Every feature we did not build has a reason, and accounts are the one people ask about most, usually when they realise their history did not come across to a new phone.
The reasoning
We started from a simple question: what does an alarm actually need to know? A time. Optionally, a fingerprint of a code to check against. Neither requires knowing who you are.
Once you accept that, an account becomes something you would add for our benefit rather than yours: retention metrics, an email list, a channel to market through. Those are real business advantages and we decided they were not worth asking you for an identity to set an alarm.
The strongest privacy guarantee is not a promise about how we handle your data. It is not having it.
What is actually stored, and where
Everything lives in Mornio's private storage on your iPhone:
- Your alarms: times, repeat days, labels, settings.
- Your registered codes, as a salted one-way hash plus a label you choose. Never a photo, never the readable value.
- Your alarm history: what happened each morning.
- Your preferences, such as the default stay-awake delay.
None of it is sent to us, because there is nowhere to send it. Full detail in the Privacy Policy.
How purchases work without an account
This is the part people expect to be complicated and is not. Purchases go through Apple's in-app purchase system and attach to your Apple Account, not to a Mornio account.
So on a new iPhone: sign in to the same Apple Account, install Mornio, open settings and tap Restore Purchases. Pro comes back. There is no password to remember and no account to recover, because there was never one to begin with.
We never see your payment details at any point.
What this costs you
Three things, and all of them are genuine:
- No backup. Lose the phone and your alarm history goes with it.
- No sync. Nothing carries across devices, and there is no web version.
- Support is limited. We cannot look anything up about you, because we hold nothing. If something goes wrong, your description is all we have to work from, which is why our troubleshooting page asks for specific details.
If keeping years of wake-up history matters to you, an app with an account genuinely serves you better. That is a legitimate reason to choose a competitor, and we would rather say so than have you find out at the worst moment.
What we do not do as a result
- No email address, so no marketing emails.
- No password to be leaked in a breach elsewhere and reused here.
- No user database to be breached, sold, or inherited by an acquirer.
- Nothing declared under Data Used to Track You.
- No ads and no ad SDK, which is usually why an alarm app ends up wanting your location.
Will this ever change?
We have no plans to add accounts. If it ever changed, it would be opt-in for sync rather than required to use the app, and we would say so plainly here rather than in a version note.
Treat that as a statement of intent rather than a guarantee, because that is what it is. The thing that actually protects you is that today there is nothing to hand over.