العربية · Čeština · Dansk · Deutsch · English · Español (LatAm) · Suomi · Français · हिन्दी · Magyar · Bahasa Indonesia · Italiano · עברית · 日本語 · 한국어 · Nederlands · Norsk · Polski · Português (BR) · Română · Русский · Slovenčina · Svenska · ไทย · Türkçe · Українська · Tiếng Việt · 简体中文

Privacy Policy — Mote

Last updated: 2026-08-12 · Effective date: 2026-05-06

1. Who we are

Mote is a mobile app for couples that helps share everyday moments of appreciation between partners. Privacy is the foundation of the product: data is end-to-end encrypted, the app is offline-first, and most content never leaves your device in a form readable by anyone other than you and your partner.

Data controller: Maciej Siemiński — the developer of Mote. Contact: mail@macsiem.dev

For the version of the app distributed via Google Play, the data controller is LICENCEPRO POLSKA Sp. z o.o., ul. Huculska 6, 00-730 Warszawa, Polska.

This Privacy Policy explains what personal data Mote processes, how, why, and what rights you have.

2. Plain-language summary

We do not store the content of your entries on our servers. Your messages, photos, voice notes, mood check-ins and tags are encrypted on your device and, when synced with your partner, end-to-end encrypted in transit. Mote can be used fully without creating an account; signing in with Apple or Google is optional and enables Premium entitlement sync and encrypted cloud-backup recovery across your devices — we never receive your cloud backup content unencrypted. We use Unity Ads for non-invasive banner ads on auxiliary screens and Apple/Google billing to process in-app purchases. Sentry is used only when explicitly enabled in a build to report crashes. You have full GDPR rights including access, deletion, and portability — most exercisable directly in the app.

3. Data we process

3.1 Local-only data

Entries, messages, tags, mood check-ins, photos and voice notes you add are stored locally on your device in encrypted form (MMKV with a device-derived key kept in Apple Keychain / Android Keystore). When synced with your paired partner's device, content is end-to-end encrypted using tweetnacl keys generated on each device — Mote's developer cannot read your entries.

3.2 Pairing relay (Cloudflare)

To pair two devices, Mote uses a 6-character invitation code or QR code. The pairing relay runs on a Cloudflare Worker + Durable Object (SQLite-backed) hosted by Cloudflare. The relay:

When two devices are paired, they are linked by a random opaque identifier that does not identify a person.

3.3 Diagnostic data (Sentry)

Mote integrates Sentry (sentry.io) for crash and error reporting. Sentry collects:

Sentry does not collect your content (entries, files, vaccination records, photos, archives), usernames, or other PII. Diagnostic data is retained by Sentry for up to 90 days. In some production builds Sentry is intentionally disabled (no DSN configured) — in that case no diagnostic data leaves your device.

3.4 Advertising (Unity Ads)

Mote shows non-invasive ads on Settings, Empty state, and Export. Ads are delivered by Unity Ads, whose SDK collects:

Default mode is non-personalized ads. On iOS, the App Tracking Transparency (ATT) prompt asks for your consent before any tracking-grade identifier is used; on Android you control the Advertising ID under system Settings. Ads can be permanently disabled via the Lifetime / Premium IAP.

3.5 In-app purchases (IAP)

Mote offers paid features through Apple In-App Purchase (iOS) and Google Play Billing (Android). When you make a purchase:

Available products: annual subscription, lifetime unlock, optional tip jar.

3.6 Device permissions

Each permission is requested contextually. You can deny any permission and still use the core features (where applicable).

3.7 What we do NOT collect

3.8 Optional account and sign-in (Apple / Google)

Mote can be used without creating or signing in to an account. Pairing and the core appreciation flow remain available anonymously. Signing in is optional and is used for Premium entitlement sync and encrypted cloud-backup recovery across devices.

When you choose Sign in with Apple or Sign in with Google:

The session JWT is valid for 30 days and may be refreshed during its final seven days. Signing out removes the session stored on the device. Signing out does not delete the server-side account record or encrypted cloud backup.

Mote does not receive your Apple or Google password.

3.9 Encrypted cloud backup (Premium)

Cloud backup is optional and requires an eligible Premium entitlement, sign-in, pairing and an acknowledged recovery phrase. Before upload, the app encrypts the backup on the device using a key derived from the recovery phrase. The service receives ciphertext associated with the internal Mote user ID; it does not receive the recovery phrase or plaintext backup.

The encrypted cloud backup can contain the pairing recovery material needed to restore the pair, the display name used inside Mote and encrypted key material. It does not contain your Apple or Google password. A new upload replaces the current backup for that Mote account.

Keep the recovery phrase safe. The encrypted cloud backup cannot be restored without it.

3.10 Sign out vs. account deletion

The local session JWT expires after 30 days unless refreshed and is removed from the device when you sign out. The provider link, internal user record, entitlement record and current encrypted cloud backup are retained until you use Delete account or ask support to delete them.

Sign out only removes the local session and disables cloud backup on that device. It is not an account-deletion action.

Delete account, used while online, sends an authenticated deletion request to the Mote service and then clears the local account, encryption material and app data. If the device was offline or the request could not be confirmed, contact mail@macsiem.dev to confirm server-side deletion.

Uninstalling the app removes app-local data according to the operating system, but does not by itself guarantee deletion of a signed-in server account or encrypted backup.

4. Why we process this data (purposes)

5. Legal basis (GDPR Article 6)

For users in the European Economic Area, United Kingdom, and Switzerland:

6. Recipients (with whom we share data)

We do not sell personal data. The categories of recipients are limited to providers strictly required to run the app:

RecipientPurposeData categoryPrivacy policy
Cloudflare, Inc.Pairing relay; optional account/session service; entitlement sync; encrypted cloud-backup storageRandom pair ID, encrypted blob, session identifier, encrypted backup ciphertext (only if you sign in and use cloud backup)https://www.cloudflare.com/privacypolicy/
Apple Inc. (Sign in with Apple)Optional account authenticationIdentity token, email address (may be an Apple private-relay address)https://www.apple.com/legal/privacy/
Google LLC (Google Sign-In)Optional account authenticationIdentity token, email addresshttps://policies.google.com/privacy
Unity Technologies (Unity Ads)Serve adsAdvertising ID, device & ad metricshttps://unity.com/legal/privacy-policy
Functional Software Inc. (Sentry)Crash reportingStack traces, device metadatahttps://sentry.io/privacy/
Apple Inc. (App Store / IAP)In-app purchase processing on iOSPurchase token, account-level entitlementhttps://www.apple.com/legal/privacy/
Google LLC (Play Billing)In-app purchase processing on AndroidPurchase token, account-level entitlementhttps://policies.google.com/privacy

We may disclose data if required by a valid court order or other binding legal process, after verifying the request and notifying you where lawful.

7. International transfers

Some of the recipients above are located outside the European Economic Area (mainly in the United States). Where transfers occur, they are protected by:

You can request a copy of the relevant safeguards by writing to mail@macsiem.dev.

8. Retention

DataWhere it livesHow long
Your in-app dataYour device only (encrypted)Until you delete it, uninstall the app, or wipe app data
Pair handshake blobCloudflare relay (encrypted)Up to 24 hours, then automatically expired
Real-time E2E messagesCloudflare relay (encrypted)Stored only until delivered to the paired device, then deleted
Random pair IDBoth devices + relayUntil you unpair or delete app data
Advertising IDUnity Ads systemsPer Unity's retention policy
Sentry crash dataSentry systemsUp to 90 days from the event
IAP purchase token / receiptYour device + Apple / GoogleUntil you uninstall; Apple / Google keep transaction records per their own policies
Session JWTYour device (secure storage)Up to 30 days, refreshable during the final 7 days; removed when you sign out
Provider link, internal account record, entitlement recordMote backend (Cloudflare)Until you use Delete account or ask support to delete it
Encrypted cloud backupMote backend (Cloudflare)Until you delete your account, request deletion, or a new backup replaces it

9. Your rights (GDPR Art. 15–22)

You have the following rights regarding your personal data:

To exercise any right, write to mail@macsiem.dev. We respond within 30 days (extendable by 60 days for complex requests, with notice).

10. Right to lodge a complaint (GDPR Art. 77)

If you believe we are processing your data unlawfully, you may file a complaint with a supervisory authority. For Polish residents:

Prezes Urzędu Ochrony Danych Osobowych (PUODO) ul. Stawki 2, 00-193 Warszawa, Poland https://uodo.gov.pl

You may also file a complaint with the supervisory authority of your habitual residence, place of work, or place of the alleged infringement in another EEA country.

11. Children's privacy

Mote is not directed at children under 13 (under 16 where applicable per local law). We do not knowingly collect personal data from children under that age. If you believe a child has provided us personal data without parental consent, contact us at mail@macsiem.dev and we will delete it promptly.

The "Designed for Families" / "Ages 5+" Apple / Google flags are not set on Mote — the app is rated for general audiences 13+.

12. Security

No system is 100% secure; please keep your device updated and use strong device locks.

13. App Tracking Transparency (iOS) and Advertising ID

On iOS, before any tracking-grade identifier is used by Unity Ads, Mote shows the system App Tracking Transparency prompt. If you decline, Mote serves only non-personalized ads.

On Android, you can reset or limit your Advertising ID under Settings → Google → Ads. Choosing "Delete advertising ID" stops Unity Ads from using a personal identifier; non-personalized ads continue to be shown.

14. In-app purchases

Mote offers the following in-app products through Apple App Store and Google Play: annual subscription, lifetime unlock, optional tip jar.

All payment data is handled by Apple Inc. (App Store / iTunes account) or Google LLC (Play Billing). We never see your card number, your billing address, or your full Apple ID / Google account. Apple and Google return only an opaque purchase token and entitlement metadata that we use to unlock features. Subscriptions can be cancelled at any time in iOS Settings → Apple ID → Subscriptions or in the Google Play app → Subscriptions; cancellation rules are governed by Apple / Google.

15. Changes to this policy

We may update this policy as the app, third-party SDKs, or applicable law change. Material changes will be announced in-app and the "Last updated" date at the top will change. Continuing to use Mote after a change constitutes acceptance of the updated policy.

16. Contact

For privacy questions, exercise of rights, or concerns about this policy:

Maciej Siemiński Email: mail@macsiem.dev

Canonical version of this policy: https://macsiem.github.io/mote-privacy/ Source: https://github.com/MacSiem/mote-privacy