Morrigan
Windows · Beta
My account ↗

Morrigan / Beta

Your data, explained.

Privacy notice for the Morrigan beta website and licensing service. Version beta-2026-09-10.

Loading operator details…

Account information

The website stores your email, a password hash, email verification time, agreement acceptance, session records, and account operations. We use them to provide access, recover accounts, enforce the evaluation limit, and investigate service problems. Passwords and raw license keys are not stored in plaintext. A newly issued key is returned once to your browser and is not saved in browser storage by the website.

Licensing information

Licensing is a separate service. The website sends an opaque account identifier and verification time to request a trial. The licensing service stores license status and expiry, key hashes, device public keys, hashed device identifiers, activation records, operating-system and device labels, and protocol/security events. Requests may also include network addresses and software versions. These records support activation, seat limits, revocation, abuse prevention, and qualified downloads.

Research content and AI providers

Your desktop workspace holds research artifacts locally. AI features send prompts and relevant content to the AI provider you configure, under that provider’s terms and privacy policies. Local storage does not mean that AI requests stay on your computer. The website does not automatically collect your APKs, traces, or research workspace. Diagnostic bundles you choose to send to support can contain sensitive research data and credentials; review them before sharing.

Transactional email

We use Resend to deliver verification, password reset, and account-security messages. Recipient addresses and message contents are sent to that provider. The website keeps an encrypted delivery queue for retries, clears message contents after successful delivery, and removes queue records after seven days. Delivery events are retained for 90 days. Marketing subscriptions, open tracking, and click tracking are not part of the beta account flow.

Cookies and logs

Essential cookies maintain your signed-in session and protect requests from forgery. The session cookie is inaccessible to page scripts and lasts up to seven days. There are no advertising or analytics cookies in this website. Application logs record route, status, timing, and request identifiers; reverse-proxy logs may include IP addresses and access times. Passwords, authorization headers, full license keys, and email-link tokens must not be included in those logs.

Retention and closure

Account information is kept while your account is active. Closing your account disables sign-in, revokes the trial, and replaces the sign-in email with an opaque placeholder. The website retains a keyed hash of the normalized email and the original verification time to prevent repeated trials. Agreement acceptance and minimal trial records remain for accountability and abuse prevention. Account audit events are retained for up to two years; expired sessions are removed daily.

Licensing records and backup copies follow the operator’s documented retention schedule. Jurisdiction-specific retention periods, processing grounds, hosting locations, international transfers, and the treatment of backup copies must be finalized before registration opens.

Your choices and contact

You can reset your password, manage your device, and close your account from the website. Contact the operator above to request access, correction, deletion, or information about handling your data. Applicable privacy rights, supervisory-authority details, and any required legal basis will be completed for the operator’s jurisdiction before launch.