Legal
Privacy Policy
Last updated: 16 August 2026
1.Who is responsible
The controller of your personal data is Piotr Sawicki, trading as Motion Factor, a sole trader registered in Poland. Contact: piotr@motionfactor.pl
2.What we collect
Account data. Your email address. If you sign in with Google, also the display name and profile picture Google returns. We never receive your Google password.
Billing data.A record of each purchase: which pack, the amount, the currency, and Paddle's transaction identifier. We do not receive or store your card details. Those go to Paddle directly.
Usage data. A row per generation: what kind it was, which AI model ran, how many credits it cost, whether it succeeded, and when. This is how your balance is calculated and how we answer billing questions.
Consent records. When you buy credits we store the exact wording you agreed to, the time, your IP address and browser identifier. We are required to be able to prove this consent, which is why it is kept.
Your creative content. Scripts, prompts and uploaded reference images are sent to the AI providers to produce your output. Reference files are uploaded to fal.ai's content network and stay there under their retention rules; deleting your account here does not remove them from fal. Everything you generate is stored in our own storage, where only your account can reach it.
What we do not keep. We do not log the text of your prompts or the replies to them. Our application logs record how long a request took and how many tokens it used, never what was in it.
Server logs. Our host records the usual request data, including your IP address, the page requested and the time. This is how a fault is diagnosed and how abuse is spotted.
A note that a reference image was uploaded. When you upload a reference image we record which account did it, when, the file size and the file type. We do not store the image itself in that record, nor a copy, a fingerprint or any analysis of it. It exists so that if someone reports a specific misuse, such as a photograph of them being used without consent, we can find it and act. Kept for 12 months.
3.Why we may use it, and on what basis
- To provide the Service. Performance of our contract with you (Art. 6(1)(b) GDPR).
- To take payment and keep accounting records. Contract, and our legal obligations under tax law (Art. 6(1)(b) and (c)).
- To prove purchase consent. Legal obligation and our legitimate interest in defending claims (Art. 6(1)(c) and (f)).
- To prevent abuse of free credits and detect fraud. Legitimate interest (Art. 6(1)(f)).
We do not sell your data, and we do not use it for advertising.
4.Who else processes it
| Processor | Purpose | Location |
|---|---|---|
| Supabase | Accounts, credit balances, purchase records | Ireland (EU) |
| Vercel | Application hosting and request logs | EU / USA |
| Paddle | Payments, invoicing and tax. Merchant of record, and a controller in its own right | UK / EU |
| fal.ai | Image, video and speech generation | USA |
| Anthropic | Script breakdown and text editing (Claude) | USA |
| Resend | Delivery of feedback emails | EU / USA |
| Sign-in, if you choose it | EU / USA |
Some of these are outside the EEA. Transfers rely on the European Commission's Standard Contractual Clauses or an adequacy decision.
What the AI providers see. The prompts and reference images you generate from are sent to fal.ai and Anthropic. Do not put personal data, client confidential material or anything you cannot share with a third party into a prompt.
5.How long we keep it
- Account data: while your account exists, then deleted.
- Billing and accounting records: 5 years from the end of the tax year, as Polish tax law requires. These survive account deletion because we are obliged to keep them.
- Consent records: 6 years, matching the limitation period for claims.
- Generation history: 24 months, then deleted.
- Reference-upload records: 12 months, then deleted.
- Your boards: until you delete them, or until you delete your account.
- Server logs: up to 30 days, depending on our hosting plan.
These periods are enforced by a job that runs every night, not by hand. Records past their period are deleted whether or not anyone asks.
6.Your rights
You may request access to your data, correction, deletion, restriction, portability, and you may object to processing based on legitimate interest. Write to us at the address in section 1; we answer within 30 days.
Two of those rights are buttons rather than requests. On the Your data page, signed in, you can download everything we hold about you as a single JSON file, and you can delete your account. Deletion takes effect 14 days after you ask, so a mistake can be undone; during those 14 days one click cancels it, and after that your boards, media, generation history and sign-in are erased for good.
Records we are legally required to keep, mainly invoices and proof of purchase consent, survive deletion for the periods above. They are stripped of what identifies you: the link to your account is removed, along with the IP address and browser identifier held with a consent record. What remains is an amount, a date and a transaction number.
If you think we are handling your data wrongly you may complain to the Polish data protection authority (Prezes Urzędu Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warszawa) or to the authority where you live.
7.Cookies
We use only what the Service needs to work: a session cookie so you stay signed in, set by Supabase. There is no analytics, advertising or third-party tracking, which is why you are not asked to accept cookies.
Paddle sets its own cookies during checkout; see Paddle's privacy policy for those.
If you signed in with Google, your profile picture is shown straight from Google's servers rather than copied to ours, so displaying it tells Google your browser asked for it. Signing in with an email address instead avoids this.
8.Changes
We will update this policy as the Service changes. For material changes we will notify you by email or in the app before they take effect.