Privacy Policy
Learn how we collect, use, and protect your personal information on the Motif platform.
Effective Date: August 25, 2026
Version: 1.5
1. Introduction
Motif ("we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our biomedical research platform ("Service").
This Privacy Policy describes our data practices. Our legal bases for processing your personal data are set out in Section 3.6.
2. Information We Collect
2.1 Information You Provide
We collect information you provide directly:
- Account Information: Email address, name, organization affiliation
- Research Data: Search queries, uploaded documents, annotations
- Payment Information: Billing details processed through Stripe
- Communications: Support requests, feedback, correspondence
2.2 Information Collected Automatically
We automatically collect certain information:
- Usage Data: Features used, search patterns, session duration
- Device Information: Browser type, operating system, device identifiers
- Log Data: IP addresses, access times, pages viewed
- Cookies: Session tokens, preferences, analytics data
2.3 Information from Third Parties
We may receive information from:
- OAuth Providers: Google account information when you sign in
- Payment Processors: Transaction confirmations from Stripe
- Analytics Services: Aggregated usage statistics
2.4 Special Categories of Data
Our Service is a research tool. We do not intentionally collect data concerning your personal health. Search queries about biomedical topics are processed to deliver research results and are not used to infer your personal health status.
The Service may not be used to upload or process Protected Health Information or other individually identifiable health information. This is a contractual prohibition under Section 7.3 of the Terms of Service, not a recommendation: Motif is not a HIPAA business associate, does not sign Business Associate Agreements, and its safeguards are not designed or assessed for this category of data. Do not upload documents containing your own or any other individual's personal health data unless it has been de-identified in accordance with 45 C.F.R. § 164.514.
3. How We Use Your Information
3.1 Service Delivery
We use your information to:
- Provide and maintain the Service
- Process your research queries and requests
- Manage your account and subscriptions
- Provide customer support
3.2 Service Improvement
We use data to:
- Improve AI models and search algorithms
- Develop new features and functionality
- Analyze usage patterns and optimize performance
- Conduct research and analytics
3.3 Communication
We may contact you to:
- Send service-related notifications
- Provide updates about your account
- Share important security alerts
- Send marketing communications (with consent)
3.4 Safety and Abuse Prevention
We screen research queries, and the names you choose for your profile or organization, through an automated content classifier operated by OpenAI. We use this to detect abuse of the Service and to recognise the narrow case where a query indicates that someone may be at risk of harming themselves, so that we can show crisis support resources.
Text sent to this classifier is not retained by OpenAI and is not used to train OpenAI's models. OpenAI's moderation endpoint holds no abuse-monitoring logs and no application state, so the screening leaves no copy of your query with them.
This screening does not make any decision about you, does not affect your account, and is not used for profiling. Queries flagged as indicating risk are answered with support resources instead of a research result; we record that this occurred, but we do not store the text of the query. Legitimate biomedical research on self-harm, overdose, toxicity, or related clinical topics is not restricted.
3.5 Legal Compliance
We process data to:
- Comply with legal obligations
- Respond to lawful requests
- Protect our rights and property
- Enforce our Terms of Service
3.6 Legal Basis for Processing (EEA Users)
Under GDPR, we process your data on the following bases:
- Contractual necessity (Article 6(1)(b)): Service delivery, account management, subscription processing
- Legitimate interest (Article 6(1)(f)): Service improvement, security, analytics, safety and abuse prevention (see Section 3.4), AI model training (see Section 3.7)
- Consent (Article 6(1)(a)): Marketing communications, analytics cookies
- Legal obligation (Article 6(1)(c)): Tax records, regulatory compliance
3.7 AI Model Training
We may use your research sessions (the prompts Motif sends to a language model on your behalf and the responses it receives, including the text of the documents those prompts carry) and your organization's knowledge graph (the entities, associations, evidence links, and reports Motif produces for you) to train and improve our own AI models. We rely on legitimate interest (Article 6(1)(f)) for this processing, having weighed our interest in improving extraction quality against your privacy rights. Research sessions and graph data belong to scientific work rather than to personal life, and the data of any user who has objected are excluded from the eligible corpus at the point of use, so an objection also covers sessions and graph data already recorded.
The setting is enabled by default and each user can disable it at any time in dashboard settings, which is how the right to object under Article 21 GDPR is exercised. Disabling it excludes your past and future research sessions and knowledge graph data from every training run started from that point; it cannot remove data from models already trained. Enterprise agreements exclude model training as a contract term.
Your knowledge graph is not shared with other customers. Files you upload are not read out of storage for training; their text is processed only as part of the research sessions you run. See How Motif uses your data to improve our AI models.
4. Data Sharing and Disclosure
4.1 Service Providers
We share data with trusted third parties:
- Cloud Infrastructure: Fly.io (backend compute), Vercel (frontend hosting)
- Database & Storage: Neon (PostgreSQL database), Cloudflare R2 (object storage for uploaded documents), Upstash (Redis cache and job queue)
- Payment Processing: Stripe (billing and subscriptions)
- Email Services: Resend (transactional emails)
- Authentication & Bot Protection: Google (OAuth sign-in, reCAPTCHA)
- AI Processing: OpenRouter, which routes to third-party large language model providers (query processing, entity extraction, and cross-referencing). A current list of AI sub-processors is available upon request.
- Content Moderation: OpenAI (safety classification of research queries and of names you choose for your profile or organization)
- Analytics: Google Analytics (usage statistics, when analytics cookies are consented to)
- Marketing: Meta (advertising measurement, when marketing cookies are consented to)
AI Processing Disclosure: Your search queries and selected documents are processed through OpenRouter, which routes requests to third-party large language model providers, to provide AI-powered summaries, entity extraction, relationship identification, and cross-referencing. These providers process this data under our data processing agreements and do not use your data to train their models. Because routing is dynamic, this processing may occur outside the United States and EU. A current list of AI sub-processors is available upon request at hello@motif.bio.
4.2 Your Knowledge Graph
Your knowledge graph is visible only to members of your own organization, on every plan. We do not aggregate it with other customers' data, do not display it to other customers, and do not license or sell it to third parties.
Within your organization, entries record which member created them so that colleagues can see who extracted what. You can remove that link at any time using Anonymize My Contributions in dashboard settings, which replaces your identity with an anonymous system identifier and leaves the scientific data in place.
4.3 Legal Requirements
We may disclose information:
- To comply with legal process
- To respond to government requests
- To protect our rights or safety
- In connection with corporate transactions
4.4 With Your Consent
We may share information for other purposes with your explicit consent.
4.5 Controller and Processor Roles
When you use the Service as an individual, Motif is the data controller. When your organization subscribes and you use the Service as an authorized user, your organization is the data controller and Motif acts as a data processor under a Data Processing Agreement in accordance with GDPR Article 28.
5. Data Retention
| Data Type | Retention Period |
|---|---|
| Account credentials, sessions, and preferences | Duration of account; deleted when you delete your account |
| AI processing logs | Duration of account; deleted when you delete your account |
| Search queries and search history | Duration of account; retained in de-identified form after deletion |
| Knowledge graph entries | Duration of account; retained in de-identified form after deletion |
| Article Library documents | Unextracted: until you remove them from the library, then deleted from object storage if no other organization still holds a live copy. Extracted: archived on removal; files stay in object storage. After account deletion: retained in de-identified form. See Section 5.3 |
| Audit and security logs | Retained as a security and legal record, including after account deletion |
| Billing records | 7 years (legal requirement) |
5.1 What Happens When You Delete Your Account
Deleting your account removes your identity from the Service. It does not erase the scientific record your organization built, and it does not delete the documents in your library. Read this section before deleting, because the action takes effect immediately and cannot be reversed.
Deleted immediately when you confirm:
- Your user account, login credentials, and any connected Google sign-in
- Every active session, on every device
- Your profile, preferences, and organization membership
- Your AI processing logs
Retained, with your identity removed: the entities, associations, observations, conversations, and research context you created are re-attributed to an anonymous system identifier and remain in your organization's knowledge graph. Documents you uploaded remain in the Service as part of that de-identified corpus, detached from your account. Once your account record is gone, these entries no longer identify you.
Retained as a legal or security record: audit and security logs recording access to the Service, and billing and tax records for seven years.
If you want an unextracted document removed from object storage, remove it from your library before deleting your account. Extracted articles are archived rather than deleted when you remove them; their files stay in object storage (Section 5.3). There is no export window after account deletion: your access ends the moment the deletion completes, so export anything you want to keep beforehand.
Research sessions already included in a model training run cannot be withdrawn from models that have already been trained. See Section 3.7.
If you want your name removed from your contributions without losing access, use Anonymize My Contributions in dashboard settings instead. This is described in Section 4.2.
5.2 Retention After Subscription Cancellation
Cancelling a subscription is not the same as deleting your account. For 90 days after cancellation you retain read and export access to the data you paid to produce. Nothing is deleted when that window closes; your access to create new work ends, and your account and its data remain until you delete the account.
We may retain data longer where required by law.
5.3 Removing articles from your Article Library
Removing an article from the Article Library is not always deletion. What happens depends on whether extraction has completed for that article in your organization.
Not extracted. Motif permanently deletes the article from your library. The PDF and any supplementary files are removed from object storage if no other organization still has a live copy of the same article. This cannot be undone.
Extracted. Motif archives the article. The PDF and supplementary files stay in object storage. Associations stay in your knowledge graph, so citations and provenance remain. You can restore the article from the Archive filter. There is no Article Library action that deletes an extracted article's files from object storage.
Account deletion does not run this removal. Documents still in the library, including archived extracted articles, remain with your organization in de-identified form as described in Section 5.1.
6. Your Privacy Rights
6.1 Access and Portability
You have the right to:
- Access your personal data
- Export your data in standard formats
- Receive a copy of your information
6.2 Correction and Deletion
You may:
- Update inaccurate information
- Request deletion of your personal data
- Withdraw consent for processing
Deletion covers your personal data. It does not extend to scientific content that has been de-identified, because once your identity is removed from an entity, association, search record, or uploaded document, that material is no longer personal data and no longer relates to you. Section 5.1 sets out exactly which category each type of data falls into on account deletion. Section 5.3 sets out what happens when you remove an article from the Article Library, which is not the same as account deletion.
Withdrawal of consent is as easy as giving it: manage cookie preferences via the consent panel, or turn off model training via your dashboard settings. Withdrawal does not affect the lawfulness of processing before withdrawal.
6.3 Opt-Out Rights
You can opt out of:
- Marketing communications
- AI model training (via Help improve our AI models in dashboard settings, on every plan)
- Non-essential cookies
6.4 GDPR Rights (EEA Users)
If you are in the European Economic Area:
- Right to erasure ("right to be forgotten"), exercised through account deletion in dashboard settings. Erasure applies to your personal data. De-identified scientific content is outside its scope under Recital 26, because it can no longer be attributed to you; see Section 5.1
- Right to restrict processing
- Right to data portability
- Right to object to processing
- Right regarding automated decision-making: We do not make decisions based solely on automated processing that produce legal effects or similarly significant effects concerning you (Article 22)
- Right to lodge a complaint with your local data protection authority
6.5 CCPA/CPRA Rights (California Residents)
California residents have the right to:
- Know what personal information is collected and how it is used
- Request deletion of personal information
- Request correction of inaccurate personal information
- Opt out of the sale or sharing of personal information
- Access their personal information
- Equal service and price, regardless of privacy choices
Motif does not sell your personal information as defined under the CCPA/CPRA. Our tiered subscription model reflects different feature sets, not compensation for personal data.
To exercise your CCPA rights, contact hello@motif.bio.
6.6 Response Timeline
We will respond to privacy requests within one month of receipt (GDPR) or 45 days (CCPA). If an extension is necessary, we will inform you within the initial period.
7. Data Security
7.1 Technical Measures
We implement security measures including:
- Encryption in transit (TLS 1.3)
- Encryption at rest (AES-256)
- Access controls and authentication
- Regular security assessments
7.2 Organizational Measures
We maintain security through:
- Employee training on data protection
- Incident response procedures
- Vendor security assessments
- Regular policy reviews
7.3 Breach Notification
In case of a personal data breach:
- We will notify the competent supervisory authority within 72 hours where the breach is likely to result in a risk to your rights, in accordance with GDPR Article 33
- Where the breach is likely to result in a high risk to your rights, we will notify you without undue delay, in accordance with GDPR Article 34
- For California residents, we will provide notification as required by Cal. Civ. Code Section 1798.82
- We will document all breaches and our response measures
8. Cookies and Tracking
8.1 Essential Cookies
Always active. Required for Service operation:
- Authentication cookies: Session management and login state (Duration: session)
- Security cookies: CSRF protection and security tokens (Duration: session)
- Consent storage: Your cookie preferences stored in localStorage (
motif_cookie_consent,motif_cookie_preferences)
8.2 Analytics Cookies
Opt-in. Only placed after you consent via the onboarding consent modal.
- Google Analytics: Cookie names:
_ga,_gid(Duration: up to 2 years; Provider: Google LLC, USA)
8.3 Marketing Cookies
Opt-in. Only placed after you consent via the onboarding consent modal.
- Meta/Facebook Pixel: Advertising effectiveness measurement (Provider: Meta Platforms Inc., USA)
8.4 Preference Cookies
Opt-in. Used to remember your settings:
- Theme and language preferences stored in localStorage
8.5 Managing Cookies
- Consent modal presented during onboarding with "Accept All" (enables analytics and marketing) or essential-only options
- You can update your cookie preferences at any time via Cookie Preferences in your dashboard settings
- Non-essential cookies are not placed until you affirmatively consent
- The Service functions fully with essential cookies only
Our marketing website (motif.bio) uses additional cookie categories including Yandex.Metrika, Google Tag Manager, and HubSpot, which are governed by the separate cookie consent banner presented on that site. The categories used on this website are:
Strictly Necessary
Essential for operation. Cannot be disabled.
Authentication cookies: Session management and login state (Duration: session)
Security cookies: reCAPTCHA protection against automated attacks (Provider: Google LLC, USA; Duration: 6 months)
Cookie consent: Stores your cookie preferences: cookie-consent, cookie-preferences (Duration: 12 months)
Analytics
Help us understand usage to improve performance. Requires your consent.
Google Tag Manager: Centralized tag and consent management (Provider: Google LLC, USA)
Google Analytics: _ga, _gid (Duration: up to 2 years; Provider: Google LLC, USA)
Yandex.Metrika: Traffic analysis, user behavior tracking, heatmaps: _ym_uid, _ym_d, _ym_isad, _ym_visorc (Duration: up to 2 years; Provider: Yandex LLC, Russia)
Performance
Optimize loading times and user experience. Requires your consent.
Google Fonts: Font optimization and caching (Duration: 1 year; Provider: Google LLC, USA)
Marketing
Only placed after explicit consent. Requires your consent.
HubSpot: Visitor tracking and form analytics (Provider: HubSpot Inc., USA)
Meta Pixel: Advertising effectiveness measurement (Provider: Meta Platforms Inc., USA)
Managing cookies on this website
- Cookie consent banner presented on first visit
- Use the Cookie Settings link in the footer to change preferences anytime
- Browser settings: Most browsers allow you to control cookies through their settings
- Direct opt-out mechanisms offered by analytics providers
Non-essential cookies are not placed until you affirmatively consent. This website functions fully with only essential cookies.
9. International Data Transfers
9.1 Data Location
Your data may be processed in:
- United States (primary)
- European Union (for EU users when available)
- Other jurisdictions where our AI processing sub-processors operate, subject to the transfer safeguards described in Section 9.2
9.2 Transfer Safeguards
For international transfers, we use:
- Standard Contractual Clauses
- Data Processing Agreements
- Appropriate security measures
10. Children's Privacy
The Service is not intended for users under 18 years of age. We do not knowingly collect personal information from children. If we learn we have collected data from a child, we will delete it promptly.
11. Changes to This Policy
We may update this Privacy Policy periodically. When we make material changes, we will post the updated policy on our website and update the "Effective Date" at the top. Continued use after the effective date constitutes acceptance of the updated policy.
12. Contact Us
The data controller is Motif Bio, Inc., a Delaware corporation.
For privacy-related questions or requests:
| Purpose | Contact |
|---|---|
| Privacy requests | hello@motif.bio |
| Data protection inquiries | hello@motif.bio |
| General support | hello@motif.bio |
13. Data Protection Officer
For GDPR-related matters, you may contact our Data Protection Officer at hello@motif.bio.
Last Updated: August 25, 2026