Privacy Policy
Mortui is built on the principle that your data belongs to you. We've designed our system from the ground up to protect your privacy.
Last updated: July 2026
Our Privacy Principles
Local Storage
All behavioral data remains on your device. Zero cloud storage.
Minimal Collection
Only necessary behavioral metrics for core functionality.
Full Transparency
Clear documentation of what data is collected and how it's used.
User Control
Complete control over data collection and usage.
What Data the App Uses
Important: Mortui (the company) does not collect your data. The Mortui app processes data locally on your device only — it never leaves your phone, never goes to our servers, and is never shared with third parties.
Behavioral Metrics
The Mortui app processes behavioral data locally on your device for the purpose of establishing your baseline patterns and detecting anomalies. This data never leaves your device. This includes:
- App usage patterns: Aggregate counts of app opens, screen time duration, and interaction frequency (specific app names are hashed, not stored in plain text)
- Device interaction: Screen unlock frequency, notification interactions, typing activity patterns
- Physical activity: Step counts and movement patterns from device sensors
- Circadian data: Typical active hours and sleep patterns based on device usage timing
Configuration Data
Your configured preferences are stored locally on your device only:
- Action settings: Files to delete, recipients for messages, vault file settings
- Encrypted vault files: Files stored in the secure vault are encrypted on-device using AES-256-GCM. Only metadata (filename, size, date) is stored in the database; file contents remain encrypted on disk and are never transmitted to Mortui servers
- Authentication data: Hashed PIN, encrypted security questions, biometric enrollment status
- Email credentials: OAuth tokens or encrypted SMTP passwords for message delivery
What Mortui Does NOT Access
Because all data stays on your device, Mortui (the company) has no access to:
- Content of your messages, emails, or communications
- Your browsing history or website content
- File contents (deletion paths and vault files are stored locally; vault contents are encrypted and never leave your device except as attachments you configure)
- Location data or GPS coordinates
- Contacts, photos, or personal media
- Any data sent to third-party analytics services
How Mortui Uses Google User Data
Mortui offers optional email delivery through your own Gmail account. If — and only if — you choose to connect a Google Account, Mortui interacts with Google user data as described below. Connecting Gmail is entirely optional; the app functions without it. This section specifically governs Google user data obtained through Google APIs.
Data We Access
When you connect a Google Gmail Account, Mortui requests the following via Google OAuth:
- Send-only Gmail access (the
https://www.googleapis.com/auth/gmail.sendscope): permission to send email on your behalf. This scope grants no ability to read, search, download, modify, or delete any of your existing messages, drafts, contacts, or other mailbox content. - Your Google Account email address: obtained through Google Sign-In so the app can show you which account is connected and set it as the sender ("From") address.
How We Use It
The gmail.send authorization is used solely to send the messages you have pre-composed to the recipients you designate — either when you send a test message, or when Mortui's dead-man's-switch detects prolonged inactivity and executes your configured actions. Your account email address is used only to label the connected account in the app and as the sender address on those messages. Google user data is never used for advertising, profiling, training AI/ML models, or any purpose other than delivering the email you configured.
How We Share It
Mortui operates no servers or backend. Google user data is not sold, rented, or shared with any third party, advertiser, data broker, or analytics provider. The only transmission of this data is directly from your device to Google's Gmail API in order to send the message you composed. The recipients you designate naturally receive the email you chose to send them; no other data is disclosed.
Mortui's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
How We Store & Protect It
The OAuth tokens Google issues are stored exclusively on your device and never transmitted to Mortui. They are encrypted at rest inside a SQLCipher (AES-256) database whose key is held in the Android Keystore — hardware-backed on devices that support it. Mortui does not retain a copy of your Google credentials; Google manages your actual account authentication.
How Long We Keep It & How to Delete It
The OAuth token is retained only for as long as your Google Account remains connected. You can revoke Mortui's access to your Google user data at any time by:
- Disconnecting the account in the app (Email setup → remove the connected account), which deletes the stored token from your device;
- Using the in-app "Delete All Data" control or uninstalling Mortui, which removes all stored tokens and data; and/or
- Revoking access from your Google Account at myaccount.google.com/permissions, which invalidates the token independently of the app.
Because Google user data is stored only on your device and never on any Mortui server, deleting it locally removes it completely. For deletion questions you can also contact privacy@mortui.com.
Data Storage & Security
Your data is yours. Mortui (the company) cannot access it, cannot see it, and cannot share it. Everything stays on your device.
On-Device Only
All data processed by the Mortui app is stored exclusively on your device. Mortui (the company) does not operate cloud servers and cannot access your data. Your behavioral patterns, configuration, and all sensitive information never leave your device except when you explicitly trigger message delivery (and even then, only the message you compose is sent — not your behavioral data).
Encryption
All stored data is encrypted using industry-standard encryption:
- SQLCipher database encryption (AES-256)
- Android Keystore for key management
- Hardware-backed encryption where available
Data Retention
Behavioral data is retained for 90 days to maintain statistical accuracy. Older data is automatically deleted. You can delete all data at any time by uninstalling the application or using the in-app data deletion feature.
Third-Party Services
Email Delivery (Paid Tier)
When you configure email delivery, Mortui may interact with:
- Gmail API: If you connect your Gmail account via OAuth. Your Gmail credentials are managed by Google; we only store the OAuth token.
- Microsoft 365: If you connect your Outlook account via OAuth. Same OAuth token storage applies.
- Custom SMTP: If you configure a custom SMTP server. Your password is encrypted locally.
These services are only contacted when actions are executed. No data is shared with these services during normal operation.
No Analytics Services
The Mortui app does not use Google Analytics, Firebase Analytics, Crashlytics, or any other third-party analytics service. Mortui (the company) cannot track your usage patterns because your data never leaves your device. We do not share any data with advertisers or third parties.
Subscription Management
Subscription purchases are processed through Google Play. Google handles all payment information; we receive only subscription status confirmations, not your payment details.
Your Rights
Access
View all data stored about you through the app's settings.
Export
Export your data in a portable format at any time.
Deletion
Delete all your data instantly through in-app settings or by uninstalling.
Control
Modify what data is collected through granular permission controls.
Regulatory Compliance
GDPR Ready
Mortui's privacy-by-design architecture naturally aligns with GDPR requirements:
- Data minimization: We only collect necessary data
- Purpose limitation: Data used only for stated purposes
- Right to erasure: Easy data deletion available
- Data portability: Export functionality provided
- Privacy by design: Built into the architecture
Questions or Concerns?
If you have any questions about this privacy policy or our data practices, please reach out to us.