This page is a working draft. It has not been reviewed by a licensed attorney and must not be relied on until it is.
Last updated: draft, not yet published
[LAWYER REVIEW] This was drafted by a non-lawyer agent, is not legal advice, and has not been reviewed by a licensed attorney. It publishes as v1 and goes to counsel for redline afterwards. See “Open for counsel” at the end for the specific open questions.
Effective date: [EFFECTIVE DATE: set on publish]
Last updated: [EFFECTIVE DATE: set on publish]
Morrow is a job-application tool operated by Simkins & Elgazar LLC, a Virginia limited liability company. In this policy, “we,” “us,” and “our” mean that company. “You” means the person who holds a Morrow account.
You can reach us about anything in this policy, including a privacy request, at hello@morrowhq.app.
Our mailing address is 10612 Center Street, Fairfax, VA 22030, United States.
Morrow works by running a worker app on your own computer. That design is the reason this policy reads the way it does.
These things live on the computer running the Morrow worker app, and we never receive them:
This section is the honest inventory. It is written from the database schema, not from intent.
4.1 Account and sign-in
Your email address, your password in hashed form, your display name, your time zone and quiet-hours settings, and your app preferences. Kept until you delete your account.
4.2 Your answer bank
Every question a job application has asked you and the answer you gave, saved so you never have to type it twice. This includes the identity fields Morrow needs for almost every form: your name, email address and phone number.
It also includes the voluntary self-identification answers you chose to save — gender, race or ethnicity, veteran status and disability status, and, where a form asks, citizenship, sponsorship need and security clearance. Under California and most other state privacy laws, racial or ethnic origin and disability status are sensitive personal information. We hold them because you asked Morrow to reuse them; you can edit or remove any answer in the app at any time.
Your answer bank is readable only by your own account, enforced at the database. It has no expiry date and is kept until you delete your account.
4.3 Applications under review
For every application waiting for your approval, we hold the field-by-field card you see on your phone: each field’s label as the employer wrote it, and the exact value about to be submitted. These rows are removed when the application they belong to is removed.
4.4 Submissions and receipts
For every application Morrow submits, we keep a permanent ledger line: the company, the job title, the job URL, the applicant-tracking system, the timestamp, the outcome and the employer’s own confirmation text. This is the record behind the Nothing-False Guarantee, and it is kept for as long as your account exists.
Alongside it we keep the frozen field list of what was actually submitted. Fields in the sensitive group described in section 4.2 are flagged and deleted after 90 days; the rest of the field list and the ledger line survive.
We also store the results of Morrow’s nine honesty checks. Those results carry field keys, labels and outcome codes only. The answer values themselves are stripped out before the record reaches our database.
4.5 Application screenshots
Morrow takes a full-page screenshot of each application, which is what a guarantee claim is judged against.
Sensitive fields are masked on your own computer before the image is uploaded. A solid box is painted over each self-identification field, the masked image is the one the checksum covers, and the masked image is the only version ever sent anywhere, including to the vision model that verifies the submission. In your review screen you will see the box and the caption “Sensitive answers hidden in this preview; values are shown in the field list.”
Screenshots live in a private storage bucket with no public reads. Access is a signed link that expires after 300 seconds and only works for the account that owns the image. Screenshots are deleted after 90 days. A screenshot attached to an application that was closed, expired, skipped or parked without ever being submitted is deleted after 30 days.
4.6 Questions Morrow could not answer
When a form asks something Morrow cannot answer honestly from what you have told it, it stops and saves the question so it can ask you. That saved question is the employer’s wording, which occasionally is itself a self-identification question. Kept until you delete your account.
4.7 Devices
The name, platform and version of the laptop you paired, plus a one-way hash of its pairing token; your phone’s push notification address; and the six-digit pairing code, which is deleted 24 hours after it expires. When a device attempts to pair, we record the IP address it came from to rate-limit abuse. Those IP records are deleted after 24 hours.
4.8 Billing
Your subscription tier, status and period, mirrored from our subscription service, and a Stripe customer identifier that links your account to your billing record. We also keep the credit ledger behind tailoring credits. We never receive or store your full card number.
4.9 Usage and telemetry
Counts of how many applications you ran per day and per billing period, and the metering counts behind Morrow’s model calls (number of calls, tokens and cost — never the text sent or received).
Separately we collect product telemetry to find and fix failures. Telemetry is pseudonymous, not anonymous: each event carries a keyed one-way hash of your account id computed with a secret only our server holds. It carries nothing else that identifies you. The only values a telemetry event is allowed to contain are the applicant-tracking system’s name, an outcome, a duration, a time-to-approve bucket, an error code, a count, your plan tier, your platform and the app version. Field labels, field values, question text, names, emails, phone numbers, resume text, job URLs and screenshots are forbidden and rejected by the database itself.
Telemetry is deleted after 180 days. It is the one category that is not deleted when you delete your account; see section 8.
4.10 Email and support
We queue transactional email for sending: your receipt notices and your daily recap. Those messages carry company names, counts and links to your own receipts, never your answers, question text, resume text or job URLs. Queued messages are deleted 30 days after they are sent.
When you write to us at hello@morrowhq.app, your message is delivered into our Google Workspace mailbox at aelgazar@simkinselgazar.com by a routing rule, and it is kept there so we can answer you and keep a history of the conversation. Our reply comes back from hello@morrowhq.app. We keep support mail for 12 months.
4.11 Waitlist
If you gave us your email address on our website before launch, we hold that address and where it came from. We delete it when you unsubscribe, when you create an account with the same address (it is merged into the account), or 12 months after launch day, whichever comes first. Every email we send to a waitlist address carries an unsubscribe link.
4.12 Replay records
To make sure a network retry never submits your application twice, we store the response to certain worker calls for 7 days. For one of those calls the stored response contains a copy of your answer bank and your name, email and phone number. It is readable only by our own servers, never by any user, and it is deleted with the rest after seven days.
We use what we hold for these purposes and no others: to run your account and sign you in; to fill and submit the applications you picked; to remember your answers so you are asked once; to show you an application before it is sent and record what was sent; to honour the Nothing-False Guarantee and the Receipt Guarantee; to bill you and manage your subscription; to send you receipts, recaps and service notices; to answer your support messages; to keep the service secure and to rate-limit abuse; and to find and fix failures using pseudonymous telemetry.
Repeat-trial detection. We use your name, email address, phone number and payment method to detect a second free trial on the same person. That is a use of your personal information and we disclose it here rather than bury it in the Terms.
Deletion. You can delete your account from inside the app, or from the Delete my account page at /account/delete, signed in or signed out. Deletion removes your stored screenshots, releases any Founding Hundred seat, clears your rate-limit state, deletes your sign-in record, and cascades to every row tied to your account: your picks, holds, answers, receipts and receipt field lists, parked questions, worker devices, push tokens, usage and credit history, and entitlements.
One category survives on purpose: telemetry events. Those rows carry a one-way keyed hash of your account id, not your account id, and no information that identifies you. They expire by themselves after 180 days. They are pseudonymous before your deletion and stay that way after it.
Access and a copy of your data. Write to hello@morrowhq.app and we will send you a copy of what we hold about you. Email hello@morrowhq.app and we will send you a machine-readable export within 30 days. There is no self-service export button yet; a later version will add one.
Correction. You can edit any answer in your answer bank in the app, and your profile details in your account settings.
California residents (CCPA/CPRA). You have the right to know what we collect, the right to delete it, the right to correct it, the right to a portable copy, the right to limit our use of sensitive personal information, and the right not to be discriminated against for exercising any of these. The categories we collect, and why, are in sections 4 and 5. We use sensitive personal information only to fill the applications you picked and to keep the record of what was sent, which is a permitted purpose that does not require a “Limit the Use of My Sensitive Personal Information” link; you can still remove those answers yourself at any time. We do not sell or share your personal information. Make a request at hello@morrowhq.app; we will verify it against your account email before we act on it, and you may use an authorised agent. [UNKNOWN: whether Morrow meets a CCPA applicability threshold at launch, which depends on user numbers. The risk assessment’s position is that CalOPPA and the app stores require this policy regardless, so it should not wait on the CCPA answer.]
Virginia residents (VCDPA). You have the right to confirm whether we process your personal data and to access it, to correct it, to delete it, to obtain a portable copy, and to opt out of targeted advertising, sale, or profiling with legal effects — none of which we do. Virginia’s law requires opt-in consent for sensitive data, and the self-identification answers in section 4.2 are saved only if you choose to save them. If we refuse a request you may appeal by replying to our decision at hello@morrowhq.app, and if the appeal is denied you may contact the Virginia Attorney General. [UNKNOWN: whether Morrow meets the VCDPA applicability threshold at launch. The risk assessment expects not, while noting Virginia is our home state and its Attorney General is the likeliest first regulator.]
Other states. If you live in a state with a comprehensive privacy law, you have broadly the same rights and can exercise them the same way. We honour requests without checking your address first.
Outside the United States. Morrow is operated from the United States and your information is processed there. If you are in a jurisdiction with laws such as the GDPR or UK GDPR, you have rights of access, correction, deletion, restriction, objection and portability, and a right to complain to your local supervisory authority. Our lawful bases are performance of our contract with you for running the service, your consent for the self-identification answers you choose to save, and our legitimate interests in security and in fixing failures. Morrow is sold in the United States only at launch. [UNKNOWN: counsel to confirm whether these generic rights are the right treatment for a US-only launch, or whether a transfer mechanism, an EU or UK representative, or an explicit geographic restriction is preferable.]
Morrow is not for children. You must be at least 18 years old to create an account, and we do not knowingly collect information from anyone under 18. If we learn that we have, we delete it. Eighteen is a confirmed policy decision, not a drafting default.
Encryption at rest is the platform default provided by our hosting providers, Supabase and Amazon Web Services. We do not add field-level encryption, per-user keys, or customer-managed keys on top of it.
Server logs are kept for 30 days.
No security claim in this section should be read as a promise that a breach cannot happen.
If we change this policy we will update the date at the top and post the new version on this page. If a change materially affects how we use your information, we will tell you by email or in the app before it takes effect. [UNKNOWN: the notice period counsel wants. The Terms draft uses 30 days for pricing changes, which would be a consistent choice.]
Simkins & Elgazar LLC
10612 Center Street
Fairfax, VA 22030
United States
hello@morrowhq.app
The decision is to publish this policy as v1 and redline it with counsel afterwards. Every business question that was open on the first draft has been answered and written into the text above. Four counsel markers remain, all of them legal, plus one [EFFECTIVE DATE] flag that is filled in at publication rather than decided.
The four remaining markers
Counsel should also rule on three things this draft asserts that a court might read narrowly: whether describing our providers as service providers is correct for every row of the table in section 6, the model providers included, and whether a data processing agreement is in place with each of them, which the risk assessment lists as open scope; whether “we do not sell or share” is safe to state flatly given the no-retention routing to third-party model hosts; and whether the Nothing-False Guarantee’s dependence on a screenshot we delete at 90 days needs a matching sentence in the Terms, since the durable evidence after 90 days is the field list, not the image.
Answered by Ahmed and the PM, 2026-09-10 — now stated as fact above
| Question | Answer written into the policy |
|---|---|
| Effective date | The day the policy is first published at morrowhq.app; a single [EFFECTIVE DATE] flag marks where the date goes. |
| Entity and address | Simkins & Elgazar LLC, 10612 Center Street, Fairfax, VA 22030, United States (sections 1, 13). |
| Minimum age | 18, confirmed as policy rather than a drafting default (section 9). |
| Queued email retention | Deleted 30 days after sending (section 4.10). |
| Support mail retention | 12 months (section 4.10). |
| Worker-side local cleanup (E37) | Implemented: per-application screenshot deletion on every terminal path, a 24-hour crash sweep at start-up, and the engine's failure log cleared after 7 days. Verified in the worker's config.rs, which defines a 24-hour screenshot age and a 7-day failure-log age and truncates the log on the start-up sweep (section 3). |
| Encryption at rest | The platform default from Supabase and Amazon Web Services, with no field-level encryption, per-user keys or customer-managed keys, stated in exactly those terms (section 11). |
| Hosting log retention | 30 days (section 11). |
| Support mail path | Google Workspace mailbox aelgazar@simkinselgazar.com; Resend sends only (sections 4.10, 6). |
| Geographic scope | United States only at launch (section 8). |
| Data export | Manual on request to hello@morrowhq.app, machine-readable, within 30 days; self-service in a later version (section 8). |
| Employer-portal credentials | None stored in V1, stated plainly with no hedge (section 3). |