Privacy Policy
Last updated: June 19, 2026
MotionBrief is operated by Humaine Technologies Inc. (the "Seller"), who acts as the data controller for personal data processed through this service. This privacy notice explains what data we collect, the legal basis on which we process it, how long we keep it, who we share it with, and the rights you have over your information.
1. Data We Collect
We only collect information that is strictly necessary to run the platform and process your records:
- Account Data: Your name, email address, and authentication details when you sign up.
- Scheduling Data: Meeting titles, descriptions, participant emails, and selected availability slots that you input into the platform.
- Session & Device Data: IP addresses, basic browser metadata, and device operating systems used solely for account security and active session tracking.
- Calendar Free/Busy Data (optional): If you connect a Google Calendar or Microsoft Outlook account, MotionBrief reads only free/busy windows — never event titles, attendees, locations, descriptions, or attachments. OAuth refresh tokens are encrypted at rest and used solely to render busy markers on your own scheduling pages. You can disconnect at any time from Settings → Integrations, which deletes the stored tokens and revokes the connection where the provider supports it.
2. How We Use Your Data & Legal Basis
Your data is used exclusively to power your workspace. We process each category on one of the following legal bases under applicable data protection law:
- Performance of contract: providing secure authentication, syncing data across devices, processing your uploaded records, and delivering the core features of your plan.
- Legitimate interests: securing the service against fraud and abuse, monitoring uptime, debugging errors, and improving the product.
- Consent: dispatching transactional email notifications or automated alerts that you explicitly enable in your account settings. You can withdraw consent at any time in settings.
- Legal obligation: retaining limited records needed to comply with tax, accounting, and other applicable laws.
We never sell, rent, or monetize your financial data or personal information to third-party advertisers or data brokers.
3. Data Storage & Third-Party Processors
We share personal data only with the following categories of recipients, who act as processors or independent controllers as noted:
- Database & Auth: Securely managed and encrypted both at rest and in transit.
- Payments — Paddle.com Market Limited (Merchant of Record): All payments, subscription billing, tax compliance, invoicing, and refunds are handled by Paddle, who acts as the Merchant of Record and reseller for our products. When you purchase a plan, your billing details (name, email, billing address, payment method) are collected and processed directly by Paddle under its own privacy notice. We receive only the limited transaction metadata required to provision your subscription. We never see or store your raw card details.
- Email Pipelines: Transmitted via secure transactional email service providers.
- Professional advisers & authorities: legal, accounting, and tax advisers, and government authorities where disclosure is required by law.
4. Data Retention
We keep personal data only for as long as it is needed for the purposes described above:
- Account & profile data: retained for the lifetime of your account and deleted within 30 days of account closure.
- Uploaded records & transaction metadata: retained while your account is active and deleted within 30 days of account closure or earlier on request.
- Billing & tax records: retained by us and by Paddle for up to 7 years as required by applicable tax and accounting laws.
- Security & access logs: retained for up to 12 months for fraud prevention and incident investigation.
5. Security
We use appropriate technical and organisational measures to protect your data, including encryption in transit (TLS) and at rest, role-based access controls, least-privilege service credentials, audit logging, regular dependency and vulnerability scanning, and isolated production environments. No system is perfectly secure — if you believe your account has been compromised, contact us immediately at hello@motionbriefapp.com.
6. Your Rights & Total Control
Subject to applicable law (including the GDPR and UK GDPR where relevant), you have the right to access, rectify, erase, restrict, or object to processing of your personal data, the right to data portability, the right to withdraw consent at any time, and the right to lodge a complaint with your local supervisory authority. To exercise any of these rights, contact hello@motionbriefapp.com; we will respond within one month.
- Instant Export: You can download a clean CSV or Excel export of all your logged transactions and metadata instantly from your dashboard.
- Permanent Deletion: Clicking "Delete Account" inside your settings panel triggers an irreversible script that permanently wipes your personal profile, credentials, uploaded assets, and transaction history from our active databases.
7. Controller & Contact
The data controller for MotionBrief is Humaine Technologies Inc.. For any privacy questions or to exercise your rights, contact hello@motionbriefapp.com.