Last updated: September 4th 2026
Morbee is a website builder at https://morbee.net, operated by Michael Linial, 56 Yefe Nof st Peduel, Israel. Contact: mikey.linial@morbee.net.
This policy covers two different groups of people, and the difference matters:
For this data, the builder is the controller and Morbee is the processor: we hold it to deliver it, and we do not use it for our own purposes.
Morbee offers two separate Google connections. They are separate on purpose: each asks for only what it needs, and connecting one does not grant the other.
| Permission | Why |
|---|---|
openid, email, profile | To label the connection with the account it belongs to, so you can tell several connections apart |
.../auth/spreadsheets | To read the rows and columns your integration is configured to read, and to write the rows it is configured to write |
.../auth/drive.readonly | Only to list the names of your spreadsheets, so you can pick one when setting up an integration |
| Permission | Why |
|---|---|
openid, email, profile | To label the connection with the account it belongs to |
.../auth/drive.file | To store files in your Drive at your request, and to read back, replace or delete the files Morbee itself put there |
drive.file reaches only the files this app creates. Morbee cannot see, list, open or download anything else in your Drive — not your existing documents, not your folders, not files put there by any other app.
Morbee's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
In particular, we do not use Google user data for advertising, we do not sell it, we do not transfer it to others except as needed to provide the feature you asked for or where the law requires it, and no human reads it except with your explicit permission, for security purposes, or where the law requires it.
The same applies to any other service you connect, such as Salesforce or any other connection enable by Morbee: we hold the credentials you authorise, and use them only to run the integrations you configure.
If you are a visitor to a site built with Morbee and want your data removed, contact the owner of that site — it is theirs, and we hold it for them.
Credentials are encrypted at rest in AWS Secrets Manager. Traffic runs over HTTPS. Session cookies are HttpOnly and cannot be read by page scripts. Access to production is limited to the founder.
Morbee itself — i.e. the builder — is a tool for adults. You must be 18 or over to hold a Morbee account, and we do not knowingly collect data from children through it.
Sites built with Morbee are a different matter. A builder may quite legitimately run a site for a kindergarten, a school or a youth club, where the people filling in a form are parents writing about their children, or children themselves. In that case the builder decides what is asked and why, holds the relationship with those families, and is responsible for any consent the law requires. We process what their form collects on their behalf, and for no purpose of our own.
If your site collects data about children, the obligations are yours: follow whichever law applies where those families are - GDPR Article 8 in the EU, COPPA in the United States, or your local equivalent - for the consent you need before collecting it.
We will post changes here and update the date above. If a change materially affects how we handle your data, we will also email account holders before it takes effect.
mikey.linial@morbee.net — Michael Linial, 56 Yefe Nof st. Peduel, Israel.