Mori
Privacy Policy
Effective 1 August 2026 · Last updated 1 August 2026
Mori is a private diary. It is built so that the ordinary way to use it involves no account, no server and no network at all, and so that the optional parts that do use a server take as little as they can and say exactly what they take.
The short version
- No account is required. Without one, nothing you write ever leaves your device.
- No analytics, no crash reporting, no advertising, no trackers. There are none in the app, at all.
- Speech is transcribed on your phone, by software running inside the app. Your voice is never uploaded for transcription.
- Your diary is encrypted on the device with SQLCipher.
- If you create an account, your entries, photos and recordings are copied to our sync server so a second device can see them. That is the only reason they are there.
- We never sell or share your data with anyone, for any purpose.
1. Who is responsible
Mori is published by Ibrahim Gul Butt, trading as Anggler (“we”, “us”), the data controller for the purposes of the UK GDPR, the EU GDPR and comparable laws.
Contact: Contact@anggler.com
2. What Mori does without an account
This is the default, and it is the whole app. When you have not signed in:
- Your entries, photos, recordings, moods and settings are stored only in Mori's own storage on your device, in a database encrypted with SQLCipher (AES-256). The key is held in the platform keystore.
- Nothing is transmitted anywhere. Mori does not contact us, and there is nothing for us to receive.
- We therefore hold no record that you use Mori at all.
The one exception is described in section 4.
3. Voice, transcription and text cleaning
Mori can turn a recording into text. This happens entirely on your device, using a speech-recognition model that runs inside the app. There is no speech service, no API key and no upload. Recordings are not sent anywhere for transcription, not to us and not to any third party.
The tidy-up Mori performs on a transcript is a set of fixed rules running on your device. It is not a generative AI model, it is not a cloud service, and by its construction it can only remove or reformat words you actually said. It cannot add any.
By default Mori keeps your recordings so you can play them back. You can change this, or delete recordings individually, under Profile → Privacy & security.
4. Network access without an account
The first time you use voice, Mori downloads the speech-recognition model, a one-time download of roughly 60 MB from huggingface.co, which hosts the model file publicly.
This is an anonymous request for a file. Nothing about you, your device or your diary is included. Hugging Face will see the request in their server logs as they would any download, including the IP address it came from. We receive nothing. After this one download, voice works permanently offline.
5. What happens if you create an account
An account is entirely optional and exists for one reason: so your diary survives a lost phone and appears on a second one. If you never make one, this section does not apply to you.
What we store when you sign up
| Data | Why |
|---|---|
| Email address | To identify your account, confirm it, and let you reset your password. |
| Password | Stored only as a salted hash by our authentication provider. We cannot read it. |
| Display name, if you set one | So Mori can greet you by name on a second device. |
| Sign-in timestamps and IP address | Recorded by the authentication provider for security and abuse prevention. |
What syncs
Once signed in, Mori copies the following to the sync server, and pulls back whatever your other devices have written:
| Data | Detail |
|---|---|
| Diary entries | Everything you wrote: title, body, the original transcript, the cleaned version, mood, language, the calendar day and time, and word count. |
| Transcript segments | The transcript broken into timed lines, so playback can follow the text. |
| Photos | The image files themselves, plus their size and format. Photos are re-encoded on the way into Mori, which removes EXIF metadata, so location coordinates from your camera are stripped before the photo is ever stored, let alone uploaded. |
| Voice recordings | The audio files themselves, plus duration and format. |
| Display name | Nothing else from your profile. |
What deliberately does not sync
- Your app-lock PIN and lock settings. These belong to one phone. Pushing a lock setting between devices is the wrong answer in both directions, so they stay put.
- Your other app settings: theme, reminders, retention choices, language, region.
- In-progress recording state.
- Your
.moribackup archives. Those are files you export and hold yourself; they are never uploaded.
Be clear about what this means
Cloud sync is the convenient tier, not the private one. Your synced entries are protected by transport encryption, per-user database access rules and storage encryption at rest, but they are not zero-knowledge. They are protected by access control, not by a key only you hold. That is the price of being able to reset a forgotten password without losing your diary.
If you want a copy that nobody but you can ever open, use
Profile → Export & backup to create a .mori archive.
It is encrypted with a passphrase you choose that never leaves your device,
and we cannot open it or recover it for you.
6. Where your data is held, and by whom
Authentication, the sync database and file storage are provided by
Supabase, Inc., acting as our data processor under a data
processing agreement. Your data is stored on Amazon Web Services infrastructure
in Tokyo, Japan (AWS ap-northeast-1).
Supabase, Inc. is incorporated in the United States and its staff may access the infrastructure from there for support and maintenance. If you are in the UK or the EU, your data therefore leaves your country. That transfer is covered by the Standard Contractual Clauses in our agreement with Supabase, together with the technical measures described in section 12. If you would rather no copy of your diary left your device at all, do not create an account, because Mori is a complete diary without one.
Supabase's own privacy notice is at supabase.com/privacy. They process this data only to provide the service to us, and are contractually barred from using it for anything else.
We use no other processor. There is no analytics vendor, no crash-reporting vendor, no advertising network and no attribution SDK in Mori.
7. Legal basis for processing
| Processing | Basis |
|---|---|
| Holding your account and syncing your diary | Performance of a contract (Art. 6(1)(b)). This is the service you asked for. |
| Security and abuse prevention on sign-in | Legitimate interests (Art. 6(1)(f)). |
| Diary content, which may reveal health, beliefs or other special-category data | Your explicit consent (Art. 9(2)(a)), given by choosing to sign in and enable sync. Withdraw it by signing out or deleting your account. |
Nothing in Mori is processed on the basis of consent for marketing, because Mori does no marketing.
8. How long we keep it
- Entries you delete are marked deleted immediately and stop appearing on every device. A deletion marker is retained so the deletion can reach your other devices.
- Your account and everything in it is deleted when you delete your account. See section 10. Deletion is immediate and cascading; it is not a soft delete and there is no recovery window.
- If you never sign in, we hold nothing to keep.
9. Device permissions
Mori asks for a permission only at the moment you use the feature that needs it, never at launch, and every one of them can be refused with the rest of the app still working.
| Permission | Asked when | Used for |
|---|---|---|
| Microphone | You tap to record | Recording a voice entry. Transcribed on-device. |
| Camera | You tap “Take a photo” | Attaching a photo you take. |
| Notifications | You turn on a reminder | Delivering the reminder you set. |
| Face ID / biometrics | You turn on biometric unlock | Unlocking the app. Handled by the operating system; Mori never sees your biometric data. |
Mori requests no location permission, no contacts permission and no broad media-library permission. Choosing an existing photo goes through the system photo picker, which hands Mori only the one file you picked.
10. Your rights, and how to exercise them
You have the right to access, correct, export, delete and restrict processing of your data, to withdraw consent, and to complain to a supervisory authority. Most of these are buttons in the app rather than requests you have to make of us:
- Access and portability: Profile → Export & backup exports your whole diary as PDF, plain text or Markdown, or as a complete encrypted archive. No request needed and no waiting.
- Erasure: Profile → Account → Delete account removes your account and every row, photo and recording belonging to it from our servers. See the account deletion page for the full procedure, including how to request deletion by email.
- Withdrawing consent to sync: sign out. Your diary stays on the phone, untouched; it simply stops syncing.
- Correction: edit any entry in the app.
For anything you cannot do in the app, write to Contact@anggler.com. We respond within 30 days. If you are in the UK or the EU and are unhappy with our response, you may complain to your national data protection authority.
11. Children
Mori is not directed at children under 13, and we do not knowingly hold data from them. If you believe a child has created an account, write to us and we will delete it.
12. Security
- The on-device diary is encrypted with SQLCipher (AES-256), with the key held in the Android Keystore or iOS Keychain.
- Optional app lock with a PIN or biometrics, and an automatic lock when Mori goes into the background.
- Android's automatic cloud backup is switched off, so your diary is never copied to Google Drive behind your back.
- Screenshots and screen recording of Mori are blocked on Android, and Mori is hidden in the app switcher.
- Everything in transit uses TLS.
- On the server, database rules make each account's rows unreadable to every other account, and photo and audio files sit in private storage keyed to your account.
.moribackup archives use Argon2id key derivation and AES-256-GCM, with a passphrase that never leaves your device.
No system is perfect. If you find a security problem in Mori, please write to Contact@anggler.com. We would much rather hear from you than not.
13. Changes to this policy
If we change this policy materially, particularly if Mori ever starts collecting something it does not collect today, we will update the date at the top and say so in the app before the change takes effect.