Skip to content
MotionSpec
Legal

Privacy Policy

This policy explains how MotionSpec handles data across three surfaces: this website, the free motion check, and the hosted MCP connector at api.motionspec.dev. The service is operated by:

Fröba Sales Solutions UG (haftungsbeschränkt)
Johann-Nikolaus-Zitter-Straße 31
96317 Kronach, Germany
Managing director: Kevin Fröba · Amtsgericht Coburg, HRB 7638
Contact: hello@motionspec.dev

What MotionSpec is

MotionSpec provides an open-source npm package and CLI, and a hosted MCP (Model Context Protocol) service that validates and compiles web-animation specifications. The MIT core runs entirely on your own machine; only the hosted connector and the free motion check involve our servers.

The free motion check (website)

On our website (the home page and /motion-check) you can enter any website URL for us to check for motion accessibility. We process (1) the URL you enter, to fetch and analyse the CSS it links to, and (2) your IP address, solely to rate-limit requests as abuse protection. Both rest on our legitimate interest in operating and protecting this free service (Art. 6(1)(f) GDPR). The URL you enter and the result are not stored; your IP address is held only transiently in memory for the rate limit — a 60-second window — and is not logged. We do keep aggregate, URL-free usage counters (how many checks ran, coarse score bands, agent-vs-browser share) via Cloudflare Analytics Engine — these contain neither the URL you enter nor any personal data. There is no profiling, and no data is shared with third parties.

Data we process (hosted MCP connector)

The connector at api.motionspec.dev/mcp exposes keyless tools (motion_catalog, motion_validate) and keyed tools (motion_compile, motion_audit, motion_stats).

  • Keyless tools. Nothing you submit — no specification contents, no prompts — is stored.
  • API key material (keyed tools). Customer keys are stored only as SHA-256 hashes in our key registry; we cannot recover plaintext keys.
  • Request telemetry. Per request we record the tool name, a non-identifying key label, plan tier, timestamp, outcome (ok / fail / rate-limited), and coarse performance counters via Cloudflare Analytics Engine. No specification contents, prompts, or personal data are stored in telemetry.
  • Operational data. Standard Cloudflare edge metadata; the connecting IP and key identity are used transiently for rate-limiting and are not retained as logs.
  • Site funnel counters. To estimate unique visitors on our own pages we record a truncated, daily-rotating hash derived from connection metadata. The raw IP address is never written, the hash cannot be reversed, and it resets every 24 hours.

Buying, delivery and billing

When you buy a paid product on motionspec.dev/pricing — the one-off Motion Report or one of the subscriptions (Dev Key, Agency) — we process the data below. This list is derived from the fields that actually exist in our database, not from a template; the technical field names are shown so that you can check a subject access request (Art. 15 GDPR) against it.

RecordFieldsPurpose
Payment
purchases
row number (purchase_id), timestamp (created_at), Stripe identifiers for the payment (stripe_object_id, stripe_event_id, payment_intent_id, customer_id, subscription_id, payment_link_id), the plan bought (sku), amount and currency (amount_minor, currency), live-or-test flag (livemode), your email address (email), the address you asked us to audit (site_url), processing state and fulfilment time (status, fulfilled_at) performing the contract, matching payment to delivery, refunds, bookkeeping
Report
reports
identifiers (report_id, session_id), your email address (email), the audited address and its host (target_url, target_host), your input verbatim (raw_input), processing state, attempt counter and claim time (status, attempts, claim_at), your personal retrieval token (token), the generated report itself (html), any error text (error_text), timestamps (created_at, ready_at), and revocation with its reason (revoked_at, revoke_reason) generating and delivering the report you bought, retrying on failure, revoking access after a refund
Access keys
dev_keys, dev_key_domains, dev_key_plan
identifier (key_id), a hash of the key and its leading characters (key_hash, key_prefix) — we do not store the key itself —, Stripe subscription and customer (subscription_id, customer_id), your email address (email), state and timestamps (status, issued_at, last_seen_at), revocation and its reason (revoked_at, revoke_reason), the token for your account page (portal_token), tier (plan), predecessor on rotation (rotated_from), live-or-test flag (livemode); per registered domain its name and time range (id, key_id, domain, added_at, removed_at); per tier the plan, domain cap, price, and when and from where it was set (key_id, paket, domain_kappe, price_usd, gesetzt_am, quelle) running the subscription, attributing requests to your contract, enforcing the agreed domain count and rate limit
Account
accounts, account_domains, audit_history
account and Stripe customer (account_id, stripe_customer), tier, domain quota and state (tier, domain_quota, status), creation time (created_at); per domain its membership and timestamps (account_id, domain, added_at, last_audit_at); per run the account, domain, audit id, finding count, score and time (account_id, domain, audit_id, mandatory_a_count, score, run_at) managing your domain slots and the dated audit history that is part of the Agency plan
Send log
mail_log
row number (id), kind of message and what it refers to (vorgang, bezug), recipient address (empfaenger), send time (gesendet_at), sending service and its id (provider, provider_id) evidence that a message was sent, and protection against sending the same message twice
  • Legal basis. Art. 6(1)(b) GDPR (performance of the contract) for purchase, delivery and account management; Art. 6(1)(c) GDPR (legal obligation) for the records German commercial and tax law requires us to keep; Art. 6(1)(f) GDPR (legitimate interest in a traceable, abuse-resistant service) for the send log and revocation markers.
  • Payments — Stripe as merchant of record. Payment runs through Stripe Payments Europe, Ltd., Dublin, Ireland. Stripe acts as merchant of record: it collects the money, calculates and owes the applicable VAT, GST or sales tax, and issues the invoice. You enter your card or bank details with Stripe only — we never see or store them. For Stripe's own purposes Stripe is its own controller; see Stripe's privacy policy. Transfer to the USA is possible and is based on the EU Standard Contractual Clauses.
  • We remain your counterparty. Warranty, withdrawal and refunds are still against us; Stripe's role does not change that.
  • Retention. Payment and invoicing records: as required by German law (§ 147 AO, § 257 HGB — up to ten years from the end of the calendar year). Report content (html) and your input (raw_input): deleted twelve months after delivery.We delete the key hash in the cache as soon as the key is revoked or the subscription ends; the record holding the hash and the domain assignment is kept until the key is revoked.

Business outreach (direct marketing to companies)

We contact companies whose website we have first audited automatically for motion accessibility. If you received such a message from us, you did not give us your data yourself — Art. 14 GDPR applies, and the full notice with every mandatory disclosure is at privacy-outreach (German: Unterrichtung nach Art. 14 DSGVO). This section names the fields.

RecordFieldsPurpose
Company and contact
leads
row number (lead_id), company and web address (company_name, domain, website_url), location and language (jurisdiction, us_state, language), type and size of company (entity_type, subscriber_type, subscriber_type_basis, vertical, regulated_flag, employee_count, employee_band), business contact details (email, email_type, email_status, contact_name, contact_role, contact_linkedin_url), technology detected on the website (tech_stack), the result of our automated audit (animation_score, reduced_motion_guard, mandatory_a_count, mandatory_aa_count, recommended_aaa_count, score, score_tier, report_token), where the record came from and on what legal basis (source, source_url, legal_basis), processing state (can_send, status, date_added, last_contacted_at), and your response (reply_status, sentiment, bounce_flag, opt_out) selecting relevant companies, personalising the message, tracing origin and legal basis per record, honouring your objection
Audit result
audits
identifiers (audit_id, lead_id), audited domain (domain), standard applied (wcag_version), finding counts (mandatory_a_count, mandatory_aa_count, recommended_aaa_count), the findings themselves (findings_json), address of the write-up (report_url), timestamp (created_at) evidence that our outreach has a concrete technical reason — what we audit is the company's website, not a person
Event log
events
row number (event_id), attribution and market (lead_id, market), kind of event (type), its details (payload_json), timestamp (created_at) tracing delivery, replies, bounces and objections; the basis for the alerts by which we notice failures
Suppression list
suppression
email address and/or domain (email, domain), reason and origin of the entry (reason, source), timestamp (added_at) solely so that we never contact you again
  • Legal basis. Art. 6(1)(f) GDPR — our legitimate interest in direct marketing to businesses (Recital 47) and in the continued viability of a small company. For recipients in the United Kingdom we also rely on UK GDPR Art. 6(1)(f) together with PECR reg. 22 (corporate subscriber); the basis chosen for each record is stored in legal_basis. We balanced the interests beforehand and limited the intrusion: business addresses only, at most four messages, no profile about you as a person, and we stop the moment you say so.
  • Where we got it (Art. 14(2)(f)). Publicly accessible sources — the company website, its imprint, its contact page, or a public professional profile — or a licensed B2B contact database (the Lead Finder of our email delivery provider Instantly.ai, paid per record); section 6 of the outreach notice sets this out. We record the specific source for every record (source, source_url) and will tell you which one applies to you.
  • Recipients. Our email delivery provider Foo Monk, LLC dba Instantly.ai, 30 N. Gould St., Ste. R, Sheridan, Wyoming 82801, USA, acting as our processor under Art. 28 GDPR. Transfer to the USA is based on the EU Standard Contractual Clauses (Implementing Decision (EU) 2021/914, Module Two) together with data minimisation; a copy is available on request. We do not sell your data and do not enrich it through third parties.
  • Your right to object (Art. 21(2) GDPR). You may object to processing for direct marketing at any time and without giving a reason; we then stop processing your data for that purpose. The fastest way is the unsubscribe link in our email; an email to hello@motionspec.dev works just as well. Both take effect within 24 hours.
  • Retention. Twelve months from collection, after which we delete the record. One exception: after an objection or unsubscribe your address stays on the suppression list (suppression) indefinitely — for the single purpose of never contacting you again. That list is used for nothing else and is never sold or transferred.
  • No automated decision-making. Our analysis is automated, but it examines the company's website. We make no automated decision producing legal effects concerning you or similarly significantly affecting you (Art. 22 GDPR).

What we do not do

No sale of data, no advertising profiles, no third-party analytics beyond Cloudflare infrastructure, and no storage of compiled output beyond transient processing. The website sets no cookies and uses only Cloudflare's privacy-friendly, cookieless analytics.

Processors

  • Cloudflare, Inc. — hosting, Workers, KV, Analytics Engine, and email routing for hello@motionspec.dev.
  • Stripe Payments Europe, Ltd. — checkout, payment and invoicing, acting as merchant of record (see “Buying, delivery and billing”). For its own purposes Stripe is its own controller, not our processor.
  • Foo Monk, LLC dba Instantly.ai — email delivery for business outreach only (see “Business outreach”).
  • npm and GitHub — distribution of the open-source package (only if you download it).

Retention

Telemetry: aggregated counters, retained per Cloudflare Analytics Engine's default retention. API key hashes: until the key is revoked. Purchase records, report content and outreach data have their own periods — see the two sections above. Backups and logs: 30 days or less.

Reports you bought. The content of a paid report — the HTML version we hold and the PDF in our object storage — is deleted 12 months after the report was made ready. The retrieval link stops working at the same time. What remains is the record of the transaction itself: report ID, session ID, status and timestamps. It is the proof that we delivered, and it is what a refund is matched against. Legal basis: Art. 6(1)(b) GDPR for the report, Art. 6(1)(c) and (f) GDPR for the remaining record.

This period applies only to reports you bought. The free motion check described above stores neither the URL you enter nor its result.

Your rights (GDPR)

You have the right of access, rectification, erasure, restriction, data portability, and objection, and the right to lodge a complaint with a supervisory authority. To exercise any of these, contact hello@motionspec.dev. Legal bases: Art. 6(1)(b) GDPR (provision of the service) and Art. 6(1)(f) GDPR (abuse prevention).

This English text is a plain-language summary and is kept in sync with our binding German Datenschutzerklärung.