Legal
Privacy Policy
This policy explains how Morphio handles information when you browse the website, view HEIC/HEIF images, convert or compress files, use an account, or make a purchase.
Effective date: September 6, 2026
1. Scope and operator
This Privacy Policy applies to the Morphio website, browser-based image viewing and Privacy conversion, Cloud image and ZIP conversion, Cloud HEIC compression, accounts, payments, and support. Morphio is operated by Yang Donghe, based in China, who is responsible for the processing described in this policy. In this policy, we, us, and our refer to Yang Donghe as the operator of Morphio.
This policy does not govern third-party websites or services that you visit independently, even if Morphio links to them.
2. Information we collect
- Account information, such as your name, email address, profile image, account identifier, and authentication provider details when you sign in.
- Session and security information, such as session tokens, IP address, browser user agent, timestamps, and authentication activity.
- Files and processing information for Cloud tools, including uploaded images and ZIP archives, images extracted from archives, conversion and compression results, result ZIPs, file names, formats, sizes, task identifiers, processing status, timing, errors, and points charged.
- Local conversion and licensing information, such as account status, a generated device identifier, permit identifiers, plan eligibility, usage counts, and conversion task identifiers. Files processed locally remain in your browser unless you separately choose a cloud workflow.
- Purchase and plan information, such as product, price, currency, order status, subscription status, transaction identifiers, refunds, disputes, and entitlement dates. Payment providers process payment-card details; Morphio does not intentionally store complete card numbers or security codes.
- Usage and diagnostics, such as pages viewed, clicks, scrolling, file counts, selected conversion mode and format, conversion duration, errors, browser identifiers stored locally, device and browser characteristics, and performance data.
- Communications you send to us, including your email address and the contents of support or privacy requests.
3. How files are handled
In Privacy mode, supported conversion work is performed in your browser. The selected image data is not uploaded to Morphio for conversion, which also avoids the upload step. The service may still contact Morphio to authenticate you, check free usage or plan eligibility, issue a signed conversion permit, and record non-file usage information.
The HEIC Viewer also parses images in your browser, including supported frames and image information. Exporting the current frame as JPG or PNG uses the local Privacy conversion workflow. Viewing the image does not upload it for decoding.
Cloud conversion uploads selected images and ZIP archives to object storage for our conversion infrastructure to process. Each archive is checked and its supported images are extracted for conversion. Source files, extracted files, processing files, converted results, and result ZIPs may pass between storage and conversion services to complete the task and provide downloads. ZIP input uses Cloud processing, not Privacy processing.
A ZIP downloaded from a batch of ordinary image conversions can instead be assembled in your browser from the individual results. Creating that download package does not upload the package to Morphio. This is different from a result ZIP generated by the Cloud archive workflow.
The HEIC compression tool also uses Cloud processing: it uploads the source image and returns a compressed result. It is not a browser-only compression workflow. Retention and download availability are explained in the Data retention section below.
Privacy and Cloud conversions retain metadata that the output format and conversion pipeline support by default, which can include EXIF, capture times, and GPS location. Conversion is not a metadata-removal tool, so a downloaded file may still contain this information. Some HEIC-specific information, including HDR, depth, auxiliary-image, motion, or container-only data, may not have an equivalent in the output format. Keep the original HEIC when those details matter.
Do not upload files that you are not authorized to process. Because images can contain personal data and metadata, use Privacy mode for sensitive material when the required conversion is supported in your browser.
4. How and why we use information
Where applicable law requires a legal basis, we rely on performance of a contract, our legitimate interests in operating and securing the service, compliance with legal obligations, and consent where required for optional analytics or similar technologies.
- Provide image viewing, conversion, compression, archive processing, downloads, accounts, plans, points, licenses, and customer support.
- Authenticate users, protect accounts, detect abuse, enforce limits, investigate failures, and secure the service.
- Process purchases, subscriptions, refunds, disputes, accounting records, and plan entitlements.
- Measure product usage, diagnose performance, understand conversion workflows, and improve site design and reliability.
- Comply with legal obligations, respond to lawful requests, and establish, exercise, or defend legal claims.
6. Cookies and browser storage
Morphio uses cookies and similar browser storage for authentication, security, preferences, licensing, and analytics. The site creates a persistent browser identifier in localStorage, a visit identifier in sessionStorage, and a new page-view identifier for behavioral analytics. These identifiers are sent with relevant analytics events together with page, authentication-state, plan, and conversion interaction information.
Google Analytics, Microsoft Clarity, Vercel Analytics, authentication providers, and payment providers may use their own cookies or similar technologies under their respective policies. Browser settings can delete or block stored data, but doing so may sign you out, reset device recognition or free-usage continuity, and limit some features.
7. Data retention
We retain information for only as long as reasonably necessary for the purposes described here, including providing downloads, maintaining accounts and entitlements, preventing abuse, resolving disputes, keeping transaction and tax records, enforcing agreements, and meeting legal obligations.
For Cloud uploads, the default one-day deletion period applies to uploaded source images.
Cloud workflows can also create or store original ZIP archives, extracted images, processing files, conversion and compression results, and result ZIPs. These are separate file objects covered by the retention purposes above. Download links are time-limited, and a link expiring does not by itself mean the associated file has been deleted. Download results promptly and keep your own copy.
Security logs, account and usage records, transaction records, legal-hold material, and backups may remain longer where reasonably required for the purposes above. Images viewed in the HEIC Viewer or converted in Privacy mode are not uploaded for image processing and remain under your control on your device.
8. Security
We use reasonable technical and organizational measures intended to protect information, including access controls, signed URLs, authenticated service requests, and restricted conversion permits. No online transmission, storage system, or browser environment is completely secure, and we cannot guarantee absolute security.
9. International data transfers
Morphio and its service providers may process information in countries other than your own. Where required, we use applicable contractual or other recognized safeguards. Local laws in those countries may differ from the laws where you live.
10. Your privacy rights
Depending on your location, you may have rights to request access, correction, deletion, restriction, portability, or objection; to withdraw consent; or to complain to a data protection authority. Some information may be retained where an exception applies, including security, fraud-prevention, transaction, legal, or recordkeeping requirements.
Submit a request using the contact email below. We may need to verify your identity and authority before acting. Authorized agents should identify the person they represent and provide evidence of authority where required.
11. California privacy notice
California residents may have rights to know, access, correct, or delete personal information, and to receive equal service when exercising applicable rights. The categories collected are identifiers; customer records; commercial information; internet or electronic activity; device and approximate network information; user-provided content; and inferences derived from usage. We use and disclose these categories for the business purposes described above.
Morphio does not sell personal information for money. Some analytics disclosures may be treated as ‘sharing’ under certain laws depending on configuration and use. You may contact us to exercise an applicable opt-out right. We do not knowingly sell or share personal information of people under 16.
12. Children
Morphio is not directed to children under 13, or a higher minimum age where local law requires it. We do not knowingly collect personal information from children in violation of applicable law. A parent or guardian who believes a child provided information may contact us to request review and deletion.
13. Changes to this policy
We may update this policy as the service, providers, or legal requirements change. We will post the revised policy and update its effective date. Where required, we will provide additional notice or request consent.
Contact and privacy requests
For privacy questions or requests, contact Yang Donghe, the operator of Morphio, at support@morphio.online