Most privacy writing treats “on-device” as straightforwardly better. It is not; it is a trade, and if you pick the wrong side of it you will be annoyed the day you change phones.
What each approach actually means
Cloud: you create an account, and your alarms, settings and history live on the developer's servers as well as your phone. Sign in elsewhere and everything follows you.
On-device: everything lives in the app's private storage on your phone. There is no account and nothing to sign into. The app cannot see your data because it never receives it.
Side by side
| Cloud, with an account | On-device, no account | |
|---|---|---|
| Sync across devices | Yes | No |
| Survives a lost phone | Yes | No, history is gone |
| Data on someone's server | Yes | No |
| Can be breached | Yes, in principle | No server to breach |
| Survives the company shutting down | Often not | Keeps working offline |
| Password to manage | Yes | No |
| Works with no connection | Usually, with caveats | Always |
| Restoring a purchase | Via the account | Via your Apple Account |
The honest case for the cloud
We build an on-device app and we still think this is underrated:
- Losing a phone is more common than being breached. For most people, most of the time, the practical risk of losing data exceeds the practical risk of a leak.
- Sync is genuinely convenient if you use more than one device.
- Long-term records survive. If you want years of wake-up history, an account is how you keep it.
- Support can actually help you. With no account, we cannot look up your data, so we can only work from your description.
The honest case for on-device
- Nothing to breach. The strongest guarantee available, because it is structural rather than a promise about security practices.
- No password, and nothing to reset or lose.
- It keeps working if the company disappears. An alarm dependent on a server stops being an alarm when the server does. On-device apps keep ringing.
- Nothing to sell. Data that was never collected cannot be monetised later, or after an acquisition.
- Less to declare. This is why on-device apps tend to have short privacy labels.
The strongest privacy guarantee is not a promise about what we do with your data. It is not having it.
Which should you choose?
- Choose cloud if you use multiple devices, want a long-term record, or would be genuinely upset to lose your history when you upgrade.
- Choose on-device if you want no account, treat an alarm as a tool rather than an archive, or would rather not add another password.
For most people an alarm history is not a document they need for years, which is why we made the trade we did. But if you disagree, an account-based app genuinely serves you better and that is a legitimate reason to pick one.
What Mornio does, and what it costs you
Everything on device: no account, no email, no password, no Mornio server. Registered codes are stored as a salted one-way hash plus a label you choose.
The cost, stated plainly: your alarm history does not sync or back up. Change phones and it is gone. Your Pro purchase does restore, because it attaches to your Apple Account rather than to us, but the data does not. If that would bother you, we are the wrong app and you should choose one with an account.