerYour instruction and any enabled sanitized page context travel to the OpenAI-compatible HTTPS API you explicitly configure.

External provider processing, retention, and account terms are controlled by the provider or endpoint you choose. Morph does not silently fall through to a disabled cloud provider.

CREDENTIALS AND LOCAL STORAGE

Provider tokens are stored in the shared iOS or iPadOS Keychain access group and are not placed in UserDefaults or page context. Non-secret provider settings, privacy choices, editor mode, recent activity, and saved rules use app- or extension-owned local storage.

Saved Safe and Agent rules affect only your Safari rendering. They do not modify the origin server or another visitor's copy of the website. Morph provides controls to clear activity and remove saved rules.

SAFARI WEBSITE ACCESS

Safari controls whether Morph is enabled and which websites it may access. Morph cannot enable itself, inspect protected browser interface, bypass Safari's website-access grants, or inherit a ChatGPT browser login.

When granted access, Morph inspects only the active webpage needed for the requested edit. It does not inspect other tabs or browsing history.

SOURCE MODE

Source Mode is off by default, requires explicit ownership consent, and works only through Codex Bridge. It is for Git repositories you own or are authorized to modify.

The paired Mac operator creates an allowlist of repository IDs and paths. The iPhone or iPad sends only a bounded workspace ID and your source-edit instruction; it cannot supply a path. Source requests contain no webpage DOM, current URL, form data, or browser-session information.

A new Source run requires a clean Git working tree. Codex receives write access only inside the selected repository, with network access and web search disabled. Morph does not commit, push, or deploy the result. You review the local working-tree changes and perform any external action yourself.

RETENTION AND DELETION

Activity, settings, and saved rules remain in app- or extension-owned local storage until you clear them or remove the app, subject to iOS and iPadOS behavior. Keychain items remain subject to Apple's Keychain behavior and can be replaced or removed through Morph's provider controls.

Requests handled by an external provider may be retained under that provider's or endpoint operator's policies. Review those policies before configuring a cloud or shared service.

CHANGES AND CONTACT

Morph is in development. If its data practices change before release, this notice and any required platform privacy disclosures will be updated.

Questions about Morph privacy can be sent through the Kaizōsha contact page: https://kaizosha.org/contact.