MorphlyDevelopers
Privacy PolicyTerms & ConditionsCookies Policy
Back to website
LEGAL

Privacy Policy

This policy explains how Morphly handles personal information across our website, developer platform, APIs, dashboards and related services.

Website
morphly.fun
Data controller
LUCKY-WEB, trading as Morphly
Effective date
July 28, 2026
Last updated
July 28, 2026
ON THIS PAGE
1. Introduction2. Scope of this Policy3. Information we collect4. How we collect information5. Why we use personal information6. Legal grounds for processing7. Images, video, voices and facial information8. AI processing9. How we disclose information10. We do not sell personal information11. Developer customers12. International data transfers13. Data retention14. Data minimisation15. Information security16. Security incidents and data breaches17. Your privacy rights18. How to exercise your rights19. Appeals20. Marketing communications21. Cookies and similar technologies22. Automated processing23. Children’s privacy24. Third-party applications and links25. Regulatory complaints26. Changes to this Privacy Policy27. Contact information

1. Introduction

This Privacy Policy explains how LUCKY-WEB, trading as Morphly (“Morphly,” “we,” “us,” or “our”), collects, uses, stores, discloses and protects personal information when you access or use:

  • morphly.fun;
  • The Morphly Developer Platform;
  • Morphly APIs;
  • Morphly dashboards;
  • Morphly applications;
  • AI video, image, voice and media services;
  • Subscription services;
  • Customer support; and
  • Other products or services provided under the Morphly name.

This Policy also explains the choices and rights that may be available to you.

Morphly acts as the controller of personal information collected for its own business purposes.

Where a developer customer submits personal information to Morphly through an API on behalf of that developer’s own users, Morphly may act as a processor or service provider for the developer.

2. Scope of this Policy

This Policy applies to:

  • Website visitors;
  • Registered users;
  • Developers;
  • API customers;
  • Subscription customers;
  • Referral participants;
  • People who contact support;
  • Representatives of business customers;
  • People appearing in submitted media; and
  • Other people whose personal information is processed through Morphly.

This Policy does not govern the independent privacy practices of third-party websites, developer applications or services that link to or integrate with Morphly.

3. Information we collect

The information Morphly collects depends on how you interact with the Services.

3.1 Account information

When you create or manage an account, we may collect:

  • Full name;
  • Email address;
  • Telephone number;
  • Username;
  • Account identifier;
  • Country or general region;
  • Password authentication records;
  • Business name;
  • Organisation information;
  • Account role;
  • Referral code;
  • Account status; and
  • Communication preferences.

Where passwords are managed by an authentication provider, Morphly does not receive your readable password.

3.2 Payment and billing information

When you purchase credits or a subscription, we may collect:

  • Package or plan purchased;
  • Payment amount;
  • Currency;
  • Transaction reference;
  • Payment date;
  • Payment status;
  • Billing history;
  • Renewal information;
  • Refund status;
  • Chargeback status;
  • Limited payment-method details;
  • Fraud-screening results;
  • Billing name;
  • Billing address; and
  • Tax or invoice information.

Full card details, card PINs, security codes and one-time passwords are normally collected directly by the payment provider and are not stored by Morphly.

3.3 API and developer information

When you use Morphly APIs, we may collect:

  • API-key identifiers;
  • Account identifiers;
  • API endpoint used;
  • Model selected;
  • Request time;
  • Request duration;
  • Processing duration;
  • Credits consumed;
  • Response status;
  • Error codes;
  • Request or job identifiers;
  • IP address;
  • Rate-limit information;
  • Authentication events;
  • Security events;
  • File metadata;
  • Request settings; and
  • Diagnostic information.

You should never send a complete active API key through ordinary email, public chat or screenshots.

3.4 User Content

Depending on the selected feature, Morphly may process:

  • Prompts;
  • Text instructions;
  • Uploaded images;
  • Photographs;
  • Reference photographs;
  • Uploaded videos;
  • Video frames;
  • Audio recordings;
  • Voice recordings;
  • Microphone audio;
  • Camera input;
  • Source files;
  • Generated content;
  • Transformed content;
  • Project names;
  • Processing settings; and
  • Other information you intentionally submit.

User Content may contain personal information about you or another person.

3.5 Device and technical information

We may automatically collect:

  • IP address;
  • Browser type;
  • Browser version;
  • Device type;
  • Operating system;
  • Application version;
  • Device language;
  • Time zone;
  • Referring page;
  • Pages visited;
  • Session information;
  • Login time;
  • Crash records;
  • Diagnostic logs;
  • Network information;
  • General location inferred from IP address; and
  • Security-related device information.

3.6 Communications

When you communicate with Morphly, we may collect:

  • Support messages;
  • Emails;
  • Refund requests;
  • Complaints;
  • Security reports;
  • Feedback;
  • Survey responses;
  • Attachments;
  • Screenshots;
  • Call or meeting notes; and
  • Other information included in your communication.

3.7 Referral information

Where you use a referral feature, we may collect:

  • Referral codes;
  • Referring account identifiers;
  • Referred account identifiers;
  • Qualifying purchase status;
  • Reward status;
  • Fraud indicators; and
  • Information needed to prevent self-referrals and abuse.

4. How we collect information

Morphly may collect information:

  • Directly from you;
  • Automatically through the website or application;
  • Through API requests;
  • Through cookies and similar technologies;
  • From payment providers;
  • From authentication providers;
  • From hosting and infrastructure providers;
  • From referral links;
  • From fraud and security providers;
  • From a developer customer using our API; and
  • From public sources where legally permitted.

5. Why we use personal information

Morphly may use personal information to:

  • Register and maintain accounts;
  • Authenticate users;
  • Provide access to dashboards;
  • Issue and manage API keys;
  • Process AI and media requests;
  • Generate or transform content;
  • Store projects where requested;
  • Calculate usage;
  • Deduct credits;
  • Process payments;
  • Administer subscriptions;
  • Deliver promotional or referral credits;
  • Send receipts;
  • Send password-reset messages;
  • Send low-credit notifications;
  • Send account and security notices;
  • Provide customer support;
  • Investigate failed requests;
  • Detect fraud;
  • Prevent abuse;
  • Apply rate limits;
  • Protect infrastructure;
  • Enforce platform policies;
  • Improve reliability and performance;
  • Fix software defects;
  • Analyse service usage;
  • Maintain financial records;
  • Comply with law;
  • Establish or defend legal claims; and
  • Send marketing communications where permitted.

6. Legal grounds for processing

Where applicable law requires a legal basis, Morphly may rely on one or more of the following.

6.1 Contract

We process information where necessary to:

  • Create your account;
  • Provide the requested Services;
  • Process your API requests;
  • Deliver generated Output;
  • Manage your credits;
  • Process purchases;
  • Manage subscriptions; and
  • Provide customer support.

6.2 Consent

We may rely on consent for:

  • Optional marketing communications;
  • Non-essential cookies;
  • Certain sensitive-data processing;
  • Optional model-improvement programmes; or
  • Another purpose for which consent is required.

You may withdraw consent at any time.

Withdrawal does not affect processing that was lawful before consent was withdrawn.

6.3 Legal obligation

We may process information where necessary to comply with:

  • Tax requirements;
  • Accounting requirements;
  • Court orders;
  • Regulatory requirements;
  • Law-enforcement requests;
  • Consumer-protection obligations;
  • Data-protection obligations; or
  • Other legal duties.

6.4 Legitimate interests

We may process information where reasonably necessary to:

  • Secure the Services;
  • Prevent fraud;
  • Maintain business records;
  • Improve platform performance;
  • Investigate misuse;
  • Protect users;
  • Enforce agreements;
  • Manage business operations; and
  • Communicate with existing customers about related Services.

We will consider the effects on your rights before relying on legitimate interests.

6.5 Protection of vital interests

In limited circumstances, information may be processed where necessary to protect someone’s life, physical safety or other vital interests.

7. Images, video, voices and facial information

Morphly may process images, video frames, faces, voices and audio where you intentionally submit them to use an AI or media feature.

This information may be used to:

  • Generate a video;
  • Transform an image;
  • Animate a photograph;
  • Process a real-time stream;
  • Modify a voice;
  • Produce requested Output;
  • Diagnose a failed request; or
  • Investigate fraud or abuse.

Morphly does not intend to use submitted faces or voices for covert biometric surveillance or identity tracking.

Morphly does not perform biometric identification unless a separate feature expressly describes that purpose and all legally required permissions have been obtained.

You must not submit another person’s face, voice, image, video or private information unless you have a valid legal basis and all required permissions.

8. AI processing

Morphly may transmit User Content and associated technical information to third-party AI infrastructure providers to complete a requested service.

Depending on the feature, transmitted information may include:

  • Prompts;
  • Images;
  • Video;
  • Video frames;
  • Audio;
  • Voice recordings;
  • Processing instructions;
  • Model settings;
  • Request identifiers; and
  • Technical metadata.

Morphly uses User Content to provide, secure, maintain and support the Services.

Morphly does not sell private User Content.

Morphly does not use private User Content for targeted advertising.

Morphly will not intentionally use private User Content to train a general-purpose Morphly model unless:

  • The practice is clearly disclosed;
  • An appropriate legal basis exists; and
  • Consent is obtained where required.

Third-party AI providers may process information under their own contractual and privacy obligations.

Do not submit highly sensitive information unless it is necessary and you have confirmed that the selected Service is appropriate for that information.

9. How we disclose information

Morphly may disclose information to service providers that perform functions on our behalf.

9.1 Supabase

Supabase may be used for:

  • Authentication;
  • Account databases;
  • User profiles;
  • Credit balances;
  • Application data;
  • Storage; and
  • Backend infrastructure.

9.2 Flutterwave

Flutterwave may be used for:

  • Payment processing;
  • Payment verification;
  • Refunds;
  • Transaction records;
  • Fraud prevention; and
  • Compliance screening.

9.3 Resend

Resend may be used to send:

  • Welcome emails;
  • Verification messages;
  • Password-reset messages;
  • Purchase receipts;
  • Low-credit warnings;
  • Suspension notices;
  • Security alerts; and
  • Other transactional communications.

9.4 Decart and other AI providers

Decart or another AI provider may process:

  • Prompts;
  • Images;
  • Videos;
  • Video frames;
  • Audio;
  • Processing settings; and
  • Other information required to perform an AI request.

9.5 Hosting and infrastructure providers

Vercel or another hosting provider may process technical data needed to host and deliver Morphly’s website, dashboard or APIs.

9.6 Analytics, logging and security providers

Morphly may use providers that help:

  • Analyse platform usage;
  • Detect errors;
  • Monitor performance;
  • Prevent fraud;
  • Investigate incidents; and
  • Secure the Services.

9.7 Professional and legal recipients

Morphly may disclose information to:

  • Lawyers;
  • Accountants;
  • Auditors;
  • Insurers;
  • Consultants;
  • Regulators;
  • Courts;
  • Law-enforcement agencies; and
  • Other professional advisers.

Such disclosure will occur only where appropriate and legally permitted.

9.8 Business transfers

Information may be disclosed in connection with:

  • A merger;
  • Acquisition;
  • Investment;
  • Financing;
  • Restructuring;
  • Sale of assets; or
  • Transfer of the Morphly business.

Any recipient will remain subject to applicable privacy obligations.

10. We do not sell personal information

Morphly does not sell personal information in exchange for money.

Morphly also does not sell private User Content.

Where an applicable privacy law defines “sale” or “targeted advertising” more broadly, you may contact Morphly to exercise any applicable opt-out right.

11. Developer customers

Where a developer submits personal information through the Morphly API, the developer is responsible for:

  • Providing its own privacy notice;
  • Establishing a valid legal basis;
  • Obtaining consent where required;
  • Informing users that Morphly or an AI provider will process their information;
  • Collecting only necessary information;
  • Protecting API credentials;
  • Responding to user requests;
  • Handling complaints;
  • Complying with children’s privacy laws; and
  • Avoiding unlawful surveillance or data collection.

Morphly may provide a separate Data Processing Agreement to qualifying business customers.

12. International data transfers

Morphly and its providers may process or store information in countries other than the country where you live.

International processing may be required to provide:

  • AI processing;
  • Cloud hosting;
  • Authentication;
  • Payment processing;
  • Email delivery;
  • Storage;
  • Security; and
  • Customer support.

Where legally required, Morphly will use reasonable safeguards for international transfers, which may include:

  • Contractual protections;
  • Data-processing agreements;
  • Transfer assessments;
  • Consent where appropriate; or
  • Providers operating under legally recognised safeguards.

13. Data retention

Morphly retains information only for as long as reasonably necessary for the purpose for which it was collected.

Retention may also be necessary to:

  • Maintain an active account;
  • Provide the Services;
  • Complete a requested generation;
  • Resolve a technical failure;
  • Maintain billing records;
  • Prevent fraud;
  • Investigate abuse;
  • Resolve disputes;
  • Enforce agreements;
  • Comply with tax or accounting obligations; and
  • Establish or defend legal claims.

13.1 Account information

Account information may be retained while your account remains active and for a reasonable period after closure.

13.2 Payment information

Transaction and billing records may be retained for the period required by accounting, tax, fraud-prevention and legal obligations.

13.3 API logs

API and security logs may be retained for:

  • Billing verification;
  • Security;
  • Fraud prevention;
  • Debugging;
  • Abuse investigations;
  • Support; and
  • Dispute resolution.

13.4 User Content

User Content may be retained:

  • While stored in your account;
  • While required to complete a request;
  • While required to investigate a failed request;
  • While required for security or abuse review;
  • Where you request continued storage; or
  • Where continued retention is legally required.

13.5 Deleted information and backups

Deleted information may remain temporarily in secure backups until the applicable backup cycle expires.

Morphly may retain anonymised or aggregated information that no longer identifies you.

14. Data minimisation

Morphly aims to collect and retain only information reasonably necessary to:

  • Provide the Services;
  • Operate the business;
  • Protect the platform;
  • Comply with law; and
  • Resolve disputes.

Users and developers should avoid submitting unnecessary personal or sensitive information.

15. Information security

Morphly uses reasonable technical and organisational safeguards designed to protect personal information.

These measures may include:

  • Secure authentication;
  • Access controls;
  • Encryption in transit;
  • Restricted administrative access;
  • Environment-variable and secret management;
  • Logging;
  • Monitoring;
  • Backups;
  • Fraud detection; and
  • Incident-response procedures.

No online service can guarantee absolute security.

You are responsible for:

  • Using a strong password;
  • Protecting your devices;
  • Protecting your API keys;
  • Restricting account access; and
  • Reporting suspected compromise promptly.

16. Security incidents and data breaches

Where Morphly becomes aware of a security incident involving personal information, Morphly will:

  • Investigate the incident;
  • Take reasonable containment measures;
  • Assess the likely risk;
  • Preserve relevant evidence;
  • Address the underlying issue; and
  • Notify affected people or regulators where required.

A notification may explain:

  • What happened;
  • What information was affected;
  • What Morphly has done;
  • What you should do; and
  • How to obtain additional assistance.

17. Your privacy rights

Depending on your location and applicable law, you may have the right to:

  • Know whether Morphly processes your information;
  • Request access to your information;
  • Request a copy of your information;
  • Request correction of inaccurate information;
  • Request deletion;
  • Request restriction of processing;
  • Object to certain processing;
  • Withdraw consent;
  • Request portability where applicable;
  • Opt out of direct marketing;
  • Opt out of sale where applicable;
  • Opt out of targeted advertising where applicable;
  • Opt out of certain profiling where applicable;
  • Obtain information about certain automated decisions;
  • Appeal a denied privacy request; and
  • Lodge a complaint with a regulator.

These rights are not absolute.

Morphly may retain information where necessary to:

  • Complete a transaction;
  • Comply with law;
  • Prevent fraud;
  • Protect security;
  • Protect another person’s rights;
  • Resolve a dispute; or
  • Establish or defend a legal claim.

18. How to exercise your rights

Submit a privacy request to:

privacy@morphly.fun

Include:

  • Your name;
  • Your Morphly account email;
  • The right you wish to exercise;
  • A description of the relevant information; and
  • Any information reasonably necessary to identify your account.

Morphly may request identity verification before processing a request.

Do not provide your password, API secret, card PIN, security code or one-time password.

Morphly will respond within the period required by applicable law.

19. Appeals

Where an applicable law provides an appeal right and Morphly denies your privacy request, you may appeal by emailing:

privacy@morphly.fun

Use the subject:

Privacy Request Appeal

Explain why you believe the decision should be reconsidered.

Morphly will review the appeal and respond within the period required by applicable law.

20. Marketing communications

Morphly may send:

  • Product updates;
  • Promotions;
  • Offers;
  • Referral announcements;
  • Educational content; and
  • Other marketing messages.

You may unsubscribe from promotional emails by:

  • Using the unsubscribe link;
  • Updating communication preferences; or
  • Contacting support.

Opting out of marketing does not stop essential communications such as:

  • Security alerts;
  • Password-reset messages;
  • Purchase receipts;
  • Billing notices;
  • Service announcements;
  • Low-credit notifications; and
  • Account-status messages.

21. Cookies and similar technologies

Morphly may use cookies, browser storage, pixels and similar technologies.

21.1 Essential technologies

Essential technologies may be used for:

  • Login;
  • Authentication;
  • Security;
  • Session management;
  • Fraud prevention;
  • User preferences; and
  • Core platform functions.

21.2 Analytics technologies

Analytics technologies may be used to understand:

  • Website traffic;
  • Feature usage;
  • Performance;
  • Errors; and
  • User navigation.

21.3 Marketing technologies

Marketing technologies may be used only where implemented and legally permitted.

Where consent is required for non-essential cookies, Morphly will request consent before activating them.

You can control cookies through your browser settings, but disabling essential cookies may prevent parts of Morphly from working.

22. Automated processing

Morphly uses automated systems to:

  • Generate or transform content;
  • Measure usage;
  • Deduct credits;
  • Detect suspicious activity;
  • Apply rate limits;
  • Detect prohibited requests;
  • Identify technical failures; and
  • Protect platform security.

Morphly does not intend to make decisions producing legal or similarly significant effects about users solely through automated processing without legally required safeguards.

23. Children’s privacy

Morphly is not intended for anyone under 18.

Morphly does not knowingly permit children to:

  • Create developer accounts;
  • Purchase Services;
  • Obtain API keys; or
  • Submit personal information directly.

Where you believe a child has submitted personal information without appropriate authorisation, contact:

privacy@morphly.fun

Morphly may delete the information and close the relevant account where appropriate.

Developers using Morphly APIs are responsible for determining whether their own service is directed to children and for complying with all applicable children’s privacy requirements.

24. Third-party applications and links

Morphly may contain links to third-party websites or may be integrated into applications operated by developers.

Morphly is not responsible for the independent privacy practices of those third parties.

Review the privacy policy of each third-party website or application before providing information.

25. Regulatory complaints

You may contact Morphly first so we have an opportunity to address your concern.

Depending on your location, you may also complain to an appropriate privacy or consumer-protection regulator, including:

  • The Nigeria Data Protection Commission, where applicable;
  • The Delaware Department of Justice, where applicable; or
  • Another competent regulator in your jurisdiction.

26. Changes to this Privacy Policy

Morphly may update this Policy when:

  • Services change;
  • Providers change;
  • Processing activities change;
  • Laws change;
  • Security practices change; or
  • Business operations change.

The updated Policy will display a revised effective date.

Material changes may be communicated through:

  • The website;
  • Your dashboard;
  • Account email; or
  • Another reasonable method.

27. Contact information

Data controller: LUCKY-WEB, trading as Morphly Business address: 651 N Broad Street, Middletown, Delaware Website: morphly.fun Privacy enquiries: privacy@morphly.fun General support: support@morphly.fun

MorphlyDevelopers

Questions about these policies can be sent to privacy@morphly.fun.

Privacy PolicyTerms & ConditionsCookies PolicyContact support