Last updated: May 13, 2026

Privacy Policy

Introduction

This Privacy Policy explains how MotionKit (“MotionKit”, “we”, “us”) collects, uses, and protects your personal data when you visit motionk.it or use our service. We are committed to handling your data in compliance with the EU General Data Protection Regulation (GDPR).

By using MotionKit you acknowledge that you have read and understood this policy.

Who we are

The data controller is 28 bit S.R.L., a Single Member Company with registered office at Strada di Paderna 2, 47895 Domagnano, Republic of San Marino, registered under Economic Operator Code (C.O.E.) SM31527.

For any privacy-related question you can reach us at hello@motionk.it.

Information we collect

We collect only the data needed to operate the service. Specifically:

  • Account data: email address and, if you sign in with a social provider, the basic profile information that provider returns to us.
  • Authentication data: hashed passwords and session tokens, managed by our auth provider (Supabase).
  • Content you create: template configurations, project metadata, and any image, video, or text assets you upload to render videos.
  • Rendered output: the videos generated on your behalf and the parameters used to render them.
  • Billing data: subscription status and customer identifiers. Payment instruments (card numbers, billing address, tax data) are handled directly by Lemon Squeezy as Merchant of Record and never reach our servers.
  • Technical data: IP address, browser, device, and OS information collected through server logs and analytics.
  • Communications: the content of any message you send us at hello@motionk.it.

How we use your information

We process your personal data for the following purposes and on the following legal bases (GDPR Art. 6):

  • To provide the service: create your account, render and store your videos, and deliver the features you request (performance of a contract).
  • To process payments and manage subscriptions through Lemon Squeezy (performance of a contract).
  • To send transactional emails such as sign-in links, receipts, and service notifications (performance of a contract).
  • To keep the service secure, prevent abuse, and debug issues (legitimate interest).
  • To understand product usage in aggregate and improve MotionKit (legitimate interest).
  • To comply with legal obligations, including tax and accounting requirements (legal obligation).

Service providers and data sharing

We do not sell your personal data. We share it only with the service providers that make MotionKit work, each acting as a data processor or independent controller for its own portion of the processing:

  • Supabase (authentication and database).
  • Amazon Web Services (S3 storage for assets and rendered videos, Lambda for rendering).
  • Netlify (website hosting).
  • Lemon Squeezy (payments and subscriptions, acting as Merchant of Record and independent controller for billing and tax data).
  • Plunk (transactional email delivery).
  • Pirsch (privacy-friendly, cookieless website analytics).
  • Mixpanel (in-product analytics, used to understand feature usage).

International data transfers

Some of our providers are based outside the European Economic Area, in particular in the United States (for example AWS, Lemon Squeezy, Mixpanel, Netlify). When personal data is transferred outside the EEA, we rely on the safeguards permitted under GDPR, such as the European Commission’s Standard Contractual Clauses and additional technical measures where appropriate.

Data retention

We keep your personal data only for as long as it is needed for the purposes described above.

Account data and the content you create are retained while your account is active. If you delete your account, we remove your account data and rendered outputs within 30 days, except for information we must keep to meet legal obligations (for example invoices, which we retain for the period required by tax law).

Server logs and aggregate analytics are kept for a limited period and then deleted or anonymized.

Your rights

Under the GDPR you have the right to:

  • Access the personal data we hold about you.
  • Request that we correct inaccurate or incomplete data.
  • Request deletion of your data (“right to be forgotten”).
  • Restrict or object to certain processing activities.
  • Receive your data in a portable, machine-readable format.
  • Withdraw consent at any time, where processing is based on consent.
  • Lodge a complaint with a supervisory authority, in particular the one in the EU country where you live or work.

Cookies and similar technologies

MotionKit uses a small number of cookies and similar technologies. Strictly necessary cookies keep you signed in and are required for the service to work. We also use product analytics cookies through Mixpanel to understand how features are used; our website analytics provider, Pirsch, does not set cookies and does not track individual visitors.

Security

We use industry-standard measures to protect your data, including encrypted connections (HTTPS), encryption at rest with our infrastructure providers, scoped access policies, and isolated per-user storage. No method of transmission or storage is 100% secure, but we work to keep your data safe and to notify you promptly if a breach affecting your data occurs.

Children

MotionKit is not directed to children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us at hello@motionk.it and we will delete it.

Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will update the “Last updated” date at the top of this page and, for material changes, notify you through the service or by email.

Contact

If you have any questions about this Privacy Policy or want to exercise your rights, contact us at hello@motionk.it.