Motion Index — Privacy Policy
Last updated: 17 September 2026
1. Who We Are
CINESUIT AS ("we," "us," "our") operates Motion Index, the platform at motionindex.io — a search engine for product films, brand films, and 3D motion design, providing a curated video reference library and creative workspace for motion design and filmmaking professionals.
CINESUIT AS is the data controller for personal data processed through the Service:
CINESUIT AS Organisation number 931 200 909 Rådhusgata 5, 0151 Oslo, Norway hello@motionindex.io
For questions about this policy or your data, contact us at hello@motionindex.io.
2. What Data We Collect
2.1 — Account Information
When you create an account, we collect:
- Email address
- Password (stored as a one-way hash — we never store or see your actual password)
- Name (optional)
- Profile image URL (optional)
- Authentication provider (if using Google or Apple sign-in)
2.2 — Device and Session Information
When you use the Service, we automatically collect:
- IP address
- User agent (browser type and version)
- Device type and identifier
- Session timestamps (login time, last active)
This information is used to manage your active sessions, enforce device limits, and maintain account security.
2.3 — Usage Data
We record how the Service is used, against your account. Being specific about this matters more than a short list, so:
Searches. The text you type, what came back, whether you clicked a result and which one, and which filters you applied. Search text is unlinked from your account after 90 days and the row is deleted after a year.
Recent searches. Your last 20 searches, listed under the search field so you can run one again: the words, the filters, and for an image search the file's name and a list of numbers describing the picture — never the picture itself. Remove one with its ×, or all of them by clearing your search history. Nothing older than 90 days stays in the list.
Viewing. Which films and frames you opened, how many times, and how long you spent. Kept for one year. This is also what "Recently viewed" and the "For You" feed are built from.
This includes shots you watch in the grid, without opening them. A tile's preview is the whole shot on a loop, so once you have watched it through — all of it, or five seconds for shots longer than that — we record that you viewed it, the same way we would if you had opened it. Most browsing here is watching, and counting only the films people click would miss the majority of it. We do not record how long your cursor rests on anything, and moving the mouse across a grid records nothing at all.
Features. Which parts of the product you use, per day, with counts. Kept for one year. We record that you used a feature, not which film it involved.
Activity. Account creation date, last active date, total time spent, days active and current streak, and API request count (rolling 30-day window). The per-day rows are kept for one year.
Profile. What you told us during signup — profession, interests, and how you found us.
You can see all of this for yourself: Settings → Your data exports every one of these in a machine-readable file. You can clear your search history at any time, and you can object to the analytics use of it entirely (see §4).
Visits, before you have an account. Everything above is recorded against an account. One thing is not, and it needs saying separately because it happens to people who have not signed up and therefore have no settings page.
We count how many people visit the site, so we can tell how many of them go on to create an account. Each page you open sends a short request to our own servers saying only that a page was opened, and whether it was the sign-up page. To avoid counting the same person repeatedly in one day without putting an identifier in your browser, our server combines your IP address and browser name with a random number that changes every 24 hours and keeps only the scrambled result. The random number is deleted when the next one is generated, which permanently removes any way — ours included — of linking those scrambled values back to an IP address or to one another. The scrambled values themselves are deleted after two days.
We also record which country the visit came from. Cloudflare, which sits in front of our servers, works this out from your IP address before the request reaches us and passes on a two-letter country code — we never look up your location ourselves, and we never receive or store anything more precise than the country. A VPN or an office connection will show wherever it exits, not where you are. The same country code is recorded against a new account when it is created, so we can see which countries people sign up from.
What remains is a count per day and country. There is no identifier in it, so there is nothing in it to show you, correct or erase, and no way for us to find "your" row. If your browser sends Global Privacy Control we do not count you at all; that is the objection mechanism here, since the settings toggle needs an account. See the Cookie Policy for the longer explanation.
2.4 — User-Created Content
We store content you create within the Service:
- Collections and saved references
- Canvas projects, drawings, and annotations
- Files you upload to the Service
- Project version history
- Collaboration settings and shared project configurations
2.5 — Payment Information
Payment data is collected and processed by Stripe, our payment processor. We do not store your credit card number, CVV, or full payment card details on our servers. Stripe provides us with limited billing information (card type, last four digits, expiration date) for display in your account settings.
3. What We Do NOT Collect
- We do not use Google Analytics, or any third-party page-view analytics service. We do count visits, but on our own servers and without putting an identifier on your device — see §2.3
- We do not use session replay or screen recording tools
- We do not use marketing cookies, advertising trackers or third-party tracking pixels
- We do not use third-party advertising trackers
- We do not sell your personal data to anyone
- We do not build advertising profiles based on your usage
- We do not use any third-party analytics processor — the usage data in §2.3 is processed on our own infrastructure and is not shared for analytics purposes
4. How We Use Your Data
We use the data we collect for the following purposes:
| Purpose | Legal Basis (GDPR) |
|---|---|
| Providing and operating the Service | Performance of contract (Art. 6(1)(b)) |
| Processing payments and managing subscriptions | Performance of contract (Art. 6(1)(b)) |
| Sending account-related emails (verification, billing, subscription changes) | Performance of contract (Art. 6(1)(b)) |
| Maintaining account security and managing sessions | Legitimate interest (Art. 6(1)(f)) |
| Monitoring for abuse and enforcing Terms of Service | Legitimate interest (Art. 6(1)(f)) |
| Diagnosing errors and improving platform stability | Legitimate interest (Art. 6(1)(f)) |
| Understanding how the library is used — what people search for, which features they use, and which professions the Service suits — so we know what footage to add next | Legitimate interest (Art. 6(1)(f)) |
| Counting how many people visit the site, and how many of them sign up, using an identifier we destroy every 24 hours | Legitimate interest (Art. 6(1)(f)) |
| Complying with legal obligations (tax records, law enforcement requests) | Legal obligation (Art. 6(1)(c)) |
We do not use your data for targeted advertising, profiling, or automated decision-making that produces legal effects.
About the analytics row. We record what you search for and which features you use, against your account, and we use it to decide what to add to the library and who the Service is a good fit for. We rely on legitimate interest rather than asking for consent, and you have an unconditional right to object:
Settings → Privacy → "Don't use my activity for analytics" turns it off immediately, no reason required, with no effect on how the Service works for you.
If you object, your searches and feature usage stop being recorded against your account. Your viewing history, saves and recent searches keep being recorded — they are what "Recently viewed", "For You" and the recent searches under the search field are built from, so removing them would break features you use — but they are excluded from our product statistics. Either way, we keep anonymous daily counts with no account, device, or session attached.
We do not sell personal data, and we use no third-party analytics processor.
5. Third-Party Services
We share data with the following third-party services as necessary to operate the platform:
5.1 — Payment Processing
| Service | Data Shared | Purpose |
|---|---|---|
| Stripe (US) | Email, tokenized payment card data, subscription status | Payment processing, billing, invoicing |
Stripe's privacy policy: https://stripe.com/privacy
5.2 — Video Platforms
| Service | Data Shared | Purpose |
|---|---|---|
| YouTube (Google, US) | Your IP address, standard embed request data | Video playback via iframe embed |
| Vimeo (US) | Your IP address, standard embed request data | Video playback via iframe embed |
Nothing is sent to YouTube or Vimeo until you click play. Most sites with embedded video contact the video platform the moment the page loads, which hands over your IP address whether or not you watch anything. We do not do that. Browsing the library — including every preview image and every thumbnail — involves no connection to any video platform, because we host those images ourselves.
The player only loads when you click the play button on a specific video. At
that moment your browser connects directly to YouTube or Vimeo, and their own
privacy policy governs what happens next. We load YouTube through its
privacy-enhanced domain (youtube-nocookie.com) and pass Vimeo a do-not-track
signal, both of which limit what those platforms record.
There is no "always allow embeds" setting to switch on, and no preference is stored — each click applies to that video only.
On joint controllership. Where a site loads a third-party resource that transmits visitor data on page load, the site operator and the third party are joint controllers for that transmission (Fashion ID, C-40/17). We have designed the transmission out rather than accept the status: until you click, no data reaches the platform at all. For the connection that follows your click, we determine nothing about what the platform does with it, and that processing is governed by the platform's own policy.
- YouTube/Google privacy policy: https://policies.google.com/privacy
- Vimeo privacy policy: https://vimeo.com/privacy
5.3 — Infrastructure and Operations
The full list, with transfer mechanisms, is on our sub-processors page.
| Service | Data Shared | Purpose | Location |
|---|---|---|---|
| Neon | The database — everything in §2 | Primary data store | EU (Frankfurt) |
| Render | All API traffic, including IP address | Backend hosting | EU (Frankfurt) |
| Vercel | All web traffic, including IP address | Frontend hosting and CDN | Global edge network |
| AWS S3 | Uploaded files, cached images | Media storage | EU (eu-central-1, Frankfurt) |
| Resend | Email address, email content | Transactional emails (verification, billing) | US |
| Cloudflare Turnstile | IP address, browser signals | Bot protection on signup | Global |
| Telegram | Operational alerts. Your email address is masked (e.g. t***@example.com) before sending; plan tier, signup method and profession may be included. If you send us feedback, the text of your message is included so we can read it. | Alerts to the founder — signups, subscriptions, feedback, service health | Global |
Telegram is used for operational alerts only (see the note on Telegram). Because Telegram offers no data processing agreement, identifiers are masked before they are sent, and no full email address, name or search text ever reaches it. The one exception is feedback you choose to write to us, which is forwarded so it can be read and answered.
Fonts are not loaded from Google. They are downloaded at build time and served from our own domain, so no font request reaches a third party and no visitor IP address is shared for font loading.
5.4 — Search and Analysis
| Service | Data Shared | Purpose |
|---|---|---|
| Anthropic (US) | Video titles, descriptions and on-screen credits from films in the library. This can include creator and studio names, because extracting those credits is the purpose. No user account data, and no search queries. | Reading credits and assessing frame quality during ingest |
Search embeddings are generated on our own servers. The model (OpenCLIP) runs locally; no search query, and no video data, is sent to a third party to produce them. Earlier versions of this policy named OpenAI as a recipient here — that was wrong. The model was trained by OpenAI and its published weights are used offline, which is not a transfer of anything.
Anthropic is sent film metadata during ingest so that credits can be extracted and low-quality frames filtered. Under Anthropic's commercial terms this input is not used to train their models. No decision about any person is made by a model: extracted credits are stored for attribution and are editable and removable by us — see our sources notice.
5.5 — Authentication
| Service | Data Shared | Purpose |
|---|---|---|
| Google OAuth | Your email address and a unique account identifier | Social login |
| Apple OAuth | Your email address and a unique account identifier | Social login |
When you choose to sign in with Google or Apple, the provider shares your email address and a unique identifier with us. We never receive your password.
We do not keep the access tokens. Signing in issues a short-lived token that would allow an app to call the provider's API on your behalf. We have no use for that — we use these providers to establish who you are, not to read your Google or Apple account — so the token is discarded and never stored. We keep only the account identifier needed to recognise you at your next sign-in.
6. International Data Transfers
Motion Index is operated from Norway (EEA). Some of our third-party service providers are based in the United States. When personal data is transferred outside the EEA, we rely on:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Adequacy decisions where applicable
- Provider-specific data protection agreements
7. Data Retention
| Data Type | Retention Period |
|---|---|
| Account information | Until you delete your account |
| Session data | Automatically pruned when sessions expire or are revoked |
| Search text and account link | Unlinked from your account after 90 days |
| Search records | Deleted after 365 days |
| Recent searches (the list under the search field) | Your newest 20, none older than 90 days |
| Viewing history | Deleted after 365 days |
| Feature usage | Deleted after 365 days |
| Activity totals (days active, time spent) | Deleted after 365 days |
| The 24-hour random number used to count visits | Deleted when the next one is generated — 24 hours |
| Scrambled visit values | Deleted after 2 days |
| Daily visit counts (no identifier of any kind) | Kept indefinitely — there is nothing in them about anyone |
| User content (collections, projects, uploads) | Until you delete the content or your account |
| Payment and billing records | As required by Norwegian tax law (typically 5 years) |
| Application error logs | 90 days |
| Transactional email records | 30 days |
These periods are enforced by an automated daily job, not by manual review.
When you delete your account, deletion is immediate — your account, collections, projects, saved frames and uploads are removed when you confirm, not queued for later. Records that outlive the account (such as search rows already unlinked from you) are scrubbed of anything identifying at the same moment. There is no grace period and the deletion cannot be undone, so export your data first if you want a copy.
The exception is data we are required by law to keep, such as billing records retained for tax compliance.
8. Your Rights (GDPR)
As a user in the EEA or Norway, you have the following rights under the General Data Protection Regulation:
- Access — You can request a copy of the personal data we hold about you.
- Rectification — You can ask us to correct inaccurate personal data.
- Erasure — You can ask us to delete your personal data (subject to legal retention requirements).
- Restriction — You can ask us to restrict processing of your data in certain circumstances.
- Portability — You can request your data in a structured, machine-readable format.
- Objection — You can object to processing based on legitimate interest. For product analytics you do not need to contact us: Settings → Privacy has a toggle that takes effect immediately.
- Withdrawal of consent — Where processing is based on consent, you can withdraw it at any time.
To exercise any of these rights, contact us at hello@motionindex.io. We will respond within 30 days as required by GDPR.
If you are not satisfied with our response, you have the right to lodge a complaint with the Norwegian Data Protection Authority (Datatilsynet): https://www.datatilsynet.no.
9. Cookies and Local Storage
Motion Index uses minimal cookies and browser storage. For full details, see our Cookie Policy.
In summary:
- Authentication cookies — Required for you to stay logged in. These are essential and cannot be disabled while using the Service.
- Local storage — Used to remember your UI preferences (theme, display mode, grid settings, sort preferences) and to cache gallery data for performance. This data stays on your device and is not transmitted to our servers.
We do not use marketing cookies, advertising trackers, or third-party analytics cookies.
10. Children's Privacy
Motion Index is not intended for users under the age of 16. We do not knowingly collect personal data from children under 16. If we become aware that we have collected data from a child under 16, we will take steps to delete that data promptly.
If you are a parent or guardian and believe your child has provided us with personal data, please contact us at hello@motionindex.io.
11. Security
We take reasonable technical and organisational measures to protect your personal data, including:
- Passwords stored using one-way hashing (never stored in plain text)
- Cookie-based authentication with secure session management
- HTTPS encryption for all data in transit
- Media storage in EU-based AWS infrastructure (Frankfurt)
- Application error logs kept on our own infrastructure, with console logging stripped in production (except error-level events)
No system is perfectly secure. While we take data protection seriously, we cannot guarantee absolute security. If we become aware of a data breach that affects your personal data, we will notify you and the relevant supervisory authority as required by law.
12. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email or through a notice within the Service at least 14 days before the changes take effect.
The current version of this policy is always available at motionindex.io/privacy.
13. Contact
For questions about this Privacy Policy, data requests, or privacy concerns:
Data controller: CINESUIT AS (operator of Motion Index) Organisation number 931 200 909 Rådhusgata 5, 0151 Oslo, Norway Email: hello@motionindex.io Website: motionindex.io Supervisory authority: Datatilsynet (Norwegian Data Protection Authority) — https://www.datatilsynet.no
This Privacy Policy was last updated on 27 August 2026.