Translation notice. This is an English translation provided for convenience only. The Simplified Chinese version is the governing text; in the event of any discrepancy, the Simplified Chinese version prevails. This translation has not been reviewed by counsel qualified in your jurisdiction.
Last updated: 31 July 2026
Effective date: 31 July 2026
Welcome to the "Morphly" product and the related services we provide (the "Services").
The app operator ("we", "us" or the "Platform") is keenly aware of the importance of personal information to you. We will strictly comply with laws and regulations and protect your personal information and privacy on the principles of legality, propriety, necessity and good faith.
This Privacy Policy will help you understand how we collect, use, store, share and protect your personal information, and how you can manage your own information. Please read and fully understand this Policy before using the Services, in particular the provisions highlighted in bold.
If you do not agree with any part of this Policy, please stop using the Services immediately; your continued use of the Services signifies that you have understood and agreed to all provisions of this Policy.
In addition to this Privacy Policy, in specific scenarios we will also explain to you the corresponding purpose, scope and manner of information collection through just-in-time notices (including pop-ups and on-page prompts) and feature-update descriptions. Such just-in-time notices and feature-update descriptions form part of this Privacy Policy and have the same effect as it.
The following will help you understand in detail how we collect, use, store, disclose and protect personal information, and how you can manage your personal information:
1. How we collect and use personal information
2. Use of cookies and similar technologies
3. Rules on cooperation with third parties and on transfer and disclosure of information
4. How personal information is stored
5. Notes concerning algorithmic models
6. How we protect the security of personal information
7. Managing your personal information
8. Protection of minors' personal information
9. Updates to and notification of this Privacy Policy
10. How to contact us
We follow the principles of legality, necessity and transparency, and collect your personal information only within the minimum scope required for the specific function concerned.
1.1 Account services
You can complete account creation without providing additional information, so that we can provide you with user services.
1.2 Content-generation services
1.2.1 Description of the function
Based on generative artificial-intelligence model technology, we provide you with services for generating AI content such as images.
1.2.2 Uploading, creating, editing and storing
In order to complete content generation, the original material you actively enter or upload — text, images, audio and the like (including content produced by speech-to-text conversion) — will be transmitted back to our servers for processing.
When you upload, create, edit or publish images, text or other content yourself, we may need to request the following permissions from you or collect the following information:
You have the right to refuse or withdraw authorisation. If you do not consent, or you withdraw your authorisation, you will be unable to use the corresponding function, but this will not affect your normal use of other functions.
1.3 Records of usage behaviour
While you browse content or publish information, we record your use, including clicks, browsing, sharing and downloads.
When you share information or receive information shared by others, we read the codes, links and similar content in your device clipboard in order to complete page redirection or accurate content sharing.
1.4 Feedback and customer-support communications
When you lodge a complaint, enquiry or appeal, in order to contact you promptly and resolve the issue effectively, we may collect contact details such as your mobile number and email address. If you do not provide them, we may be unable to give you the outcome of our handling.
1.5 Service operation and safeguarding secure running
1.5.1 Security and stable operation
We are committed to providing a secure and trustworthy product environment. To maintain the normal operation of the Services and protect your lawful rights and interests and those of other users, we collect information necessary for secure operation. Such information may be used for identity verification, security protection and fraud monitoring, so as to prevent, detect and investigate fraud, security threats, unlawful activity or conduct in breach of the agreements.
The categories of information specifically collected include:
1.5.2 Device information and log information
1.6 Message notifications
You understand and agree that we may send notices through one or more of the contact details you provide in the course of using the product (such as contact telephone number and email address), covering matters including without limitation user-message notifications, identity verification, security reminders and user-experience research.
1.7 Notice concerning changes to service content
As the business develops, we may adjust the functions of "Morphly" and the services provided. In principle, where a new function or service is related to a current function or service, the personal information collected and used will bear a direct or reasonable connection to the original processing purpose. If, following the adjustment, the purpose, manner or scope of processing personal information in the product or service changes, we will inform you again and obtain your consent in accordance with law.
1.8 Third-party SDKs and management of device permissions
So that Morphly can run properly on different mobile devices and third-party platforms, and to support functions such as identity authentication, device security and sharing to social platforms, we have integrated third-party SDKs. The providers of these SDKs include mobile-device manufacturers, social platforms and telecommunications carriers. Some third-party SDKs may invoke your device permissions or obtain related information about you, which may specifically include: location information, reading and writing external storage cards, reading phone state and identity, viewing WLAN connections, retrieving running applications and Bluetooth status. The permissions invoked and the types of information obtained may differ between SDKs. We recommend that you consult the service agreement and privacy policy of the relevant third party to understand its specific data-processing practices.
1.8.1 Notes on the app's use of device permissions
When you use the Morphly app, we apply to the system for the following device permissions in order to ensure that functions work properly. Before each permission is first invoked, a dialog will seek your consent, and you may choose "Allow" or "Deny". After granting a permission, you may turn it off at any time in system settings. Turning off a permission will only render the corresponding business function unavailable; it will not affect your use of other functions.
You can review permission details in the app (Settings → Permission List) and manage permissions in your device's system settings. The way permissions are displayed and controlled may differ slightly between devices or system versions; the device manufacturer's documentation prevails.
| Permission | Purpose | When requested | Can it be turned off? |
|---|---|---|---|
| Wireless network | Supports network communication for all business functions | Dialog on first opening the app | Yes |
| Storage | Saves images, files, logs, content supplements, interaction information and the like | Dialog on first opening the app | Yes |
| Photo album | Uploading images and saving images to the album | Dialog on first saving an image/video | Yes |
| Camera | Taking photos for upload; recognising image content and returning intelligent analysis results | Dialog on first using the camera to shoot | Yes |
| Microphone | Interacting by voice input and converting speech to text | Dialog on first using the relevant function | Yes |
1.8.2 Notes concerning AI services
How the technology works
The AI image-generation function in this application is underpinned by models provided by a third-party artificial-intelligence technology service provider. When you actively enable this function, the content you enter is sent to that provider over an encrypted transmission channel (TLS 1.2 or above), which invokes the model and returns the generated result. We transmit only the minimum volume of data strictly necessary to complete the service.
What data we collect
Notes on facial data
We do not share the following information with third-party AI service providers:
How data is collected and transmitted
The above data is collected automatically only when you actively use the AI image functions, and is at all times transmitted over an HTTPS-encrypted connection.
Third-party service-provider information
We share and process the above data with the following third-party service provider:
Storage arrangements
Data protection and security
We have entered into data protection agreements (DPAs) with all third-party AI service providers that receive user data, confirming that they provide data-protection measures at a level equal to or higher than that of this Privacy Policy, including:
1.9 Performing obligations under laws and regulations
Under Article 10 of the Provisions on the Governance of the Online Information Content Ecosystem, where we discover unlawful or undesirable information in the Services, we must report the relevant records to the competent authority. Accordingly, we need to record and may provide to the competent authority the following log information: your account, time of operation, type of operation, network source and destination addresses, network source port, client hardware characteristics and the like, together with the content you have entered. In such statutory circumstances, our processing of your personal information does not require your separate consent.
1.10 Other data-processing situations
1.10.1 Use of de-identified information
We may de-identify your personal information by technical means, such that the processed information can no longer identify a specific natural person. In that case, we are entitled to use such de-identified information and, without disclosing your personal identity, to analyse and commercially exploit the user database.
1.10.2 Masking when information is displayed
When we display your personal information, we mask it using methods including content substitution and anonymisation, so as to protect the security of your information.
1.10.3 Interactive functions based on device motion
While you use this product, we may collect sensor information from your device in order to adapt to your device's state. For example, we use the gyroscope, accelerometer and gravity sensing to implement switching between portrait and landscape orientation, giving you a better experience. All sensor data is processed locally on your device. Please note that sensor data does not itself constitute personal information and cannot identify you either directly or in combination with other information.
1.10.4 Use of information beyond the scope of this Policy
Where we wish to use your personal information for purposes not set out in these rules, or to use information collected for a specific purpose for another purpose, we will seek your consent in advance. Please understand that the services we provide are constantly being updated and changed. If you choose to use other functions not yet set out in this Privacy Policy, then before we collect your personal information we will explain to you in detail, by agreement or on-page prompt, the purpose, manner and scope of the collection, and seek your express consent. If you do not agree to provide the foregoing information, you may be unable to use that service, but this will not affect your use of other services.
1.11 Circumstances in which your consent is not required
In the following statutory circumstances, our collection and use of your personal information does not require your authorisation and consent:
1.11.1 where necessary to conclude or perform a contract at your request;
1.11.2 where related to our performance of obligations imposed by laws and regulations;
1.11.3 where directly related to national security or national defence security;
1.11.4 where directly related to public security, public health or major public interests;
1.11.5 where directly related to criminal investigation, prosecution, trial and enforcement of judgments;
1.11.6 where necessary to protect major lawful rights and interests such as the life or property of you or another person, but consent is difficult to obtain from the individual;
1.11.7 where personal information that you have made public yourself, or other personal information already lawfully made public (such as personal information lawfully disclosed through lawful news reporting or government information disclosure), is processed within a reasonable scope;
1.11.8 other circumstances provided by laws and regulations.
It should be noted in particular that if information cannot identify you personally, whether on its own or in combination with other information, it does not constitute personal information in the legal sense. Once we use such unidentifiable data in combination with your personal information, it will, for the duration of that combined use, be treated and protected as your personal information in accordance with this Privacy Policy.
Cookies and similar device-identification technologies are techniques commonly used in internet services. When you use the Services, we may send one or more cookies or anonymous identifiers (collectively, "cookies") to your device by means of the relevant technology, in order to collect, identify and store information about your use of the Services.
Our principal purposes in using cookies are:
We undertake not to use cookies for any purpose other than those described in this Privacy Policy.
You may manage or delete cookies according to your own preferences. Most browsers provide a function for clearing browser cache data, and you can clear cookie data in your browser settings. Please note, however, that after clearing, the normal use of certain functions or services that rely on cookies may be affected.
3.1 Principles for using data jointly with partners
3.1.1 We follow three basic principles:
Where the processing of personal information is entrusted to another party, we enter into the relevant processing agreement with the entrusted partner in accordance with law and supervise its personal-information activities.
3.1.3 Joint processing
Where personal information is processed jointly, we enter into the relevant agreement with the partner in accordance with law, setting out each party's rights and obligations, so as to ensure compliance with the relevant provisions of law and the protection of data security in the course of using the personal information concerned.
3.1.4 Description of cooperation scenarios
Where a specific function or scenario involves services provided by our affiliates or third parties, the scope of partners includes our affiliates and third parties.
3.1.4.1 Security and statistical analysis
In order to safeguard the security of accounts, services and content and to prevent harm to your lawful rights and interests and ours, our partners may use necessary device information, account information and log information.
3.2 Transfer of information
If we need to transfer your personal information by reason of merger, division, transfer of assets, dissolution or a declaration of bankruptcy, we will inform you of the recipient's name and contact details and require the recipient to continue to perform the obligations set out in this Privacy Policy. If the recipient changes the original purpose or manner of processing, it must obtain your consent afresh.
3.3 Disclosure of information
We will not proactively disclose information that you have not made public yourself, unless in compliance with national laws and regulations or with your consent.
3.4 Exceptions to sharing, transfer and disclosure of personal information
Under laws and regulations, your consent is not required for sharing, transferring or disclosing your personal information in the following circumstances:
1) where necessary to conclude or perform a contract to which you are a party, or to carry out human-resources management under lawfully formulated labour rules and a lawfully concluded collective contract;
2) where necessary to perform a statutory duty or statutory obligation;
3) where directly related to national security or national defence security;
4) where directly related to criminal investigation, prosecution, trial and enforcement of judgments;
5) where necessary to respond to a public-health emergency, or, in an emergency, to protect the life, health and property safety of a natural person;
6) where personal information is processed within a reasonable scope for news reporting, supervision by public opinion and similar activities in the public interest;
7) where personal information that an individual has made public, or that has otherwise been lawfully made public, is processed within a reasonable scope in accordance with the relevant provisions of law;
8) where personal information is collected from lawfully and publicly disclosed information;
9) other circumstances provided by laws and administrative regulations.
4.1 Storage location
We store within the territory of the People's Republic of China the personal information collected and generated in the course of operations within that territory. If your personal information needs to be transferred from within the territory to outside it, we will act strictly in accordance with the provisions of law and obtain your separate consent.
4.2 Retention period
4.2.1 General principle: we retain your personal information only for the time necessary to achieve the purposes of the Services and for the retention periods provided by laws and regulations.
4.2.2 Termination of services: if "Morphly" terminates its services or ceases operations, we will notify you in advance by service or public announcement, and will delete or anonymise your personal information within a reasonable period after the termination of services or operations.
4.2.3 After account deletion or data deletion: when you delete your account, delete personal information yourself, or the retention period expires, we will delete or anonymise your personal information, save in the following cases:
You shall ensure that the content you enter is lawful and compliant, does not infringe the rights of any third party, does not involve undesirable information, and does not contain content relating to politics, violence or pornography. If your improper use causes harm to the rights and interests of any third party, you will bear the corresponding liability in accordance with law. The output of "Morphly" is generated by algorithms; "Morphly" gives no warranty as to the generated content and accepts no legal liability for it. Algorithmically generated content does not represent the attitude, views or position of "Morphly".
6.1 We attach great importance to the security of your personal information, and will take reasonable technical and managerial measures to protect your personal information from improper use or unauthorised access, disclosure, use, modification, damage, loss or leakage.
6.2 We protect your personal information using encryption technology, anonymisation and other reasonably practicable means at a standard no lower than prevailing industry practice, and we have established security-protection mechanisms to guard against malicious attacks.
6.3 We have established dedicated security-management systems and data-security procedures, implement strict data-access controls to ensure that only authorised personnel can access your personal information, and conduct security audits of data and technology at appropriate intervals.
6.4 Although we have taken the above reasonable and effective measures and complied with the relevant provisions of law, please understand that, because of technical limitations and the possible existence of malicious means, it is not possible in the internet industry to guarantee information security one hundred per cent at all times. We will use our best efforts to ensure the security of the personal information you provide to us.
6.5 You acknowledge and understand that the systems and communications networks you use to access our services may experience problems owing to factors beyond our control. We therefore strongly recommend that you take active measures to protect the security of your personal information, including without limitation using complex passwords, changing passwords regularly, and not disclosing your account password and related personal information to others.
6.6 Once you leave "Morphly" and the related services and browse or use other websites, applications, services or content resources, we will be unable to continue to protect any personal information you submit on those external platforms, whether or not you reached them via a link or referral from the Services.
We attach great importance to your autonomous control over your personal information, and do our utmost to protect your rights to access, copy, correct, supplement and delete your personal information, to withdraw consent and authorisation, to delete your account, to lodge complaints and reports, and to configure privacy features, so that you are able to safeguard your privacy and information security.
Please understand that particular business functions and services require your information in order to be delivered. Once you withdraw your consent or authorisation, we will be unable to continue providing the functions and services corresponding to the withdrawn consent or authorisation, and will no longer process the corresponding personal information. However, your decision to withdraw consent or authorisation will not affect the processing of personal information previously carried out on the basis of your authorisation.
7.1 How to exercise personal-information rights
If you, or another party you have authorised, wish to exercise the personal-information rights conferred by the relevant laws and regulations, you may contact us by email at morphlyivai@gmail.com. We will respond within 15 working days after verifying your identity.
7.2 Managing system permissions
You can go directly to your device's system settings to manage permissions such as location, contacts, microphone, camera, photo album, calendar, storage and phone state (names may differ between devices; the actual name on your device prevails), so as to change the scope of authorisation or withdraw it. You can also tap Settings → Permission List in the Morphly app to view the description of permission requests and their purposes.
7.3 Account deletion
You may apply to delete your account through the feedback page of "Morphly" or by sending an email to morphlyivai@gmail.com. We will act promptly on receipt of your application and complete our response within 15 working days or within the period required by laws and regulations. Before deletion, we will verify your personal identity, security status, device information and the like.
Please note that account deletion is irreversible. After deletion, we will delete or anonymise your relevant information (unless laws or regulations provide otherwise). You will be unable to sign in to "Morphly" with that account, and will be unable to recover any content or information associated with it. In addition, you remain responsible for your conduct in using the Services prior to deletion.
7.4 Feedback, complaints and reports
You may lodge complaints or reports through the channels we publish. If you have any comment, or consider that your personal-information rights and interests may have been infringed, or discover relevant leads, you may submit them on the user-feedback page in the app, or contact us by email at morphlyivai@gmail.com.
7.5 Viewing this Privacy Policy
You may view the content of this Privacy Policy via app → Settings → Privacy Policy.
Please note that the services described in this Privacy Policy may differ depending on factors such as the device model, system version and application version you use. The services you actually use prevail.
7.6 Handling on cessation of operations
If we cease operations, we will promptly stop collecting your personal information, notify you by individual service or by public announcement, and delete or anonymise the personal information of yours held in respect of the discontinued product or service.
We attach great importance to the protection of minors' personal information.
9.1 As the services are continually optimised, the app's related services may be updated from time to time. We will revise this Privacy Policy accordingly. We will not diminish the rights to which you are entitled under the version currently in force without your express consent.
9.2 After this Privacy Policy is updated, we will publish the updated version in the app so that you can learn its latest content in good time.
9.3 We may also help you better manage your personal information by way of feature updates; please pay attention to the relevant feature descriptions.
If you have any question, complaint, comment or suggestion concerning the protection of personal information or the AI generation services, you may contact us by: