Privacy Policy

Last updated:

Draft — test deployment. The operator details on this page are not set yet, and this document is not in force until they are.

This document is published in English only. The English version is the one that applies.

1. Who this policy is about

This policy explains what MotionGirl does with information about the people who use it. References to “we”, “us” and “our” below mean MotionGirl. References to “you” mean anyone who visits the site or holds an account on it.

The site is strictly for adults. Nobody under 18 may use it or hold an account, and we do not want their information at all. See the section on people under 18 below.

The service runs on one shared account system that also serves a sibling site of ours. If you have used both, the same account, credit balance, plan and history stand behind each of them, and this policy covers that shared record.

2. What we collect, and why we hold it

We keep the smallest set of information that lets an account work, be paid for, and be defended against abuse. Each category below says what it is and what it is for.

Account details. Your email address, a display name, and a photo URL if your sign-in method supplied one. If you sign in through Telegram, or pay through it, we also store the numeric account id it gives us. We hold these because they are what an account is: without them we cannot let you back in, address you, or show you your own history. If you signed up with a password, what we store is a bcrypt hash of it, never the password.

Sign-in material. One-time codes sent to your email address, which are short-lived and are cleared once used or replaced, and the session token issued when you sign in. These exist so that we can tell you apart from someone claiming to be you.

Credits and the ledger. Your credit balance, and one record for every movement of it: the amount, a machine-readable type, a short description and the time. If a member of our staff adjusts a balance, the record also names which staff account did it. The ledger is append-only — entries are added, never edited — because a balance nobody can reconcile is a balance we cannot honestly show you.

Your plan and your payments. Which tier and term you bought, when it expires, and one record per payment: the rail it came in on, what it was for, the amount, its status and the provider’s reference for it. We do not receive or store card numbers — no card is ever entered into this service. On the crypto rail we hold the order reference and the confirmation the processor reports; on the Telegram rail, the charge id it gives us, which is also what a reversal is matched against.

Referral records. A referral code of your own, a record of who introduced whom, the commission entries produced by a referred account’s payments, and the payout address you give us when you ask to withdraw. These exist to run the partner programme described in the terms.

Technical records. The IP address the account signed up from and the one most recently seen, a language code, a country code derived from the connection, and the times an account was created and last active. These are how we spot duplicate accounts, referral self-dealing and credential stuffing, and how we honour any restriction on where the service may be offered.

Uploads and what is made from them. When you upload a photo to a template, that photo is sent to the rendering provider that performs the generation and is processed in order to produce the video you asked for. That is the whole purpose it is used for: it is not used to train anything, it is not published, and it is not shown to other users.

Generation records. For each generation, which template you ran, the settings you chose, the prompt if you typed one, what it cost, whether it succeeded, and the link to the result. These are what your collection is made of, and they are what lets us return credits when a generation fails and answer you when you say one did.

Messages you send us. If you write to support, by email or through Telegram, we keep the correspondence so the next person who reads it has the history.

3. The purpose and the basis for each of those

Where the law requires a stated basis for processing, these are ours, category by category.

  • Performing our agreement with you — account details, sign-in material, credits and the ledger, your plan and payment records, referral records, and processing an upload into the output you asked for. Without these the service cannot be delivered at all.
  • Our legitimate interest in a service that is not abused — technical records, rate limits, fraud, payment-reversal and duplicate-account checks, and enforcing the prohibitions in the terms. We think this is a fair use of the data because the alternative is a platform that cannot keep out the conduct it forbids.
  • Your consent — anything optional you choose to add, such as signing in through a third-party account or supplying a display photo. You can withdraw that consent by removing the item or closing the account.
  • Legal obligation — records we are required to keep, including accounting records for payments taken, and anything we must retain in response to a lawful request.

Where the basis is our legitimate interest, you can object; see your rights below.

4. What we do not do

We do not sell your information, and we do not trade it for anything of value. We do not build advertising profiles, and we do not share your activity with advertising networks.

We do not use your uploads or your generated videos to train models. We do not put them in the public catalogue, and no other user can reach them through the service.

We do not read your generations to profile you, and there is no automated decision with a legal or similarly significant effect on you. Content checks happen — an upload can be refused, and an account can be suspended under the terms — and where one of those decisions goes against you, a person can look at it if you ask.

5. Uploads and generated videos

An uploaded photograph is held on our side for about 2 hours — the window the generation needs it for — and is then dropped. The rendering provider takes its own copy in order to run the job, and keeps it under its own schedule.

A finished video is kept for as long as your plan pays for. While a plan is running that is between 3 and 12 months from the moment the video completed, depending on the tier, and the exact date is shown against the video in your collection. Without a running plan there is no storage period: the video stays reachable only for the short window the rendering provider keeps its own copy, which is measured in hours.

Deletion at the end of that period is automatic and permanent. A deleted video cannot be restored, by you or by us. Downloading one gives you a copy that is yours to keep — these periods apply only to the copy on our systems.

You can delete a generation from your collection yourself at any time before its period ends, and doing so removes it from the service.

6. Who else handles your information

We use a small number of outside providers to run the service. They are described here by the job they do rather than by name, because the supplier for a given job is a configuration decision that can change without the substance of this policy changing. We can tell you the current supplier for any of these roles if you ask.

  • A hosting and database provider runs the servers and stores the database. It holds everything the service holds, and processes it only on our instructions.
  • A generation provider runs the models. It receives the photograph you uploaded, the template and settings for the job, and returns the video, which it also hosts. It is the one outside party that sees your uploads, and it sees them in order to do the thing you asked for.
  • Payment providers — Telegram’s own payment rail, and a cryptocurrency payment processor. Each receives what it needs to take the payment and reports back its result. Neither passes us card details, because no card is ever entered into this service, and what we keep of a payment is described above.
  • An email delivery provider sends the one-time sign-in codes. It receives your email address and the message we ask it to deliver.
  • Identity providers — the account systems behind the optional social sign-in buttons. These only come into it if you choose one, and then only to confirm that the account is yours and to pass us a basic profile. They handle what they receive under their own terms, not ours, and we do not control that.
  • A content delivery network serves images and video. It sees the network request needed to deliver a file — including your IP address — as any network carrying a file must.

We may also disclose information where we are legally required to, or where it is necessary to establish or defend a legal claim, or to protect someone from harm. If the business is ever sold or reorganised, the records may pass to the acquirer, who would be bound by a policy no less protective than this one.

7. Cookies and browser storage

We do not set advertising cookies, and there are no third-party tracking scripts on the site. What the site does use is your browser’s local storage, which stays on your own device, and it holds exactly four things:

  • Your session token — the bearer token that keeps you signed in between visits. Anyone with access to your browser profile has access to your session, so sign out on a device you share.
  • Your language choice — so the interface opens in the language you picked instead of guessing again from your device.
  • Your theme choice — the appearance you selected, so the page paints the right way before it is shown to you.
  • Your age confirmation — a single marker recording that you confirmed you are 18 or over, so the entry gate is not put in front of you on every visit.

None of these is sent to anyone but us, and the last three are never sent anywhere at all — they are read by the page itself. Clearing your browser’s storage for this site removes all four: you will be signed out, and the age confirmation will be asked for again.

One of our two sites carries links to the other. Those links spell out which page and which placement sent you, so we can tell what works. That marker describes the placement, not you: it is the same for everyone who clicks the same thing, and it carries no identifier of any kind.

If we ever add analytics or advertising technology, this section will be rewritten before it goes live, and where consent is required we will ask for it rather than assume it.

8. How long we keep it

  • Account details — for as long as the account is open.
  • One-time sign-in codes — minutes. They are cleared when used, when replaced, or when they expire.
  • The credit ledger, payment and referral records — these outlive the account. They are financial records: they show what was paid, granted, spent and owed, we are required to keep accounting records for a period set by law, and deleting them would leave balances and commissions that cannot be reconciled or audited.
  • Technical records — signup and last-seen addresses are kept with the account; server logs are kept for a limited operational period and then discarded.
  • Uploads — about 2 hours on our side.
  • Generated videos 3 to 12 months while a plan is running, hours without one. See the section above.

Closing an account marks it closed rather than erasing every row immediately. The account stops working and stops being usable, and the address cannot be re-registered; what remains is the record we are required or entitled to keep, as set out above. If you want the remaining personal details erased rather than closed, ask us and we will erase whatever we are not obliged to keep.

9. Your rights

Depending on where you live, some or all of the following apply to you. We will honour them regardless of where you live, as far as we are able:

  • Access — ask what we hold about you, and get a copy.
  • Correction — have anything inaccurate fixed.
  • Deletion — have your account and personal details removed, subject to the records described above that we must keep.
  • Export — receive your data in a machine-readable form you can take elsewhere.
  • Objection and restriction — object to processing we do on the basis of legitimate interest, or ask us to pause processing while a dispute is worked out.
  • Withdrawal of consent — where we relied on consent, take it back at any time. That does not undo processing already carried out.

To exercise any of these, write to [email protected] from the email address on the account, or reach us through our support channel, saying which right you are exercising. If we cannot tell that the request comes from the account holder we will ask you to confirm control of the account — an identity check that let a stranger read someone’s history would defeat the point of having one. We aim to answer within one month, and will tell you if a request will take longer.

If you are unhappy with how we handled a request, you may complain to the data protection authority for your country.

10. Where your information goes

We and our providers operate across more than one country, so your information may be stored or processed outside the country you are in, including in countries whose data protection law differs from your own. Where that happens we use providers that commit contractually to protecting the data to the standard described in this policy, and we rely on the transfer safeguards available to us in law. You can ask us which safeguard applies to a particular provider.

11. People under 18

This is an adult service. It is not directed at children, no part of it may be used by anyone under 18, and we do not knowingly collect information about anyone under 18.

If we learn that an account belongs to someone under 18, we close it and delete the personal information held under it. If you believe a minor has an account here, or that an image of a minor has been uploaded, write to [email protected] immediately and we will act on it as a priority.

12. How we protect it

Traffic to and from the site is encrypted in transit. Passwords are stored only as bcrypt hashes. Sessions use signed tokens that expire. Access to the production database is limited to the people who need it, and staff adjustments to a balance are recorded against the staff account that made them. No system is perfectly secure, and we do not claim otherwise; if a breach affects you and the law requires us to tell you, we will.

13. Changes to this policy

We will update this policy as the service changes. The date at the top always reflects the current version. If a change materially affects your rights, we will draw attention to it in the product or by email to the address on your account, rather than relying on you noticing a new date.

14. Contact

Privacy questions and requests: [email protected], or our support channel. Please say which site your account is on, as one account system serves two.

15. 18 U.S.C. § 2257 exemption

MotionGirl operates as a purely AI-generated content platform where no real individuals are portrayed or engaged in any content creation. All content accessible on the Service is exclusively generated through artificial intelligence technology. This method eliminates the participation of real human beings in the creation of images, videos, or any other material available on our platform.

The Federal Labeling and Record-Keeping Law (18 U.S.C. § 2257) is therefore not applicable to any content produced by or available on the Service.