This notice describes what the current Morrovia product collects, stores, sends and derives, why it does so, and the controls available to you.Last updated 1 September 2026
The short version
Morrovia uses the details you provide to build, save and improve your trips. Guest drafts and recovery copies can remain on this device. Signed-in trips and profile choices are stored with your account. Optional analytics and affiliate attribution remain off until you allow them. Morrovia does not scan your inbox, sell travel, or silently turn one trip’s interests into permanent profile preferences.
Who is responsible
Shaun Whiting Limited, trading as Morrovia is the operator of Morrovia and the data controller for the personal data described in this notice. You can reach the monitored privacy contact through the contact form.
DATA AND PURPOSE
What Morrovia uses
These are the current product data categories and their operational purpose. Some fields are optional and appear only when you use the relevant feature.
Account and authentication
Name, email, account identifiers, verification state, authentication records, server-side sessions, IP address and user agent are used to create and secure your account. Better Auth handles email/password and session records. If you choose Google sign-in, Google supplies the provider identifier, verified-email state, email, name and profile image under the openid, email and profile scopes. Morrovia does not request Google Drive, Calendar, contacts or mailbox access.
Your control: You can update your name in Profile. Account access, correction and deletion requests currently use the manual privacy-contact process below.
Trips and planning content
Trip titles, free-text prompts, structured intent, routes, dates, nights, traveller count, destinations, coordinates, transport, budgets, constraints, selected places, bookings, notes, custom activities, URLs, itinerary items and recommendations are used to build, explain, save and edit your plan. Guest drafts and recovery state can be held in browser storage. Signed-in trips are stored in Morrovia’s Neon Postgres database.
Your control: You can edit trip content, remove plan items and request data rights. The Trips delete action currently soft-deletes a trip from normal account views; a permanent purge period has not been set.
Profile, preparation and memories
Language, usual interests, pace, hotel-move and budget preferences can be saved as profile defaults. Optional preparation fields can include nationality or nationalities, country of residence and passport-expiry month, but the product does not ask for a passport number, scan or image. Country stamps, notes and an optional memory photo can also be saved.
Your control: You can edit or remove profile defaults in Profile, override them on a trip, and remove stamps, notes or photos from Stamps. Never enter passport numbers, scans or photos.
Feedback, contact, sharing and email
Ratings and comments are stored for support and product improvement. Contact-form messages and reply addresses are sent through Resend to Morrovia's private monitored inbox and are not intentionally stored in Morrovia's database, though provider and hosting operational logs may exist. A trip gift stores the recipient email, optional note, private token hash, status and claim information. Transactional email records can include recipient email, subject, template, delivery status, provider ID and a bounded failure message.
Your control: Contact and feedback are optional. A gift is created only when you enter a recipient and confirm it. Do not send passwords, passport details or payment-card information through free-text fields.
Why Morrovia uses data
The legal basis depends on the purpose and circumstances. Current engineering evidence supports these candidates, which still require legal review:
Steps you ask Morrovia to take, and performance of the account and trip-planning service, for account, trip, support and import functions.
Legitimate interests where appropriate for security, fraud prevention, service reliability, support and limited product improvement, balanced against traveller rights.
Consent for optional product analytics and optional affiliate attribution. You can withdraw it at any time in Cookie settings.
Legal obligations where Morrovia must retain or disclose information to meet an applicable requirement.
PERSONALISATION
How personalisation works
Interests and preferences supplied for a trip may influence route scoring, night allocation, nearby suggestions, activities and recommendation ranking. Explicit profile defaults may seed an untouched future trip and nearby recommendations. Trip-specific edits take priority. Changing interests on one trip does not silently rewrite your permanent profile, and this is ordinary travel personalisation rather than sensitive profiling.
Edit or remove saved defaults in Profile. Remove or replace interests in the trip builder. A trip can keep its own choices without changing the profile used for future trips.
Luna is Morrovia’s AI travel assistant and uses the server-side OpenAI Responses API. Initial trip capture may send up to 600 characters from the prompt, plus fixed planning instructions, so OpenAI can return a bounded semantic interpretation and optional destination candidates. A signed-in co-pilot request may send your question, up to 500 characters, with a reduced trip view containing planning context such as stop names, dates, nights, transfers, itinerary text, preferences, constraints and readiness summaries.
The co-pilot view excludes canonical IDs, coordinates, URLs, confirmation references, provider payloads, owner and authentication data, change history and the raw initial brief. Requests currently use store:false, but that setting does not prove that provider retention is zero. OpenAI processing occurs outside Morrovia systems and may involve international processing. Provider retention and transfer safeguards still require contractual and legal review.
Luna can make mistakes. It cannot directly save a supported trip change: Morrovia creates a deterministic preview and you must review and apply it. The initial prompt and a resulting trip can still be stored by Morrovia as part of your draft or saved trip.
Speech input
Speak uses the browser’s SpeechRecognition or webkitSpeechRecognition service in English or Spanish, one shot at a time. The browser or its speech provider may process the audio. Morrovia receives the final transcript text rather than an uploaded audio file, but cannot prove that speech audio stays on-device or state the browser provider’s retention period.
The transcript is placed into the same editable field as typed text and does not submit automatically. If you submit it, it follows the same draft, AI and trip-storage paths as text you typed. You can deny microphone access and continue typing.
Location, place and accommodation searches
If you choose nearby search or allow browser location, coordinates are sent to Morrovia and can be passed to Google Places or OpenStreetMap-based services such as Nominatim, Overpass and Photon. Place queries can include a destination, country, planning area and nearby coordinates. Live Booking.com Demand searches can include coordinates, dates, adults, rooms, currency, booker country and locale. Search results do not become part of a saved trip unless you choose a place, pin, stay or booking.
Destination content and images
Morrovia can send place or route search terms to Wikipedia, Wikimedia and, when configured, Unsplash. Unsplash can also receive the provider-required download or selection event for a chosen image. Validated route-photo details and attribution may be cached on this device. Morrovia-provided editorial images are served as ordinary site assets.
Forwarded booking import
Forwarded booking import is optional and remains unavailable unless the server-side activation gates are configured. When you create a private alias and deliberately forward one confirmation, Resend receives that message. Morrovia verifies the private address and account sender, rejects attachments, and deterministically extracts a booking candidate for your review. Nothing is applied to a trip until an authenticated traveller confirms it.
Morrovia’s database stores the extracted candidate and provenance, deduplication fingerprints, status, trip suggestion, provider message ID and categorical security/processing result. It does not intentionally copy the raw subject, body, HTML, headers or attachment content into the Morrovia database. The received message remains subject to Resend’s own retention. Morrovia does not connect to or scan Gmail, Outlook or another mailbox.
COOKIES AND ANALYTICS
Necessary technology and optional measurement
Necessary session and security cookies keep signed-in accounts working. Functional browser storage supports language, trip handoff, private owner-scoped recovery, preferences and UI state. These do not depend on optional analytics consent.
When configured and allowed, PostHog and Google Analytics receive deliberately limited page and product events. PostHog automatic capture, session recording, heatmaps and similar automatic collection are disabled in Morrovia’s configuration. Optional affiliate attribution, including Omio Impact when configured, is a separate choice. Microsoft Clarity is disabled and is not active tracking.
Changing Cookie settings stops Morrovia’s optional event dispatch, opts out or resets configured analytics where supported, removes known Morrovia optional state and reloads after affiliate-attribution withdrawal. Browser code cannot guarantee deletion of records already held by a provider. Rejecting optional technology does not disable core planning or account functions.
Depending on the feature and deployment configuration, data can be received by the following services:
Neon for the server-side Postgres database; Better Auth as the authentication software used by Morrovia; and the deployed hosting/runtime provider for application delivery and operational logs.
Google when you choose Google sign-in, Google Places for configured nearby stay search, and Google Maps or Flights when you open an explicit external handoff.
Resend for contact-form and transactional email and, only when activated and deliberately used, a forwarded booking message.
OpenAI for initial semantic trip interpretation and signed-in Luna requests.
PostHog, configured Google Analytics and Omio Impact only after the matching optional choice.
OpenStreetMap services including Nominatim, Overpass, Photon and CARTO, plus Wikipedia, Wikimedia and Unsplash for configured map, place and image features.
Booking.com Demand for configured live accommodation search, and travel or affiliate providers when you choose to open their external links. Their sites handle their own checkout, payment and policies.
International processing
Some providers may process data outside the UK or EEA depending on their service location and Morrovia’s deployment configuration. The repository does not prove each processing location, transfer mechanism or contractual safeguard. Those facts remain a provider and legal review item. Opening an external provider also sends the normal browser request and any context visible in the destination URL to that provider under its own notice.
RETENTION
How long data is kept
Morrovia keeps account and saved-trip data while the account is active and as needed to provide the service, but fixed deletion periods are not yet implemented for most database records. Browser drafts, recovery copies, preferences and functional state generally remain until product cleanup runs or you clear Morrovia site data. A trip deleted in Trips is currently soft-deleted from normal views rather than immediately purged.
Account deletion is a verified manual support process. It removes the product user and its cascading trips, stamps, memories, booking aliases/candidates and co-pilot previews, plus the associated Better Auth sessions and accounts. The current operation retains a minimal account-deletion audit record. Transactional email events are keyed by recipient email and are not currently removed by that operation; gift-recipient records and some provider-held records can also remain. Preview expiry fields exist, but a broader purge schedule, including booking import, feedback, gifts, email events and audit records, is still an unresolved operating and legal item for retention work.
YOUR RIGHTS
Your data rights
Depending on the law and circumstances, you may have rights of access, correction, deletion, restriction, objection and data portability, and the right to withdraw consent. Morrovia does not currently provide a complete automated account export or self-service account deletion tool. A trip PDF is not a full account-data export.
Use the privacy contact form and enter the address on your Morrovia account.
Say which right you want to use and identify the account or trip involved. Do not send passwords, passport numbers or identity documents unless Morrovia specifically asks for a proportionate verification step.
Morrovia may verify that you control the account before disclosing, correcting, exporting or deleting data, and will explain if a request cannot be fulfilled in full.
You can edit your name and travel-profile defaults in Profile, edit trip content in the planner, and remove optional interests, memories and photos. Cookie consent can be withdrawn without contacting support.
If you have raised a concern with Morrovia and remain dissatisfied, you can complain to the UK Information Commissioner’s Office (ICO).
Morrovia still needs an approved retention schedule, verified hosting and processor locations, international-transfer safeguards, complete provider contract review, a confirmed public registered office and company-registration details, and solicitor review of its Terms. This notice does not invent those facts or claim legal certification.