Open the editor

Privacy policy

Last updated: 6 October 2026

This translation is provided for convenience. In case of discrepancy, the Spanish version prevails. Read the Spanish version

Controller

ARSICE NETWORK, Zaragoza. Contact for any privacy matter: emarin@arsice.com.

Your logo

The preview is computed in your browser. When you export, the logo file and the settings you chose are sent to our server, which renders the video or image; the logo and the rendered file are deleted automatically after 15 minutes, whether or not they were downloaded. If you save a project to your account, the logo is kept with it until you delete the project or the account. We do not use logos for anything else or to train any system.

Other data we process

  • Your account, if you make one (you can try the editor without one; downloading, saving or sharing needs one, and it is free): your email, your name if you give it, the language of your emails and how you sign in. If you use a password we only keep a hash of it, never the password; when you choose it we check against Have I Been Pwned that it does not appear in known breaches, sending only the first 5 characters of its SHA-1 hash. The codes and links we send you to sign in expire after 10 minutes and are also stored as hashes. For each open session we keep the IP address and browser, so you can see and close them from your account. And your projects: the logo, the settings and a thumbnail.
  • Your profile review: when your account is new we ask for your name and, if you want to answer, what you will use Motiful for, your team size and how you heard about us; we use it to tailor the product and understand who it serves, never for third-party advertising. Your profile picture: an image we generate from your account, or one you upload (we crop it and store it as a new 256×256 image, without the original file’s data). If you sign in with Google, we keep the address of your Google photo and only use it if you choose to. And if you tick the news box, that you ticked it and when; you can untick it at any time.
  • Technical data of each visit: IP address and browser, for security and to limit free exports per day. For that limit we keep a keyed hash of the IP (not the IP), or your account if you are signed in, and delete it after 2 days. Per-IP counters are deleted when their period ends.
  • Purchases: if you buy a plan, Paddle (see below) collects your payment and billing details. We receive the transaction and customer IDs, your email and, for a project export (or the earlier Pack), the fingerprint of the logo file and its settings (a code that identifies them without containing the image), and we keep the issued licence and, for Pro, the status of your subscription. If you buy without an account and later make one with the same (confirmed) email, the purchase moves to your account. So that you can download a project export again, when you click “pay” we keep the logo and settings of that version; if it is not paid, they are deleted after a day.
  • How Motiful is used review: we measure it ourselves, without third-party tools and without cookies: which pages are visited, which website people come from (only its domain) and the product steps (uploading a logo, choosing a template or a style, changing a setting, exporting, opening the checkout, sharing). Each visit is identified by a code calculated from your IP address, your browser and a key that changes and is deleted every day: we do not keep the IP or the browser, and one day’s code cannot be linked to another’s. What is measured from the browser is never joined to your account; what happens on our server (signing up, signing in, exporting, paying, sharing) is, because those are the same facts we already keep to provide the service. If your browser sends the “Do Not Track” or “Global Privacy Control” signal, we keep nothing of what the browser measures, and the server events are counted without your account or visit code. We use it only to learn what works and improve the product.
  • Your browser: the editor settings, your licence, the session cookie if you sign in and, for a few minutes, the logo you drop on the home page are stored in your own browser.

Legal basis

Providing the service you ask for, including licences and your profile (Art. 6(1)(b) GDPR); your consent, for news and tips emails (Art. 6(1)(a); you can withdraw it at any time, without affecting what came before); legal obligations (Art. 6(1)(c)); and website security and abuse prevention (legitimate interest, Art. 6(1)(f)); and our own usage measurement described above, to understand and improve the product (legitimate interest, Art. 6(1)(f): it uses no cookies or identifiers lasting more than a day, and you can object with “Do Not Track” or “Global Privacy Control”, or by writing to us). We do no profiling, sell no data and use no third-party advertising or analytics.

Who else processes it

  • Paddle.com Market Ltd (United Kingdom) sells the paid plans as Merchant of Record: it is the seller towards you, charges, invoices and handles taxes. It processes your payment data as an independent controller under its own privacy policy.
  • Resend (Plus Five Five, Inc., United States) sends our emails on our behalf: sign-in codes and links, your licence, billing and account notices. It receives your email address and the content of each email.
  • Google, only if you choose to sign in with Google: it gives us your name, email and the address of your profile picture. What Google processes on that screen is governed by its privacy policy.
  • Cloudflare, Inc. carries and protects traffic between your browser and our server.

The server that renders exports and the database (Postgres) are in Spain, on a machine owned by the controller. Some of these providers are outside the European Economic Area; transfers rely on adequacy decisions or the European Commission’s standard contractual clauses.

How long

Logo and export: 15 minutes; the logo and settings of a version you are about to pay for, one day if it is not paid and, if it is, while the service exists (it is what you download again). Free-quota records: 2 days. Usage data (our own measurement): 13 months, then deleted automatically; each day’s key, at the end of the day. Actions we take on your account from the administration (for example, granting or revoking a licence, or handling a request from you) are logged, with who did them and when, while the service exists: that is what lets us answer for them. Your account, sessions and projects: until you delete them; from “Your account” you can delete it all, which deletes the account, sessions and projects. Purchases and licences are kept (without your email or the link to the account, if you delete it) while the service exists, because they are needed for a licence to keep working and to handle refunds. Database backups are kept for up to six months and then deleted automatically.

Your rights

From “Your account” you can download your data (a ZIP with everything we keep about you, as JSON, plus your logos), correct it and delete the account. You can also ask for access, rectification, erasure, objection, restriction and portability by writing to emarin@arsice.com. If you think we did not handle your request properly, you can complain to the Spanish Data Protection Agency (aepd.es).