Legal

Privacy Policy

What the BountEx Motion license server stores, what it deliberately does not, and how to make us delete it. The licence covers 3 devices by default, and the data we hold exists to make that work — nothing else.

Last updated: · Operated by BountEx Labs, LLC

This is a template. It has not been reviewed by counsel.

The text below was written by the people who build the product so that nothing about the subscription is hidden, but it is a working draft, not a lawyer-reviewed agreement. Before it is relied on as final it must be reviewed and adapted by qualified counsel in the jurisdiction BountEx Labs, LLC operates from — including the governing-law clause, which is a placeholder. Questions, or a correction you think we owe you: Telegram @bountexlabs.

1. The short version

BountEx Motion is a licence server with a tool attached to it, so we collect what a licence needs: a fingerprint of your key, an opaque device id, when each device was last seen, and whether your subscription is currently paid.

We do not collect your work. Your briefs, prompts, storyboards, ledgers, assets, and renders stay on your machine — the workflow is built to run there, and the only things that cross the network are licence checks and phase fetches.

2. What we collect, and why

The list below is what the license server actually stores today. We keep it deliberately small, and we would rather add a paragraph here than add a tracking script.

A fingerprint of your license key
Your key is turned into an HMAC-SHA256 hash, keyed by a server-side secret, and that hash is what the database stores. The key itself is never stored in plaintext, so a database leak cannot be turned into working licences.
A device id, derived not harvested
The id is a hash of your machine’s hostname and platform plus a random salt generated on that machine and kept in your local config. We do not collect hardware serials, MAC addresses, disk identifiers, or any other hardware fingerprint — and the salt means the same hostname on two machines produces two different ids.
A device label and some technical fields
The device name shown in your device list (usually "hostname (platform arch)"), the platform, the version of the tool that activated, and the AI coding tool you installed into, when the tool reports it.
Timestamps
When a device was first seen and when it was last seen, when a seat was claimed or released, and when a licence was created or changed status.
Install and fetch counts
Which kit version was downloaded for which tool, and a count of licensed phase fetches. The fetch log records the phase id and the time — and nothing else. It never records the content of a phase.
Rate-limit counters
Activation attempts are counted per client IP address for a short window so a script cannot brute-force keys. These counters are operational and short-lived.
Billing status, not billing details
Card numbers, bank details, and your billing address are held by the payment provider, not by us. We receive a customer reference and the subscription facts we need to run the licence: plan, status, current period end, and whether a payment failed or was refunded.

3. What we do not collect

This list matters more than the one above, so it is just as specific.

  • The content of your video projects: briefs, production prompts, storyboards, critic ledgers, quality reports, and review notes.
  • Your source files, media assets, references, renders, or audio.
  • The text of your conversations with the AI tool you run the workflow inside.
  • The body of any licensed phase you fetch. The server knows which phase and when; it does not keep what it sent.
  • Your website’s content, analytics, or customer data, even when you point the workflow at your site.

4. How the licensed fetch is logged

When your agent loads a phase, the request carries a device token, the kit id, and the phase id. The server checks entitlement, returns the Markdown body with cache headers that forbid caching, and records the phase id, the device, and the time for rate limiting and support.

The body is never written to the database, never written to a log, and never cached on disk. That is not only a licensing choice: it means a fetch is not a copy of your work sitting on our side.

5. Why we are allowed to hold it

PURPOSE AND LAWFUL BASIS — PLACEHOLDER: we process this data to perform our contract with you (running the licence you paid for), for our legitimate interests (preventing key sharing and abuse, keeping the service working, and supporting subscribers), and to meet legal obligations such as tax and accounting records. Counsel should confirm this wording, and the international-transfer mechanism used for any processing outside your region, before launch.

6. How long we keep it

Licence and device records are kept while the licence exists and for up to twelve months afterwards, so a reactivation, a refund, or an audit can be answered. Billing records are kept for as long as tax law requires. Rate-limit counters expire within hours. Support conversations are kept for as long as they are useful, and you can ask us to delete one.

These periods are a working draft: counsel should confirm them against the retention obligations that apply to the operating jurisdiction.

7. Your choices and rights

Ask us for a copy of what we hold about your licence, ask us to correct it, or ask us to delete it: Telegram @bountexlabs. Deleting licence records ends the licence, because the record is the licence — we will tell you that before doing it.

You can free a device seat yourself at any time, which stops that machine being tracked as active. In the dashboard you can also clear the local device salt, which makes this browser a new device the next time it activates.

Depending on where you live you may have additional rights — access, correction, deletion, restriction, portability, and objection — and the right to complain to your data-protection authority. We will not treat a request as an inconvenience.

8. Cookies and browser storage

This website sets no cookies of its own and runs no advertising trackers. The dashboard keeps a random device salt in your browser’s localStorage so the same browser is the same device, and it stores your licence key there only if you tick "remember on this device" — untick it and the key stays in memory for that tab only.

The dashboard talks to the licence API directly from your browser. Your key is never sent to the server that renders these pages.

9. Who else touches the data

PLACEHOLDER: the payment provider that processes subscriptions, the hosting provider that runs the licence server, and any email provider used for receipts and notices are processors acting on our instructions. Counsel should insert the named providers, their locations, and the transfer mechanism before launch.

We do not sell personal data, and we do not share it for advertising.

10. Security

Traffic to the licence API is encrypted in transit. Keys and device tokens are stored only as keyed hashes. Device tokens are scoped to one licence and one device, expire after thirty days, and stop working the moment a seat is released or a licence is revoked. The credential file the CLI writes on your machine is created with 0600 permissions.

No system is perfect. If we ever suffer a breach that affects your data, we will tell you and the relevant authority as the law requires.

11. Children

The service is a professional tool and is not intended for children. We do not knowingly collect data from anyone under 16.

12. Changes to this policy

If we start collecting something new, this page changes and the date at the top changes with it. For a material change we will give notice by email to the address on your subscription before it takes effect.

13. Contact

Privacy questions, access requests, and deletion requests: Telegram @bountexlabs. BountEx Motion is operated by BountEx Labs, LLC.