Skip to main content

LegalUpdated September 2026

Privacy policy

What personal data MorningRead processes, why, who we share it with, and the rights you have.

MorningRead (“we”, “us”) delivers one personalized research paper each morning with optional AI summaries. This policy explains what personal data we process, why, the legal basis, who we share it with, and the rights you have under the EU and UK General Data Protection Regulation (GDPR).

1. Data controller

MorningRead is the data controller for the personal data described here. For any privacy request, contact hello@morningread.ai.

2. Data we collect

  • Account: email, name, and, if you sign in with ORCID, Google, GitHub, or Apple, the identifier and profile fields that provider returns. Email and password accounts store a salted bcrypt hash, never the password itself.
  • Research profile: your interests and keywords, followed and excluded journals, affiliation, and reading preferences (summary length, expertise level, model, delivery time, time zone).
  • Usage: which papers were recommended, viewed, saved, or marked read; AI summaries generated for you; questions you ask in Q&A.
  • Device: a push notification token and delivery settings, if you turn on notifications, and basic security logs (IP address, timestamp) for sign-in attempts.

3. Why we use it, and the legal basis

  • Providing the service (recommendations, summaries, Q&A, notifications): performance of a contract.
  • Account security (sign-in attempt logging, lockout): legitimate interests.
  • Analytics and advertising, only if you accept them in the cookie banner: consent, which you may withdraw at any time.

4. Who we share data with (processors)

  • OpenRouter: to generate summaries and answer Q&A, we send the article text and your question and expertise level. We do not send your name or email. If you provide your own AI key, requests use your key.
  • Sign-in providers (ORCID, Google, GitHub, Apple): only when you choose to sign in with them.
  • Apple Push Notification service and Web Push: to deliver the daily reminder, if you turn it on.
  • Google Analytics and Google AdSense: only after you consent in the cookie banner.
  • PubMed, Europe PMC, OpenAlex, Unpaywall: for article metadata. We send search terms, not personal identifiers.

5. International transfers

Some processors are located outside the EEA. Where that is the case, transfers rely on the provider’s Standard Contractual Clauses or an adequacy decision.

6. Retention

We keep your account and profile data while your account is active. Security logs are kept only as long as needed to protect the service. When you delete your account, your personal data is erased (see below); shared, non-personal caches of article metadata may be kept.

7. Your rights

  • Access and portability: export all your data as a JSON file. On the web, open Settings, then Account, then Export my data; in the iPhone app, Profile, then Export my data. You can also ask us for it.
  • Rectification: edit your profile and preferences at any time, in Settings on the web or Profile in the app.
  • Erasure: delete your account to permanently remove your personal data. On the web, open Settings, then Account, then Delete my account; in the iPhone app, Profile, then Delete account.
  • Withdrawing consent: change your analytics and ads choice at any time with Cookie settings in the footer.
  • Complaints: you may lodge a complaint with your local data protection authority.

8. Children

MorningRead is not directed to children under 16, and we do not knowingly collect their data.

9. Changes

We will post any changes here and update the date above. Material changes will be highlighted in the app.


See also our terms of service and cookie policy.