Legal

Privacy policy

Last updated 30 August 2026

This page is the record of what MotiBlog holds about you and what we do with it. It matches the product as shipped, not a template.

Who we are

MotiBlog is the autoblogging service at motiblog.ai. It is operated by Jenga CodeLabs. Write to us at support@motiblog.ai.

What we collect

When you use MotiBlog we hold:

  • Account details: email, name, and either a password hash or your Google account id and avatar if you sign in with Google.
  • Billing records: Stripe customer and subscription ids. Card numbers stay with Stripe; we never store them.
  • Project data you give us: site URL, CMS credentials, brand voice, product facts, authors, and anything else you type into the dashboard.
  • Pages we crawl from your site and from competitor URLs you add, plus the articles and images we generate for you.
  • Search Console tokens and query data if you connect Google Search Console.
  • Email preferences, notification history, and newsletter sign-ups.
  • Text and URLs you submit to the free tools (title tags, meta descriptions, and the rest).

How we use it

We use this data to run the product: sign you in, research and write articles, publish to the CMS you connect, bill the plan, send transactional mail (verification, password reset, receipts, publish notices), and — unless you opt out — occasional product email. We do not sell personal data.

Google API data

Google connections are optional and limited to the Google account and MotiBlog project you choose. If you connect Google Search Console, we access its site, search-query, page-performance, and URL-inspection data. If you connect Google Analytics 4, we use the read-only analytics.readonly permission to access the GA4 properties available to your account and the property you select. From that property, we store aggregated landing-page metrics: sessions, active users, key events, and total revenue. We cannot create, change, or delete data in your Google Analytics account.

We use Google user data only to provide MotiBlog's user-facing features: syncing your project's search and analytics results, showing performance and indexing status, combining Search Console demand with GA4 outcomes, and producing project-specific content opportunities, refresh suggestions, and reports. We do not use Google user data for advertising, sell it, provide it to data brokers, use it to determine creditworthiness, or use it to develop, improve, or train generalized AI or machine-learning models.

We disclose Google user data only as needed to provide those features: to Hetzner, which runs the MotiBlog API; to Neon, which stores the project database; to Google when MotiBlog exchanges OAuth tokens or requests Google API data; and to an AI agent or MCP client only when you explicitly authorize that application to access the relevant MotiBlog project. These providers process the data on our behalf or at your direction. We do not transfer or disclose Google user data to any other third party except when you direct us to, when required by law, or when necessary to investigate fraud, abuse, or a security threat.

Google OAuth access and refresh tokens are encrypted at the application layer with AES-256-GCM before storage. Google API requests and product traffic use HTTPS/TLS encryption in transit. Access to stored Google data is limited by authenticated account and project permissions; production encryption keys and credentials are kept outside the source code; and OAuth tokens are excluded from user-facing responses and operational logs. We limit staff and service-provider access to people and systems that need it to operate, secure, or support MotiBlog.

You can disconnect Google Analytics or Search Console at any time. Disconnecting removes the corresponding OAuth connection and its synced analytics or search data from the live project. You can also revoke MotiBlog in your Google Account permissions. The retention and deletion periods below apply to any remaining backups or records.

Agents and MCP connections

When you connect an AI agent through MotiBlog's MCP server, we store the connecting application's name and redirect addresses, the permissions you approved, the project you selected, and hashed OAuth credentials. Access and refresh tokens are not stored in readable form. You can revoke a connection from Agent access in the dashboard.

For each MCP action, we process the tool name, the arguments needed to perform that action, and the MotiBlog account or project data needed to return the result. We do not ask for or collect the agent's surrounding conversation, chat history, memory, or unrelated files. MCP data is used only to authenticate the connection, perform the requested operation, prevent abuse, and diagnose failures.

Cookies

Signed-in sessions use two httpOnly cookies, access_token and refresh_token. They are required for the app to work. Stripe sets its own cookies on checkout. If Crisp chat or Google Analytics is loaded on a page, those vendors set their own cookies.

Who processes it

We use these processors to run MotiBlog:

  • Vercel — the website
  • Hetzner — the API
  • Neon — the database
  • Cloudflare R2 — images
  • Stripe — payments
  • Resend — email
  • Google — sign-in, Search Console, and Gemini when that model is selected
  • OpenAI and other model providers you pick for generation
  • Crisp — support chat, when the widget is on
  • Vercel Analytics — page traffic

Several of these run in the United States. Using MotiBlog means that data can leave your country.

Your rights

You can ask for a copy of your data, a correction, or deletion. Account deletion is not self-service yet — email support@motiblog.ai and we will delete the account and the projects, articles, crawls and tokens attached to it. We keep billing records Stripe requires us to keep.

Every product email has an unsubscribe link. Transactional mail (verification, password reset) still goes out so the account stays usable.

How long we keep it

We keep account and project data while the account is open. We complete verified deletion requests against live systems within 30 days. Deleted data may remain in encrypted infrastructure backups for up to 90 more days before those backups rotate out; we do not restore it except for disaster recovery. Invoices and transaction records may be kept for up to seven years where tax, accounting, or payment law requires it.

MCP authorization requests expire after 10 minutes, authorization codes after one minute, access tokens after one hour, and refresh tokens after 30 days. Expired OAuth rows are removed by an hourly cleanup. Revoking an agent blocks the grant immediately; its hashed token record remains only until that normal expiry cleanup or account deletion. Operational request logs are retained for no more than 30 days for security, abuse prevention, and service diagnosis.

Security reports

Report a suspected vulnerability or unsafe connector behaviour to support@motiblog.ai with “Security report” in the subject. We investigate reports and will work with the reporter on reproduction, remediation and responsible disclosure.

Children

MotiBlog is not for anyone under 16. We do not knowingly collect their data.

Changes

If this policy changes we will update the date at the top of this page. Material changes will also go out by email to the address on the account.

Questions: support@motiblog.ai