MORTIC DEVELOPER PREVIEW

Privacy and support

Mortic needs a small amount of account and device information to connect your Mac. Your coding and voice content takes a different path and is not collected as Mortic product telemetry.

What Mortic stores

Google or GitHub confirms your identity and verified contact email when you connect a Mac. Mortic stores the provider name, its stable account identifier, your verified email, display name, account state, and last sign-in time. Your account remains bound to the first provider you use. Mortic does not retain OAuth access or refresh tokens.

New accounts can be created only from a valid, short-lived authorization started by the Mortic installer. The browser stores a signed, HttpOnly binding only long enough to complete that authorization. Historical invitation records are retained only for existing-account access, expiry, audit, and recovery; Mortic no longer creates new invitations.

For an authorized Mac, Mortic stores its name, operating system, processor type, access status, model-usage state, active-model selection, and revocation history. Customers see model usage only as a remaining percentage; internal allocation amounts are restricted to the owner view. The sign-in details needed by the Mac are kept in macOS Keychain. Short-lived voice access stays in memory and is not written to local files.

If managed account or model capacity is full after sign-in, Mortic stores your verified email, provider identity, waitlist state, and timestamps so the owner can admit identities oldest-first or override the order. Separately, the public landing-page waitlists, including valency-one early access on the mortiphi home page, store only the email and form source you submit, used only to contact you about access. The landing page does not assign a persistent visitor ID or send visit, demo-open, or signup analytics events. Email Mortic to request deletion of a waitlist record.

Public installers report anonymous setup stages and release versions so we can find installation failures. No account, device or visitor identifier, file path, error text, prompt, transcript or audio is included. Reports are optional, best-effort and cannot identify unique users. Disable them with curl -fsSL https://mortiphi.com/install.sh | env MORTIC_INSTALL_METRICS=0 sh. Stage observations are removed after six months. Address hashes enforce abuse limits separately; they are not attached to setup observations and expired buckets are removed by the daily retention job.

Where product traffic goes

  • Model requests and responses go directly from your Mac to the approved model access service. Vercel is not a model proxy.
  • Live voice traffic goes directly from your Mac to Deepgram and Cartesia. Vercel is not an audio proxy.
  • Mortic's Vercel service receives authentication, device, usage, grant, rate-limit, and revocation information needed to operate the Developer Preview.
✓ No content telemetry

Mortic does not send prompts, model responses, transcripts, or audio through Vercel, and does not collect them as product telemetry.

Provider master credentials stay in protected server-only Vercel settings. They are never returned to your browser or Mac, placed in OpenCode configuration, or included in Mortic logs.

Mortic applies its closed model/provider routing and data-collection restrictions, but cannot make promises beyond the external model and voice services' current terms. Review their current policies before using the Developer Preview with sensitive content.

How long Mortic keeps data

Mortic keeps redacted security events and model-usage snapshots for up to six months, then removes them. Account, device, and access-operation records are kept separately while needed to authorize, operate, revoke, recover, and support Developer Preview access.

Historical expired invitation claim digests are cleared by the daily retention job. Revoked invitations and invitations that expired unused are removed after six months. A redeemed historical invitation remains while needed to authorize its existing account.

Verified capacity-waitlist and historical public waitlist records are kept while needed to manage access and are deleted on request. Mortic does not retain prompts, model responses, transcripts, or audio.

Recovery and support

Run mortic logout to remove Mortic access from the current Mac. You can also revoke a Mac from your account page. To reconnect after access expires or is revoked, run mortic login and approve the new matching code in your browser. Reinstalling does not silently restore revoked access.

If those steps do not recover access, email Mortic supportwith only your opaque account ID. Never send API keys, device credentials, prompts, transcripts, or audio in a support request.

The owner can disable an account or revoke a Mac from the private owner console. Removal blocks the Mortic session and new device, model, and voice grants immediately and disables the member's restricted provider key with provider readback confirmation. Already issued voice grants expire within 60 seconds.