Privacy Policy
Effective date: June 29, 2026 • Last updated: June 29, 2026
Motiveaction ("we", "our", or "us") is committed to protecting your personal information. This Privacy Policy explains what data we collect, why we collect it, how we use and share it, and the rights you have over it.
This policy applies to the Motiveaction desktop application (macOS, Windows, Linux), the Motiveaction mobile application (iOS and Android), and the website at motivaction.app (collectively, the "Service").
1. Data Controller
The data controller responsible for your personal data is:
Softs AV (operating as Motiveaction)Email: [email protected]
Contact form: [email protected]
If you are located in the European Economic Area (EEA) or United Kingdom, you may also contact our EU/UK representative at the same address.
2. Personal Data We Collect
2.1 Account data
When you create an account we collect:
- Email address (required for authentication)
- Password (stored as a cryptographic hash — we never see your raw password)
- Account creation date and timestamp
- Premium subscription status
2.2 Learning content you create
Topics, roadmap items, progress records, completion timestamps, and any notes you enter are stored to provide the core functionality of the Service. This content belongs to you.
2.3 Payment data
Premium subscriptions are processed by our third-party payment processor. We do not store your full card number, CVV, or bank details. We receive only a transaction reference, subscription status, and renewal date.
2.4 Device and usage data
We collect limited technical data to operate and improve the Service, including:
- Device type, operating system version, and app version
- Crash reports and error logs (anonymised where possible)
- Notification delivery status (sent / opened / dismissed)
- General feature usage patterns (e.g., which screens are visited)
We do not use persistent advertising identifiers or sell usage data to advertisers.
2.5 Data you do not need to provide
The free tier of Motiveaction does not require an account. You can create roadmaps and use the app locally without providing any personal data. An account is only required to sync data across devices or to subscribe to Premium.
3. Legal Basis for Processing (EEA / UK Users)
If you are located in the EEA or UK, we process your personal data under the following legal bases:
| Processing activity | Legal basis |
|---|---|
| Creating and managing your account | Performance of a contract (Art. 6(1)(b) GDPR) |
| Providing the core Service features | Performance of a contract (Art. 6(1)(b) GDPR) |
| Processing Premium payments | Performance of a contract (Art. 6(1)(b) GDPR) |
| Security monitoring and fraud prevention | Legitimate interests (Art. 6(1)(f) GDPR) |
| Service improvement and crash analytics | Legitimate interests (Art. 6(1)(f) GDPR) |
| Sending transactional emails (receipts, security alerts) | Performance of a contract (Art. 6(1)(b) GDPR) |
| Sending optional product updates | Consent (Art. 6(1)(a) GDPR) — you may opt out at any time |
| Compliance with legal obligations | Legal obligation (Art. 6(1)(c) GDPR) |
4. How We Use Your Data
- To create and manage your account and authenticate you securely
- To sync your learning data across your devices
- To deliver desktop and mobile notifications as configured by you
- To process and manage your Premium subscription
- To respond to your support requests
- To detect and prevent fraud, abuse, and security incidents
- To monitor app stability and diagnose technical issues
- To comply with applicable legal obligations
We do not use your learning content to train AI models or sell it to third parties.
5. Sharing Your Data
We do not sell, rent, or trade your personal data. We share data only with:
5.1 Infrastructure and service providers
- Supabase — database, authentication, and real-time sync (hosted on AWS in the US/EU). Supabase acts as a data processor under a Data Processing Agreement (DPA).
- Payment processor — to handle subscription billing. They are independently PCI-DSS certified.
- Error monitoring — crash and error reports (anonymised) may be processed by a monitoring provider.
5.2 Legal disclosures
We may disclose your data if required by law, court order, or governmental authority, or if necessary to protect the rights, property, or safety of Motiveaction, its users, or the public.
5.3 Business transfers
If Motiveaction is acquired or merges with another entity, your data may be transferred as part of that transaction. You will be notified via email or a prominent notice in the Service before any such transfer occurs.
6. International Data Transfers
Our primary database is hosted by Supabase. You may choose an EU-based Supabase region to keep your data within the EEA. Where data is transferred outside the EEA or UK, we rely on the European Commission's Standard Contractual Clauses (SCCs) or equivalent UK transfer mechanisms to ensure adequate protection.
7. Data Retention
- Account and learning data — retained for as long as your account is active. When you delete your account, all personal data is permanently deleted within 30 days.
- Payment records — retained for 7 years to comply with accounting and tax laws.
- Crash logs — retained for 90 days, then automatically purged.
- Backups — encrypted backups are retained for up to 30 days before being overwritten.
8. Cookies and Tracking
The Motiveaction website uses a minimal set of cookies:
- Session cookie — a short-lived, encrypted cookie used only if you log into the admin dashboard. It is strictly necessary and cannot be disabled without breaking that feature.
- We do not use advertising cookies, social-media tracking pixels, or third-party analytics cookies on the public marketing pages.
The desktop and mobile apps do not use browser cookies. They use local device storage for settings and an authentication token provided by Supabase.
9. Children's Privacy (COPPA)
The Service is not directed at children under 13 years of age (or under 16 in the EEA/UK). We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us at [email protected] and we will promptly delete it.
10. Your Privacy Rights
10.1 EEA and UK residents (GDPR / UK GDPR)
You have the right to:
- Access — obtain a copy of the personal data we hold about you.
- Rectification — correct inaccurate or incomplete data.
- Erasure ("right to be forgotten") — request deletion of your data, subject to legal retention obligations.
- Restriction — ask us to limit how we process your data in certain circumstances.
- Data portability — receive your data in a structured, machine-readable format.
- Object — object to processing based on legitimate interests or for direct marketing.
- Withdraw consent — where processing is based on consent, withdraw it at any time without affecting past processing.
- Lodge a complaint — with your local supervisory authority (e.g., your national Data Protection Authority).
10.2 California residents (CCPA / CPRA)
California residents have the right to:
- Know what personal information we collect, use, disclose, and sell (we do not sell personal information).
- Delete personal information we have collected, subject to certain exceptions.
- Correct inaccurate personal information.
- Opt out of the sale or sharing of personal information (not applicable — we do not sell or share data for advertising).
- Limit use of sensitive personal information (we do not process sensitive personal information beyond what is necessary for the Service).
- Non-discrimination for exercising your CCPA rights.
To exercise any California right, email [email protected] with the subject "CCPA Request". We will respond within 45 days.
10.3 Other US states
Residents of Virginia (CDPA), Colorado (CPA), Connecticut (CTDPA), Texas (TDPSA), and other states with enacted privacy laws may have similar rights. We will honour verified requests from residents of any US state in accordance with applicable law.
10.4 How to exercise your rights
Email us at [email protected]. We will respond within 30 days (GDPR) or 45 days (CCPA). We may ask you to verify your identity before processing the request. Account deletion can also be performed directly from within the app — on mobile, under Settings → Account → Delete Account; on desktop, from the account menu (top-right avatar) → Delete Account.
11. Security
We implement industry-standard security measures including:
- Encryption in transit (TLS 1.2+) and at rest (AES-256)
- Bcrypt-hashed passwords — we cannot recover your password
- Row-level security (RLS) policies in the database so users can only access their own data
- Regular security reviews of third-party dependencies
No method of transmission over the internet is 100% secure. In the event of a data breach affecting your rights or freedoms, we will notify you and the relevant supervisory authority within 72 hours of discovery, as required by GDPR.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated by email (if you have an account) or via a notice in the app at least 30 days before they take effect. Continued use of the Service after that date constitutes acceptance of the updated policy. The "Last updated" date at the top of this page always reflects the most recent revision.
13. Contact Us
For privacy-related questions, data subject requests, or complaints:
Motiveaction — PrivacyEmail: [email protected]
General enquiries: [email protected]
If you are not satisfied with our response, you have the right to lodge a complaint with your local data protection authority.