Miomoto
Privacy notice

How Miomoto handles personal data.

This notice explains how Moto Video Ltd processes personal data across the Miomoto website, desktop application, web editor, cloud projects, account services, and AI-assisted features.

Last updated August 18, 2026

1. About Moto

Moto Video Ltd ("Moto", "we", "us", or "our") provides the Miomoto desktop application, web editor, website, account services, cloud project storage, and AI-assisted media-generation features (together, the "Service").

Moto is intended for business and professional use. Customers may include companies, freelancers, sole traders, and individual editors acting in the course of their business or profession.

Legal entity: Moto Video Ltd, Israel Privacy and rights contact: support@usemoto.app

This notice explains how Moto processes personal data, the purposes and legal bases for that processing, the parties with whom data is shared, applicable retention practices, and the rights available to individuals.

2. Scope

This notice applies to personal data processed through:

  • the usemoto.app website and account area;
  • the Miomoto desktop application and web editor;
  • account registration, authentication, and administration;
  • browser-local and cloud project functionality;
  • AI generation requests and results;
  • plans, credits, subscriptions, and payments;
  • service emails, support, feedback, and security operations.

It does not govern services that a customer independently chooses to use outside Moto or the independent processing performed by payment providers and other third parties under their own privacy notices.

3. Our Roles

Moto acts as a controller when it determines the purposes and means of processing account, authentication, billing, website, security, service operation, support, and business-contact data.

Moto may act as a processor when it processes project content or other personal data solely on the documented instructions of a business customer. In that situation, the customer is normally the controller and is responsible for its legal basis, required notices, and instructions to Moto. Where applicable, this processing is governed by a Data Processing Agreement with the business customer.

Moto may process limited service, security, billing, and compliance records as a controller even when it acts as a processor for customer content.

4. Personal Data We Process

4.1 Account and authentication data

We process data needed to create, authenticate, secure, and administer an account, including:

  • email address and internal user identifier;
  • account, plan, access, subscription, and credit status;
  • acceptance of service terms and related timestamps;
  • magic-link and login-attempt records;
  • session identifiers, expiry, refresh, and revocation records;
  • login timestamps, IP address, browser or application user agent, and device or platform information.

Moto sends raw magic-link tokens only through the authentication link and stores cryptographic token hashes for verification.

4.2 Access-request and business-contact data

When someone requests access to a limited feature or AI trial, contacts Moto, or communicates with our business, we may process their email address, name, role, company, team size, proposed use, request status, source, message, and administrative notes.

4.3 Browser-local data

The web editor uses browser storage, including the Origin Private File System (OPFS), to maintain a local working copy of projects and media on the user's device. Data that exists only in browser-local storage is not available to Moto unless the Service uploads or synchronizes it.

Clearing browser data, changing browser profiles, using another device, or a browser storage decision may remove or make the local copy unavailable. Moto cannot remotely erase a copy that remains solely on a user's device.

4.4 Project and media data

Projects may contain personal data selected or created by the customer, including:

  • project names, manifests, project documents, timeline data, and revisions;
  • images, video, audio, fonts, and other imported files;
  • generated media, prompts, captions, transcripts, HTML, and metadata;
  • previews, proxies, exports, and project summaries;
  • file names, paths, object sizes, content types, integrity identifiers, storage keys, upload states, and synchronization timestamps.

Desktop projects are normally stored in locations selected by the customer on their device. Cloud projects are stored by Moto so that they can be opened, synchronized, and recovered through the Service.

4.5 AI generation data

When a customer requests an AI operation, Moto may process:

  • prompts, instructions, model selections, and generation parameters;
  • source images, video, audio, masks, or other reference material;
  • temporary object references and time-limited transfer URLs;
  • project, job, queue, provider, status, timing, error, and cost information;
  • generated text, image, video, audio, 3D, HTML, transcript, or other output.

Moto sends only the information needed to perform the selected operation to an active AI infrastructure provider. Moto currently uses Fal for most AI operations and BytePlus for selected video operations. An underlying model provider may also process the request where the selected model is delivered through a third-party API.

Moto configures Fal API requests so that request input and output payloads are not stored in Fal's request history. Fal-hosted generated media is configured to expire after approximately 15 minutes. Moto uses temporary, access-limited Cloudflare R2 objects to transfer customer-provided media where required.

Moto only enables Fal endpoints covered by Fal's enterprise-ready contractual protections. Under Fal's API Services Terms, Fal does not use customer content to create, train, or develop its products or services, and applies that restriction to covered third-party APIs. BytePlus processes customer data to provide the selected AI operation under its applicable service agreement and Data Processing Addendum. Moto does not use customer projects, prompts, inputs, or generated outputs to train Moto models.

Generation job records retained by Moto may include prompts, parameters, status, errors, accounting information, and output references as necessary to deliver the result, recover jobs, administer credits, provide support, prevent abuse, and resolve disputes.

4.6 Billing and transaction data

For paid plans and credit transactions, Moto may process:

  • selected plan, billing interval, subscription status, and renewal period;
  • external subscription, payment, and transaction identifiers;
  • credit grants, usage, adjustments, refunds, and balance history;
  • payment-provider status and webhook events;
  • invoices and accounting information received by Moto.

PayPal processes payment credentials and payment-account information under its own privacy terms. Moto does not receive or store full payment-card details from PayPal.

4.7 Technical, usage, and security data

We process technical information needed to operate and protect the Service, including:

  • IP address, request time, route, response status, and user agent;
  • application version, platform, operation, duration, resolution, and format;
  • project, generation, provider, and transaction identifiers;
  • error details, diagnostic metadata, security events, and abuse indicators;
  • credit usage, supplier cost, and service-performance records.

We seek to avoid placing project content in operational logs unless necessary to investigate a particular fault, security event, or support request.

4.8 Website measurements

Moto records first-party aggregate counters for page views and selected media events. Aggregate dimensions may include date, page, event, referring domain or campaign source, coarse country, and count.

These aggregate records do not use a persistent visitor identifier or retain a full IP address, full referrer URL, or full user-agent string. Infrastructure may nevertheless process an IP address and user agent temporarily to deliver requests, apply rate limits, maintain security, and create operational logs.

Google Analytics is not currently enabled. Moto will update this notice and implement any required consent controls before enabling optional third-party analytics.

4.9 Support, feedback, and communications

When a person contacts Moto or submits feedback, we may process their email, message, attachments, application version, platform, relevant request history, and our response. We also process delivery and event information needed to send authentication, account, access, security, billing, and operational emails.

5. Sources of Personal Data

Moto obtains personal data:

  • directly from customers, account users, and business contacts;
  • from the projects, prompts, media, and instructions customers submit;
  • automatically from devices, browsers, applications, and use of the Service;
  • from PayPal concerning subscription and payment status;
  • from service providers concerning delivery, hosting, storage, security, and generation operations;
  • from a business customer that administers access for its personnel.

7. Cookies and Device Storage

Moto uses cookies, browser storage, and similar technologies that are necessary to authenticate users, maintain sessions, preserve security state, store local projects, and provide requested functionality.

Moto does not currently use third-party advertising cookies or third-party analytics cookies. If optional non-essential technologies are introduced, Moto will provide any notice and consent mechanism required by applicable law.

8. Recipients and Service Providers

Moto limits access to personnel and providers that need personal data for the purposes described in this notice. Current production recipients include:

  • Render Services, Inc.: application, API, private worker, and PostgreSQL database hosting;
  • Cloudflare, Inc.: durable cloud-project storage and separate temporary AI-input storage using R2, together with related network services;
  • Features & Labels, Inc. (Fal): AI request execution and generation delivery, including covered underlying model providers;
  • BytePlus: selected video request execution and generation delivery;
  • Plus Five Five, Inc. (Resend): magic links and transactional service email;
  • PayPal: subscription checkout, payment, and billing administration.

We may also disclose personal data:

  • when required by applicable law, a court, or a competent authority;
  • to investigate fraud, misuse, security incidents, or unlawful activity;
  • to protect the rights, safety, or property of Moto, customers, or others;
  • in connection with a merger, financing, acquisition, reorganization, or sale of relevant business assets, subject to appropriate safeguards;
  • when instructed or authorized by the relevant customer or individual.

Further provider information appears in Schedule 1.

9. International Processing and Transfers

Moto is established in Israel. The European Commission recognizes Israel as providing an adequate level of protection for covered transfers of personal data from the EEA.

Moto's providers may process data in the United States and other countries. For transfers not covered by an adequacy decision, Moto relies on safeguards made available under the applicable provider agreement, including the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or another legally recognized transfer mechanism. Supplementary technical and organizational measures are applied where appropriate.

Individuals and business customers may request further information about the applicable safeguards by contacting support@usemoto.app.

10. Retention

Moto retains personal data only for as long as reasonably necessary for the purposes described in this notice, including service delivery, security, support, legal compliance, and dispute resolution.

10.1 Accounts and authentication

Account records normally remain while an account is active. Magic links normally expire after 15 minutes. Authenticated sessions normally expire after 30 days and may be revoked earlier.

Login, security, and abuse-prevention records may be retained after their operational expiry where reasonably necessary to secure the Service, investigate misuse, or resolve disputes.

10.2 Browser-local projects

Browser-local data remains until it is deleted through the Service, removed by the user or browser, or becomes unavailable because browser storage is cleared. Moto does not control copies stored solely on a user's device.

10.3 Cloud projects and media

Cloud project content normally remains until the project owner deletes the project or the relevant account is deleted. Project deletion marks stored objects for removal, and automated cleanup retries removal when an object cannot be deleted immediately.

Limited metadata may remain where necessary to complete deletion, maintain storage accounting and integrity, investigate misuse, resolve disputes, or comply with law. Provider backups may retain deleted data temporarily until their normal rotation completes.

10.4 Temporary AI inputs and Fal data

Temporary R2 input objects are separate from durable project storage. Upload authorization normally expires after 15 minutes and provider access is time-limited. Temporary objects are subject to automated lifecycle deletion and are not retained as cloud-project media unless the customer separately adds them to a project.

Moto disables Fal request-payload storage. Fal-hosted generated media is configured to expire after approximately 15 minutes. Moto downloads results needed for delivery or project storage before provider expiry.

10.5 AI jobs and generated results

Moto may retain generation-job records while an account is active and afterward for a limited period where needed for result delivery, job recovery, credit accounting, support, fraud prevention, or disputes. Results saved into a cloud project follow the cloud-project retention rule. Results downloaded only to a customer's device are controlled by that customer after download.

10.6 Billing and legal records

Subscription, transaction, invoice, tax, fraud, chargeback, and related records may be retained for the period required by applicable accounting, tax, financial, and limitation laws. PayPal separately retains payment data under its legal obligations and privacy terms.

10.7 Logs, support, and feedback

Operational and security logs are retained for periods proportionate to security, troubleshooting, fraud prevention, and service operation. Support and feedback records are retained while needed to address the request, understand recurring issues, resolve disputes, and protect legal rights.

11. Deletion and Account Closure

A project owner may delete a cloud project through the web project-selection interface. Deletion is irreversible from the user's perspective and schedules the project's stored cloud objects for removal.

An account user may request account deletion at support@usemoto.app. Moto will verify the request and arrange deletion or anonymization of personal data for which Moto is the controller, except where retention is required or permitted for billing, tax, fraud prevention, security, disputes, or legal compliance.

Where Moto acts as a processor, deletion is handled under the business customer's instructions and the applicable Data Processing Agreement. Moto may direct an individual to the relevant business customer when that customer is responsible for the request.

Account closure does not erase project copies, exports, or other files retained solely on a user's device. Cancellation of a subscription and deletion of an account may require separate actions.

12. Security

Moto applies technical and organizational measures intended to protect personal data against unauthorized access, loss, alteration, disclosure, and destruction. Measures include, where appropriate:

  • HTTPS encryption in transit;
  • private object storage and authenticated, time-limited object access;
  • production and administrative access controls;
  • cryptographically hashed authentication tokens and revocable sessions;
  • separation of durable project storage and temporary AI-transfer storage;
  • file integrity verification, upload limits, and quota controls;
  • rate limiting, security logging, monitoring, and cleanup processes;
  • provider contracts and security review.

No online service can guarantee absolute security. Customers are responsible for protecting their devices, email accounts, browsers, credentials, active sessions, exported files, and locally stored projects.

13. Individual Rights

Subject to applicable law, an individual may have the right to:

  • access personal data held about them;
  • correct inaccurate or incomplete personal data;
  • request deletion of personal data;
  • restrict certain processing;
  • object to processing based on legitimate interests;
  • receive eligible personal data in a structured, commonly used, machine-readable format;
  • withdraw consent where processing relies on consent;
  • lodge a complaint with a competent data-protection authority.

Requests may be sent to support@usemoto.app. Moto may request information needed to verify the requester's identity, authority, and relationship with the relevant business account. Moto will respond without undue delay and normally within one month, subject to lawful extensions, exceptions, or limitations.

Where Moto processes data on behalf of a business customer, Moto may refer the request to that customer or assist the customer with its response.

14. Business Customer Responsibilities

Business customers must ensure that they have the right and an appropriate legal basis to submit project content and personal data to Moto. They are responsible for providing required notices and obtaining required permissions from personnel, clients, contributors, performers, and other people represented in uploaded or generated content.

Customers should avoid submitting personal data that is unnecessary for the requested editing or generation operation, particularly special-category, highly confidential, health, biometric, financial, children's, or otherwise regulated information.

15. Children

The Service is intended for business and professional users and is not directed to children. A customer must not permit a child to create or administer an account or submit children's personal data without an appropriate legal basis, authority, and safeguards.

16. Communications

Moto may send authentication, account, security, billing, support, legal, and service-operation messages necessary to provide or protect the Service.

Optional marketing communications will include an appropriate opt-out where required. Opting out of marketing does not prevent necessary service messages.

17. Changes to This Notice

Moto may update this notice when the Service, providers, legal requirements, or processing practices change. The current version and effective date will be published with the notice. Moto will communicate material changes by an appropriate method, such as email, an account notice, or an in-product notice.

18. Contact and Complaints

Privacy questions, rights requests, account-deletion requests, and complaints may be sent to:

Moto Video Ltd, Israel Email: support@usemoto.app

Individuals in the EEA may also complain to the data-protection authority in the country where they live or work, or where they believe an infringement occurred.

Schedule 1: Current Production Providers

ProviderPurposeData involvedGeneral role and safeguards
Render Services, Inc.Public application, API, private worker, and PostgreSQL hostingAccount, authentication, project metadata, AI job and queue records, billing metadata, feedback, aggregate usage, and server logsProcessor or subprocessor under Render's DPA; applicable SCC modules and UK terms are incorporated into the DPA
Cloudflare, Inc.Durable cloud-project R2 storage and separate temporary AI-transfer R2 storageProject files and metadata; temporary reference media and access metadataProcessor or subprocessor under Cloudflare's DPA; SCCs and applicable international-transfer provisions are incorporated into the DPA
Features & Labels, Inc. (Fal)AI generation infrastructure and deliveryPrompts, parameters, temporary reference media, outputs, and provider job metadataProcessor or subprocessor; Fal DPA, security terms, subprocessor controls, and SCCs apply subject to the applicable contractual role
BytePlusSelected video generation infrastructure and deliveryPrompts, parameters, temporary reference media, outputs, and provider job metadataProcessor or subprocessor under BytePlus's applicable service agreement and Data Processing Addendum
Plus Five Five, Inc. (Resend)Transactional emailEmail address, magic link or service-message content, and delivery metadataProcessor or subprocessor under Resend's DPA; Module 2 and Module 3 SCCs and UK terms are incorporated into the DPA
PayPalSubscription checkout, payment, and billing administrationMoto user reference, plan, subscription and payment identifiers, and transaction informationPayPal generally processes payment information as an independent controller under its privacy statement and payment data terms