Motions — Privacy Policy

Last updated: July 16, 2026 · Draft pending legal review

This policy explains how Rip Build, Inc. ("Motions", "we", "us", "our") collects, uses, shares, and protects information across motions.games, motions.build, motions.live, and related apps and subdomains — including the Motions Studio games built on the same platform (e.g. 67 Speed, Shadowbox, Pose-Off), which we also operate (together, the "Service"). It should be read together with our Terms of Service. If a term isn't defined here, it has the meaning given in the Terms.

Jump to: What we collect · Camera & biometric data · Guest play · Biometric law (BIPA/CUBI/WA) · How we use it · Sharing & subprocessors · Data retention · Trust & safety · Your choices & rights · California (CCPA/CPRA) · EU/UK/EEA (GDPR) · Cookies & ads · Children · Security & breach notice · International transfers · Changes · Contact

1. What we collect

Account & profile

Email or OAuth identity, handle/display name, account settings, and (for the builder) tester status and builder role.

Content you provide

Games and prompts you create, published games, clips you record and post, scores and handles, room/chat messages, player reports, support/feedback messages, and survey responses.

Camera, motion & biometric data

Client-side processing. Games use MediaPipe hand/pose/face landmark models running locally in your browser to turn your movement into gameplay (scores, rep counts, gesture matches). This processing — landmark detection and analysis — runs on your device, not ours.

By granting camera permission and playing, you provide informed consent — including, where a jurisdiction requires it, informed written consent via electronic signature — to the processing described here and in Biometric law below. Declining camera access means you can't play games that require a camera; some games offer a mouse/pointer fallback instead.

Multiplayer & video calls

Room/match metadata (opponent id, scores, duration, outcome, connection/heartbeat signals), reports you file or that are filed against you, and — for 1:1 video calls — the fact that a call happened. Call video/audio itself is peer-to-peer (browser-to-browser via WebRTC) and does not pass through our servers except when TURN relay is required for connectivity, in which case media is relayed, not recorded or retained by us.

Guest play & claiming

You can play most games without an account. A guest score is stored on that game's public leaderboard tied to whatever guest name you used (or one generated for you) — not to you as a person — plus basic play stats (duration, completion). We don't ask for or store an email, and we don't link it to an account unless a specific game offers a "claim your score" step at the time. Signing in later doesn't automatically retroactively attach past guest scores unless that game offers a claiming flow; guest data tied only to your browser's local storage may become unavailable if you clear it, switch devices, or switch browsers, and we don't guarantee its recovery. Guest play is still subject to this policy, our Terms, and our safety/enforcement systems.

Posting a clip as a guest. If you post a clip without signing in, we create a temporary anonymous account (a random internal ID — no email, no name) so the clip stays attributable, deletable, and rate-limitable. Each guest clip also receives a public, non-identifying support code such as Player-A1B2C3D4-E5F64A1B, derived from that clip's random ID. The code helps you identify which clip to review or remove; it does not identify you or link your separate clips together. That anonymous account lives in your browser's local storage: you can later claim it by adding an email or Google sign-in, which keeps the same account (your clips and scores stay attached). If you clear local storage, switch devices, or go incognito before claiming, the anonymous account can't be recovered and you won't be able to delete those clips from within the product yourself — but you can always have them taken down using the "It's me in this video" report option on the clip or by contacting us.

Usage & device data

IP address, coarse location derived from IP, device/browser type, pages/games viewed, referrer, and similar technical data, collected via Cloudflare Web Analytics (cookieless), Cloudflare Analytics Engine (a lightweight per-play beacon keyed by game slug — not tied to your identity), PostHog (builder funnel events and, on some builder surfaces, sampled session replay — never on gameplay), and Google Analytics 4 / Google Tag Manager (marketing/acquisition). For public clips, we also store a view activation after the real player has begun playback and remained active briefly; loading only a clip card or poster is not intended to increment that count. We use this count in creator, game, feed, and product metrics.

Payment data

Builder credit purchases are processed by Stripe. We receive your billing history, subscription status, and a tokenized payment method reference — never your full card number.

Communications

Support emails, Discord messages, and anything else you send us directly.

If we introduce age or identity verification

We don't use a third-party identity-verification service today. If we or a specific game later engage one (for example, to confirm you meet an age requirement for a feature), that provider may briefly process a government-issued ID image and/or a selfie on its own servers to perform the check; we would store only a verification reference id and the outcome/timestamp, not the underlying ID image, selfie, or any biometric template the provider generates. We'd update this policy before turning that on.

2. Biometric-privacy-law disclosure (Illinois BIPA, Texas CUBI, Washington HB 1493)

If you reside in Illinois (BIPA, 740 ILCS 14), Texas (CUBI, Bus. & Com. Code §503.001), or Washington (HB 1493, RCW 19.375), the following applies to you:

3. How we use information

We do not use your name, voice, photo, clip footage, or likeness in paid outside advertising, app-store listings, or press materials unless you separately opt in (Terms §8) — that's different from the in-product and aggregated-data uses above, which don't require opt-in. The one exception: footage we've edited so no one in it is reasonably identifiable (faces blurred, cropped, or removed) can be used in outside marketing without opt-in, since it's no longer your likeness. If you appear in someone else's posted clip without agreeing to be shown, you can ask us to blur or remove you from it — use the "It's me in this video — take it down" option in the report menu on any clip (no account required), or see Contact us. We prioritize these takedown reports.

4. How we share information & our subprocessors

We use the following providers and partners to operate and support Motions. Where a provider processes information on our behalf, our agreement limits that use to the contracted service. Advertising partners may instead process online identifiers in the roles and for the purposes described in Cookies, analytics & advertising:

ProviderWhat it handles
SupabaseDatabase, authentication, and file storage — account, game, score, clip, and report data.
CloudflareSite hosting/CDN (Pages), object storage for game/clip artifacts (R2), the realtime rooms/multiplayer transport (Workers/Durable Objects), and cookieless traffic + per-play analytics (Web Analytics, Analytics Engine).
StripePayment processing and subscription billing for builder credits. We never see your full card number.
PostmarkTransactional account email (signup confirmation, password reset, magic-link sign-in) sent via Supabase Auth's SMTP integration.
PostHogBuilder funnel analytics and, on some builder surfaces, sampled session replay — never on gameplay.
GoogleGoogle Analytics 4 / Google Tag Manager (measurement) and Google sign-in (authentication, if you use it).
PlaywireAdvertising management through its RAMP platform and our dynamic authorized-sellers file. When advertising tags are enabled, Playwire and the demand partners it authorizes may process online identifiers to serve and measure ads (see Cookies, analytics & advertising).
jsDelivrCDN that serves the MediaPipe camera-tracking model files your browser downloads to run gameplay locally.
Anthropic & OpenAIAI model providers that power the game builder — your builder prompts and conversation are sent to whichever provider is generating your game.

Where information is transferred from the EU/UK/EEA, we rely on Standard Contractual Clauses with these providers (see International transfers). We'll update this list if we add, remove, or replace a subprocessor.

5. Data retention

DataRetention
Account informationUntil you delete your account
Facial/hand/body landmark dataNot retained on our servers — processed locally, discarded per-frame/per-session (see Camera, motion & biometric data)
Guest scores & play statsRetained for leaderboard/history features; not linked to a person unless claimed (see Guest play & claiming)
Scores & play history (signed-in)Retained for leaderboard/history features unless you request deletion
Clips you postUntil you delete them or they're removed for a policy violation
Reports & moderation evidenceTreated as sensitive personal information, admin/trust-and-safety access only; retained only as long as necessary to investigate abuse or appeals, then deleted or anonymized — except evidence under a legal hold (e.g. reported to NCMEC, see Trust & safety), preserved at least one year as required by 18 U.S.C. §2258A(h) and not deleted on request during that hold
Billing & credit-transaction recordsRetained while your account/subscription is active, and up to 7 years after for tax and accounting record-keeping
Stripe webhook/billing event logRetained as part of our payment audit trail; pruned once no longer needed for reconciliation, dispute response, or tax/accounting
Builder prompts & conversationsRetained to provide and improve the builder and, as disclosed above, to improve our AI models
Technical/security logsUp to ~30 days
Aggregated/de-identified dataMay be retained indefinitely — it's no longer tied to you

6. Trust & safety, reporting, and law enforcement

In-product reporting

You can report another player from a room/match. Reports may include a category, a description, and (if you choose to attach one) a screenshot; that evidence is stored in a private, access-controlled bucket available only to our trust-and-safety reviewers and treated as sensitive personal information.

CSAM detection & NCMEC reporting

Motions is an "electronic communication service" under U.S. federal law. If we obtain actual knowledge of apparent child sexual abuse material, child sexual exploitation, child sex trafficking, or the enticement of a minor on Motions, we're required by 18 U.S.C. §2258A (as amended by the REPORT Act of 2024) to report it to the National Center for Missing & Exploited Children (NCMEC) CyberTipline as soon as reasonably possible, and to preserve related evidence. Reports to NCMEC and the underlying evidence are preserved for at least one year (longer if law enforcement requests it) and are not deleted in response to an account-deletion request during that period. Report suspected child-safety violations immediately through the in-product report tool or by contacting us.

Nonconsensual intimate imagery — TAKE IT DOWN Act

Consistent with the federal TAKE IT DOWN Act, we provide a process for victims to request removal of nonconsensual intimate imagery (including AI-generated deepfakes) shared on or through Motions. To submit a request, contact us with: identification of the depicted person; identification of the content and where it appears; a statement of nonconsent (or, for a deepfake, that you didn't consent to its creation or distribution); and your contact information or that of an authorized agent. Valid requests receive action within 48 hours of receipt.

Law-enforcement requests

We respond to lawful government requests for user information consistent with applicable law, requiring legal process appropriate to what's requested (for example, a subpoena for basic subscriber information, a court order for non-content records, or a warrant for content). Where permitted by law, we try to notify affected users before disclosure. Emergency-disclosure requests are handled case-by-case under 18 U.S.C. §2702(b)(8) standards. Send formal legal process to the contact in Contact us.

7. Your choices & rights

You can update your profile/handle and delete your account from Motions account settings, or by emailing us. You can decline camera access, decline a video call, leave a room, and report a player at any time. You can opt out of marketing email via the unsubscribe link in any email. The banner shown on your first visit — and the "Privacy choices" link in the site footer — let you accept or limit non-essential cookies/analytics and set your Do Not Sell or Share preference (see California (CCPA/CPRA)), which this site (and its ad tags) will honor going forward on that browser.

8. California (CCPA/CPRA)

If you're a California resident, in the preceding 12 months we've collected the categories of personal information described in What we collect — including, as sensitive personal information, short-lived in-browser biometric/landmark coordinates and clips/screenshots you or others submit. You have the right to: know what we collect and why; delete it; correct it; opt out of the sale or sharing of personal information; and limit the use of sensitive personal information. Concretely:

Do Not Sell or Share My Personal Information / Limit the Use of My Sensitive Personal Information. Use the control below (or your browser's Global Privacy Control signal, which we honor) to opt out on this device.

We won't discriminate against you for exercising these rights. To exercise them by request instead (including via an authorized agent, who may need to show proof of authorization), email us (Contact us) from the address on your account — we verify requests that way and respond within 45 days, as permitted by California Civil Code §1798.130(a)(2).

9. EU / UK / EEA (GDPR)

Motions is primarily US-first, but if you're in the EU/UK/EEA: our legal bases are your consent (camera access, marketing, non-essential cookies/ads), performance of a contract (providing the Service you asked for), and legitimate interests (fraud/abuse prevention, keeping the Service running). You have rights of access, rectification, erasure, restriction, portability, and objection, and the right to withdraw consent at any time without affecting prior processing. Data is processed in the United States (see International transfers); where required, we rely on Standard Contractual Clauses with our subprocessors. You can lodge a complaint with your local supervisory authority. Residents of other US states with comprehensive privacy laws (e.g. Virginia, Colorado, Connecticut, Utah) have similar rights — contact us to exercise them.

10. Cookies, analytics & advertising

We use: strictly-necessary cookies/local storage (session, auth, security); analytics (Cloudflare Web Analytics — cookieless; Cloudflare Analytics Engine — per-play beacon; PostHog — builder funnel/sampled replay); and, when enabled, advertising technologies managed through Playwire's RAMP platform and its authorized demand partners, which may use cookies or similar identifiers to serve and measure ads, including personalized ads. On first visit, a banner lets you accept this or limit non-essential categories; we record that choice and configure supported tags to honor it, together with the Do Not Sell/Share toggle in California (CCPA/CPRA). You can also opt out of personalized advertising at aboutads.info, use a demand partner's own controls, or block/delete cookies in your browser. We do not use camera/biometric data, clip content, or moderation evidence for ad targeting or ad-model training — see What we collect. Opting out reduces ad relevance; it does not stop all ads.

11. Children's privacy

Motions is not directed to children under 13 and we do not knowingly collect personal information from children under 13, or knowingly sell or share the personal information of anyone under 16. Some features (e.g. 1:1 video "duel" modes) require users to be 18+. We've considered the California Age-Appropriate Design Code and similar children's-privacy laws in how we handle under-13 users, age gates, and default settings — if you believe a child under 13 has used Motions or given us information, contact us and we'll delete it.

12. Security & breach notification

We use encryption in transit, row-level security on our database, and access controls scoped to what each system needs, including admin-only access to moderation evidence and report attachments. No method of transmission or storage is 100% secure, and you're responsible for keeping your own account credentials safe. If we determine that unencrypted personal information was acquired without authorization, we'll notify affected individuals and, where required, the California Attorney General, in the form and timing required by California Civil Code §1798.82 and other applicable breach-notification law. To report a suspected security incident or vulnerability, contact us.

13. International transfers

Motions is operated from and data is primarily processed and stored in the United States (see the subprocessor list in How we share information). Using the Service means you consent to your information being transferred to and processed in the United States, which may have different data-protection laws than your country.

14. Changes to this policy

We may update this policy; the "Last updated" date will change. For material changes — like new categories of data sale/sharing — we'll make reasonable efforts to post a notice on Motions before they take effect.

15. Contact us

Privacy questions, access/deletion requests, security reports, takedown requests, or to exercise any right in this policy: email zakaria@motions.build. Email is our official channel for privacy requests — please don't rely on Discord or other community channels for these. See also our Terms of Service.