Private storage by default
Your Sparks live on your device and in your personal iCloud account through CloudKit private storage. That is an important distinction. MorningKeep is not built around a centralized database of everyone's Sparks sitting on company servers. Sync happens inside your Apple ecosystem, which keeps ownership of the source material much closer to you.
In practice, that means the core record of your thinking follows the same privacy posture as CloudKit private storage: Apple-managed encryption, private-database access control, your account, your storage, and your devices. MorningKeep is the interface and the intelligence layer on top of that, not the long-term warehouse of your inner life. MorningKeep Release does not claim full application-layer end-to-end encryption for synced CloudKit content.
That also changes the trust model. If you delete data from MorningKeep, you are not asking a remote service to forget a copy it was built to retain forever. You are managing data that lives in your own environment. For a product centered on private Sparks, that local-first posture is not marketing language. It is architecture.
Why App Check and consent controls matter
When MorningKeep needs to connect to Cue services, the app uses security controls designed to keep that path narrow and intentional. Firebase App Check helps verify the app instance, while a separate short-lived account authorization proves Dawn access, cloud consent, the approved route, and remaining allowance. Combined with secure network handling, those controls reduce abuse around the parts of the product that leave the device.
Consent is the second half of that story. Validated Apple processing runs on your device without off-device consent or a cloud allowance. Private Cloud Compute and approved third-party routes are Dawn-only and require explicit consent; turning that consent off keeps new content out of those off-device routes. That makes privacy a product setting, not just a legal paragraph.
The practical effect is that you can decide how much intelligence you want versus how much isolation you want. Some people want Cue fully involved in their thinking. Others want MorningKeep primarily as a trusted capture and review system. The controls are there so the product can support both modes without pretending they are the same thing.
On-device fallback and what never leaves
The core of MorningKeep still works even when cloud AI is unavailable or disabled. You can capture new Sparks, keep your history, and continue using the app as your record of Sparks without being forced through a remote model call. That on-device fallback matters because it keeps the product useful even when you want a more private mode or when the network is not cooperating.
Biometric systems like Face ID or Touch ID remain inside Apple's secure hardware model. Sensitive credentials stay in Keychain storage rather than being exposed as plain account secrets inside the app. If you never send a Spark through an AI feature, it stays in the local and CloudKit path instead of being shipped to an external provider.
The same principle applies to identity. MorningKeep uses Apple account primitives instead of asking you to build a separate public profile for a private thinking app. That keeps the product narrower: fewer copies of your information, fewer places to secure, and fewer assumptions that your personal Sparks should become platform data.
The practical takeaway is simple: MorningKeep is built to earn trust by limiting what moves, verifying the parts that do move, and giving you the choice to keep your thinking closer to home when that matters more than convenience.

