Skip to content

Draft, pending legal review. This page describes how the product works today. It has not been reviewed by a lawyer and it is not a final agreement.

Legal

Privacy

Draft last edited October 9, 2026.

This page describes what Motion collects, where it goes and what you can ask us to remove. It is written to match how the product works today.

01What this page covers

Motion is a B2B outreach product operated by SuperScraper. This page covers the Motion website and app. It describes three kinds of data: your account, the work you do in the product, and the company information the product gathers to build lists.

02Your account

You sign up with an email address and a password, or with a Google account. Sign-in is handled by our authentication provider, which stores your credentials. We store your email address, a workspace id, and an API key for your workspace. That API key is encrypted before it is stored.

03Cookies and browser storage

The app sets a sign-in cookie. It holds your session, it is marked so page scripts cannot read it, and it is set to expire after an hour at most. The sign-in library also keeps your session in your browser storage so you stay signed in.

The app keeps a few preferences in your browser storage: your light or dark theme, an unsaved campaign draft, recently opened items and saved table views. The site code includes no advertising pixel and no third-party tracking script.

04Product analytics and error reports

We record six product events on our server and send them to an analytics provider: sign-up, workspace created, campaign created, campaign sent, reply sent and deal marked won. Each event carries an identifier, which is your account email or the first characters of your workspace key, plus an id such as the campaign id. A won deal also carries its amount, rounded to the nearest hundred dollars. The app does not put the email addresses of your leads or the text of your messages in these events.

Our API can send error reports to an error tracking provider. It is set up to strip secrets and personal fields from a report before sending it.

05What you put into the product

Motion stores the work you do so the product can run. That includes:

  • Lists and the contacts in them, whether you import a CSV, import from a connected CRM, or build the list in the product. A contact can include a name, email address, company, domain and phone number.
  • Campaigns, sequence steps, drafts, and the research facts a draft is based on.
  • A record of each send, the replies and delivery events your sending account reports back, and the labels you put on them.
  • Deals, meetings, and revenue amounts you record or connect.
  • Your suppression list.

Each of these records is stored against your workspace. The API is built to read and write them only for the workspace that is signed in.

06Keys you connect

You can connect your own keys for a sending account, model providers, contact and verification providers, a CRM and a calendar. Keys are encrypted with AES-256-GCM before they are stored. The app does not show a stored key again in full. It shows that a key is connected and, when you save one, its last four characters.

07Who else receives data

Motion runs on third-party hosting, database and authentication services, and everything described on this page is stored or processed there. Beyond that, these providers receive data when you use the feature named:

  • Your sending account receives the contacts you enroll, the message text and the unsubscribe link. It sends the email and reports replies and delivery events back. This uses your own key.
  • An email verification provider receives the email addresses you ask to verify, and may receive an address again when it is checked at send time. Verifying a list uses your own key.
  • Contact data providers receive a company domain and a person name when you ask the product to find a contact. This uses your own key.
  • A web search provider receives the search terms from a brief, such as an industry and a place. This uses our key. Search results are used to find company websites and are not stored.
  • Model providers receive prompts that contain company facts and draft text when the product researches, writes or checks a message. This uses your key if you connected one and our key if you did not.
  • Reply sorting may send the text of a reply to a model provider on our key when keyword rules do not settle it.
  • A CRM or calendar you connect is read with the token you supply.

We have not yet published a named list of these providers. Ask us and we will tell you which ones apply to your workspace.

08What is shared between customers

Your lists, campaigns, drafts, replies, deals, revenue records, keys and suppression list are not shared with other customers.

SuperScraper keeps a set of business records that describe companies and come from public sources. That set is shared across its products, and parts of this product can read it. The code that would write your campaign outcomes into that shared set is switched off today. If that changes, this page will say so before it does.

We do not use your leads, messages or replies to train models. The product has no model training code. What a model provider does with the prompts it receives is set by that provider and its terms.

09Unsubscribes and suppression

The product adds an unsubscribe link to the footer of each campaign step, and it refuses to launch a campaign when the link is not set up. The link opens a page with one button. When a recipient confirms, the address is written to your suppression list in the same request.

A clear opt-out reply adds the address too, and so does a hard bounce or a spam complaint that your sending account reports back. An unsubscribe or complaint also suppresses the company domain, unless it is a shared mailbox domain such as a free webmail service. A reply that might be an opt-out but is not clear is put in front of you to decide.

Suppression is checked when a contact is enrolled and again before a campaign starts. If the check cannot run, the send is refused. Suppression entries have no expiry, and the app has no control for removing one.

10How long we keep data

We keep your account and your workspace data while your account is open. We have not yet set fixed retention periods for lists, campaigns, replies and logs, so we do not state any here. A stored email verification result is accepted for 30 days when a campaign is checked for launch. A session cookie lasts up to one hour.

11Deleting your account or getting a copy of your data

Motion does not yet have a button to delete your account or export your data. Until it does, email privacy@superscraper.dev from your account address and we will handle the request by hand. We plan to keep suppression entries when an account is deleted, so people who opted out stay opted out.

12If your business or your name is in our records

You may be reading this because you received an email sent through the product, or because your business appears in a list. To stop email from a sender, use the unsubscribe link in the message. It applies to the sender who emailed you, not to every customer.

To have a person removed from our business records, email privacy@superscraper.dev. An operator marks the record removed. From then on it is left out of what the product reads, and it is scheduled for permanent deletion 30 days later. You can also ask us to mark a business as do not contact.

13Security

The site tells browsers to use HTTPS only. Stored keys are encrypted as described above. The tables that hold workspace data have row-level security switched on with no public access rule, and the API is built to scope reads and writes to the signed-in workspace. An automated two-workspace test suite covers that separation.

We hold no security certification and do not claim one. To report a vulnerability, email security@superscraper.dev.

14Contact

Privacy requests and questions: privacy@superscraper.dev. General support: support@superscraper.dev.