FeaturesPricingDocsDownload
Get mote
Privacy policy · Effective at 1.0 release

We don't want your data. Here is what we hold anyway.

The short version
  • The app has no account, no telemetry, and no analytics. Your documents never leave your computer through mote.
  • Buying a license goes through Paddle (worldwide) or Toss Payments (Korea), who collect what a payment needs. We receive your email, order ID, and country — never card numbers.
  • Activating a license sends your key, a hashed machine identifier, and the app version to our server. Nothing else.
  • This website uses Google Analytics, loaded only after you accept it, and our own cookieless measurement. Nothing is loaded before you choose. Paddle's checkout script loads when you open the checkout.

1. Who we are

mote is made by MentorGrad ("we"), a business in the Republic of Korea. We are the data controller for everything described here. Paddle.com Market Ltd. is a separate controller for purchases it processes as merchant of record. Our privacy officer is the representative of MentorGrad, reachable at privacy@motemd.com.

2. The application

mote runs entirely on your device. It does not collect usage statistics, crash reports, or file contents, and it does not phone home except in the two cases below. You can verify this with any network monitor; the only hostnames the app can contact are the two named below.

Update check. Once a day, if enabled, the app requests https://updates.motemd.com/latest.json. The request carries the app version and platform. Our server records the request with your IP address hashed together with a key that changes every day, so the record cannot be joined across days or traced back to you; it is kept for 30 days to count installations and to limit abuse. No identifier is attached.

License activation. When you enter a license key, the app sends the key, a one-way hash of a machine identifier, the app version, and the platform to https://license.motemd.com. We store the hash against your license to enforce the device limit. The hash cannot be reversed into a serial number or hostname. Deactivating a device overwrites its hash with zeros at once; the row keeps only the platform and the dates.

Crash reports are never sent automatically. If the app crashes, it writes a report to your disk and offers to open it so you can choose to email it to us.

3. Purchases

Outside Korea, Paddle.com Market Ltd. is the merchant of record. When you buy, Paddle collects your name, email address, billing country, and payment details under Paddle's privacy policy. Paddle sends us your email address, order ID, product, price, tax, and country so we can issue and support your license.

In Korea, you buy from us and pay through Toss Payments, which handles your card or bank details under its own policy. Toss sends us the amount, the payment method type (for example "card"), a receipt link, and the order ID; we also keep the email address and name you typed at checkout. We never receive card numbers from either provider.

We keep order records for as long as your license exists and for seven years afterward to meet tax, accounting, and electronic-commerce record-keeping obligations. Refund and dispute records are kept for the same period.

4. Discount and education requests

If you request education or non-profit pricing, we keep your name, institutional email address, the institution you named, and any note you wrote. The email domain is matched against public lists of academic domains; we do not ask for or store documents. A request is kept until the code it produced expires, plus one year, so that the one-code-per-person rule can be enforced. Codes issued through Paddle also exist in Paddle's systems.

5. This website

This website uses Google Analytics, loaded only after you accept it, and our own cookieless measurement. Nothing is loaded before you choose. Paddle's checkout script loads when you open the checkout. Accepting lets Google Analytics set its own cookies (_ga and _ga_*) and send your visit to Google; declining requests nothing from Google at all. Our own measurement is in development: a random session id in your browser's session storage (cleared when the tab closes), the pages you view and the buttons you press, no cookies, no cross-site identifiers, and your IP address hashed with a daily key and never stored. Your consent choice and analytics setting are remembered in your browser's local storage. We load no fonts from third parties. "Analytics settings" in the footer lets you change your choice at any time.

6. Support

If you write to us through the support form or by email, we keep the conversation to help you and to improve the product. Support requests are stored with a ticket number, your email address, your message, and a daily-keyed hash of your IP address for abuse prevention, and are retained for two years and then deleted. We do not add you to any list.

7. Service providers and international transfers

We use these providers to run the service, each bound by a data-processing agreement or its own terms as a controller: Supabase (database, Frankfurt, Germany); Vercel (website hosting and edge network, United States and worldwide); Paddle (payments outside Korea, United Kingdom and United States); Toss Payments (payments in Korea, Republic of Korea); Resend (transactional email, United States); and Google (analytics, only after you accept). Purchase and support notifications sent to our own team pass through Discord (United States) and contain your email address and order ID. Transfers out of Korea and the EEA rely on the providers' standard contractual clauses and on the necessity of performing our contract with you.

8. How long we keep things

License and activation data: for the life of the license and seven years after. Order, refund, and dispute records: seven years. Support requests: two years. Education requests: until the code expires, plus one year. Update-check and rate-limit records: 30 days and 2 days respectively. Raw payment-provider notifications: 90 days, after which only the derived order record remains. Website measurement events: 13 months. When a period ends, the data is deleted or made anonymous.

9. Legal bases and your rights

We process purchase and license data to perform our contract with you, and keep accounting records to comply with law. Update-check, rate-limit, and abuse-prevention records are processed under our legitimate interest in keeping the service available. Analytics runs only with your consent. Wherever you are, you may ask to see, correct, delete, or receive a copy of your personal data, to restrict or object to its processing, and to withdraw consent; under the Personal Information Protection Act of Korea, the GDPR, the UK GDPR, and the CCPA these are your rights by law. Email privacy@motemd.com; we answer within 10 days. You may also complain to your supervisory authority — in Korea the Personal Information Protection Commission.

10. Security and children

Data in transit uses TLS 1.3; license data at rest is encrypted, access is limited to the people who run the service, and every administrative action is logged. If a breach affects your data, we notify you and the authorities without undue delay. mote is not directed at children under 14 (Korea) or 16 (EEA), and we do not knowingly collect their data; if we learn that we have, we delete it.

11. Changes

If this policy changes in a way that matters, the app's update notice and this page will say so, with a summary of what changed and the date. Previous versions are available on request.

Nothing but writing.
English
© 2026 mote