Privacy Policy
Effective 18 September 2026. This explains what Motiontone collects, why, who else sees it, how long we keep it, and what you can do about it. We are the data controller for the information described here.
What we collect and why
- Account details — your email address, name, and sign-in credentials
- To create your account, sign you in, and contact you about the service. Stored with: Clerk (our authentication provider). Lawful basis: contract.
- Your content — projects, text, images, fonts, uploaded audio, and rendered videos
- To store your work, render it, and show it back to you. Stored with: Our database and Vercel Blob storage. Lawful basis: contract.
- Payment records — your subscription status and the identifiers Stripe gives us
- To bill you and to know what your plan includes. Stored with: Stripe, plus subscription identifiers in our database. Lawful basis: contract.
- Product usage — which features you use, exports you complete, and pages you visit
- To understand what works, fix what does not, and decide what to build. Stored with: PostHog (EU hosting), and a daily activity count in our database. Lawful basis: legitimate interests.
- How you first arrived — campaign tags in the link you clicked and the domain that referred you
- To know which channels bring people who find the product useful. Stored with: PostHog (EU hosting). Lawful basis: legitimate interests.
- When you last used the app and how many projects you have, so we can write to you about how you are getting on
- To ask people who tried the product what they made of it, and to offer help to people who got stuck. Stored with: Our database, and Resend (who deliver our email). Lawful basis: legitimate interests.
- A copy of each email we send you
- To answer questions about what we sent and when, after our email provider's own 30-day log has expired. Stored with: Our database. Lawful basis: legitimate interests.
- Email addresses used for complimentary access, including of people who have not signed up
- To honor a free or beta access grant when that person creates an account. Stored with: Our database. Lawful basis: legitimate interests.
- Waitlist answers — the email address and form answers of someone asking to be told when accounts open, and the campaign tags in the link that brought them
- To tell them when there is room, and to know which channels reach the people the product is for. Stored with: Our database. Lawful basis: legitimate interests.
- What you ask the assistant — the instruction you type, plus a summary of the project it is working on: layer names, the first line or so of each text layer, sizes and timings
- To work out what you asked for and change your project accordingly. Stored with: Anthropic (the model that runs the assistant), and our database. Lawful basis: contract.
- The record of an assistant request — your instruction, what the model did with it, and what the request cost us
- To find where the assistant fails people, fix it, and know what the feature costs to run. Stored with: Our database. Lawful basis: legitimate interests.
- Security and abuse signals — rate-limit counters and error logs
- To keep the service available and to investigate misuse. Stored with: Our database, our hosting provider's logs, and Sentry (crash reports). Lawful basis: legitimate interests.
We do not sell your data, and we do not use your projects or your uploaded audio to train machine-learning models.
Motionbot, the AI assistant
If you ask Motionbot to change your project, that request goes to Anthropic, who run the model. This is the only place any part of your work leaves us, and it only happens when you ask it to — if you never use Motionbot, nothing here applies to you.
- What we send. Your instruction, and a summary of the project: layer names, the first line or so of each text layer, sizes, colors and timings. Enough for the model to know what it is looking at.
- What we do not send. Your files. Images, fonts and audio are named but never uploaded to the model, and neither is your email address or any account identifier.
- Not used for training.Requests made through Anthropic’s commercial API are not used to train their models.
- We keep a record. What you asked, what Motionbot did, and what the request cost us, stored for as long as you have an account. It is how we find out where Motionbot is letting people down. Ask us and we will delete yours.
Analytics, and what we deliberately do not collect
We use PostHog to count product events — a project created, an export finished. It is configured conservatively, and these are facts about the product rather than promises:
- No session recording. We do not replay your screen.
- No autocapture. We record a fixed list of events we chose, not every click, so the text in your projects is never swept up by analytics.
- No analytics cookies.PostHog is set to use your browser’s local storage instead.
- EU hosting.Analytics data goes to PostHog’s EU infrastructure.
- No content in events. Event properties are limited to categories and counts — never a project name, the text in a layer, a file name, or an email address.
Cookies we do use are the ones needed to keep you signed in, set by our authentication provider. Without them the service cannot work, so there is nothing to opt into.
Who else processes your data
We use a small number of providers to run the service. They process data on our instructions:
- Clerk — Accounts, sign-in, and session management. Their privacy policy.
- Vercel — Hosting, file storage, and the database that holds your projects. Their privacy policy.
- Stripe — Subscription payments and billing. Their privacy policy.
- PostHog — Product analytics, hosted in the EU. Their privacy policy.
- Anthropic — The AI assistant. Receives your instruction and a summary of the project it is editing. Under their commercial API terms this is not used to train their models. Their privacy policy.
- Sentry — Crash and error reports, so faults get fixed. Their privacy policy.
- Resend — Delivering our email — invites, sign-up confirmations, and notes we write to you about the product. Their privacy policy.
We also disclose data where the law requires it, or to establish or defend legal claims — including responding to a copyright complaint under our Terms of Service.
Where your data is processed
Our providers operate internationally, so your data may be processed outside your country, including in the United States. Where data leaves the UK or the EEA, our providers rely on the safeguards published in their own privacy documentation, such as standard contractual clauses.
Sharing a project makes it public
If you create a share link, anyone who has that link can open the project — including its audio — without signing in, and can remix it into their own account, which copies the project’s files. Only share links for work you are content to have seen and copied. You can turn a share link off at any time from the project.
How long we keep it
- Projects and the files in them (images, fonts, audio)
- Until you delete the project or your account. Files no longer used by any project are removed by an automated cleanup, normally within a few days.
- Rendered videos
- Until you delete the project or your account. We do not currently expire them on a schedule.
- Account details
- Until you delete your account.
- Payment and subscription records
- For as long as tax and accounting law requires us to keep them, which is longer than your account lives.
- Product analytics
- Retained by PostHog under their standard retention. We ask them to delete data tied to your account when you delete it.
- Copies of emails we send you
- Until you delete your account.
- Complimentary-access grants
- Until the grant expires and is no longer needed, or until you ask us to remove it.
- Waitlist entries
- Until accounts are open to everyone and the list has been contacted, or until you ask us to remove yours.
- Assistant requests
- Until you delete your account. We keep what you asked and what the assistant did with it for as long as you have an account, because the pattern of what people ask over months is what tells us where the feature falls short. Ask us and we will delete yours sooner.
Your rights
If you are in the UK or the EEA you have the rights below. We extend them to everyone, because running two standards is a good way to get one of them wrong.
- Access
- Ask what we hold about you and get a copy.
- Rectification
- Have inaccurate details corrected.
- Erasure
- Have your data deleted. Email us and we will delete your account and everything in it.
- Restriction
- Ask us to stop processing your data while a dispute is resolved.
- Portability
- Receive your data in a portable form, or have it sent elsewhere.
- Objection
- Object to processing we base on legitimate interests, including analytics. Reply to any email we send you asking us to stop, and we will.
- Withdraw consent
- Where we rely on consent, withdraw it at any time without affecting what came before.
- Complain
- Lodge a complaint with your local data-protection authority. In the UK that is the ICO.
To exercise any of these, email support@motiontone.app. We will respond within one month. We may need to confirm who you are before acting on a request.
Security
Your uploads are stored privately and are served through checks that confirm you are entitled to read them. Payments are handled entirely by Stripe — we never see or store your card details. No service can promise perfect security, and we do not.
Children
The service is not for anyone under 16. We do not knowingly collect data from children. If you believe a child has given us data, email us and we will delete it.
Changes
If we change this policy, the effective date above changes with it. If a change is material we will make a reasonable effort to tell you.
Contact
Privacy questions, or any request about your data: support@motiontone.app. If you are in the UK or the EEA and think we have handled your data badly, you can also complain to your local data-protection authority.