Privacy Policy

Last updated: October 7, 2026

Highlights are provided for readability. The full Privacy Policy text controls.

What we collect

  • Account information: email address, name, profile image, sign-in provider, and account settings. If you sign in with a third-party provider such as Google or Discord, we receive the profile details that provider shares, which can include an account identifier, username or display name, and avatar. Some older accounts may not have an email address.
  • Generation and job data: prompts, animation settings, character type, motion mode, target rig, trim selection, duration, job IDs, statuses, errors, generated files, previews, history, and library items.
  • Uploaded source files and user materials: Video-to-Motion source videos, Speech-to-Motion audio, avatars, reference images, titles, descriptions, tags, and other content you choose to submit. These materials may include a person's face, body, likeness, voice, movement, surroundings, or other identifying details.
  • Records from retired community features: motions shared through Explore, motion packs, download and purchase records, reports, moderation details, and related metadata from before these features were retired. We keep these records to preserve copies other users already obtained, handle support and disputes, and meet legal obligations.
  • Billing records: Polar customer, subscription, checkout, order, refund, and credit information. We do not store full payment card numbers.
  • Connected app data: when you connect the NoCapMocap plugin for Roblox Studio to your account, we collect device pairing codes (stored hashed), device_name, user_agent, client_ip_hash (hashed IP), token_hash and scopes for scoped access tokens (stored hashed), and timestamp fields for creation (created_at), authorization (authorized_at), polling (last_polled_at), usage (last_used_at), and revocation (revoked_at).
  • AI agent connections: when you create an agent connection in Settings, we store its name, scopes, credit allowance and the credits it has used, its expiry date, the name of the agent app it reports, a hash of its token (never the token itself), and when it was last used.
  • Roblox upload access: when you let Motion Lab upload animations to Roblox, we store your Roblox user ID, the permissions you granted, and Roblox's access and refresh tokens, encrypted. We use them only to upload the animations you choose. You can disconnect in Settings at any time. This revokes the access and deletes the tokens.
  • Generate assistant: your assistant chats stay in your browser on this device. We do not store them on our servers. To answer, we send your messages and details of your current generation setup to an AI provider. To enforce usage limits, we keep a daily count of assistant replies and their cost under a hashed identifier.
  • Usage and security data: logs, IP address, device and browser information, rate-limit signals, analytics events, performance data, and error data.
  • Communications: support requests, privacy requests, copyright reports, Discord-related contact, and other messages you send us.

How we use your data

  • To process uploaded videos and other source files, create generated animations, previews, thumbnails, history, and library items.
  • To authenticate accounts, provide customer support, and send service messages.
  • To process subscriptions, credit purchases, refunds, chargebacks, and billing records.
  • To prevent fraud, enforce rate limits, secure the service, debug errors, and maintain reliability.
  • To improve product quality, generation workflows, performance, and user experience.
  • To comply with legal obligations and respond to lawful requests or disputes.

AI processing

To provide generation and helper features, we may send prompts, settings, uploaded source files, generated files, and reference images to third-party infrastructure and AI providers. These providers process the data needed to return the requested result, apply abuse-prevention controls, and operate their services under their applicable terms and policies.

Third-party services

We use service providers to run NoCapMocap, including providers for:

  • Database, authentication, account management, and account deletion.
  • Hosting, analytics, deployment, performance monitoring, security, network infrastructure, and internal team messaging for support requests and payment alerts.
  • Private object storage, asset delivery, and generated media processing.
  • AI generation, prompt helper features, and related processing.
  • Checkout, subscription management, customer portal, refunds, and payment records.
  • OAuth sign-in when you choose a third-party sign-in method, such as Google or Discord.
  • Roblox OAuth when you choose to connect a Roblox account to your existing NoCapMocap account. We receive and store your Roblox user ID, username, display name, and avatar to identify that connection. Connecting Roblox does not enable Roblox sign-in and is separate from pairing the Roblox Studio plugin.

Outplace gifts

If you choose to redeem an Outplace gift, we exchange account-linked gift identifiers, eligibility, claim, and placement information with Outplace to complete that request. We keep gift funding and claim records to preserve accepted placements, prevent duplicate redemption, and enforce the campaign cap. Those records can remain after account deletion and may still be linked to payment or gift identifiers. Contact us about these records when making a privacy request; deleting your NoCapMocap account does not itself remove an accepted placement on Outplace.

Roblox Studio plugin

The NoCapMocap plugin for Roblox Studio connects to your account using a one-time pairing code that you approve on our site after signing in with Google, Discord, or email. Once connected, the plugin uses a scoped access token to act on your behalf, including listing your library, starting generations, uploading source videos you choose to submit from Studio, and importing animations. Plugin requests are processed the same way as the equivalent actions on our website. You can review and revoke active Studio connections at any time from dashboard settings, and tokens expire automatically.

Uploaded videos and source files

When you use Video-to-Motion or related features, uploaded videos and source files are private by default. Other users can view a source video only if a feature explicitly says that the source file itself will be shared or published and you choose to use that feature. We process uploaded source files to provide the service, generate motion data and animation outputs, preview results, support downloads, troubleshoot issues, prevent abuse or fraud, enforce our Terms, and comply with legal obligations.

Our team does not review private uploaded videos except where reasonably necessary to provide support, debug a user-reported issue, investigate abuse, enforce our Terms, protect the service, or comply with law.

Your generated content

As between you and NoCapMocap, we do not claim ownership of your prompts, uploads, source videos, generated animations, or saved library items. Your content is private to your account by default. Explore, community sharing, and motion packs are no longer offered. Copies of shared motions or packs that other users obtained before these features were retired stay in those users' Libraries.

Data retention

Generated motions in History are kept for 7-90 days depending on your plan. Items saved to your Library are kept while your account is active. Generated motion files, previews, thumbnails, exports, and related metadata may remain available in your account history or library until you delete them, delete your account, or we remove them under our Terms.

Video-to-Motion source videos and diagnostic video copies expire 30 days after a generation completes or fails and are scheduled for deletion. The source-video comparison then becomes unavailable; saving an animation to your Library does not extend source-video retention. Saved animation outputs remain available under the Library retention rules above. Uploads that are not attached to a generation normally expire within two hours. Other source files, including Speech-to-Motion audio, follow the retention of their associated generation or saved Library item.

We may retain relevant source files, logs, and records for longer where needed to resolve an active dispute, legal request, safety issue, fraud investigation, billing issue, policy violation, or security incident. When uploaded source files are no longer reasonably needed for these purposes, we delete or de-identify them according to our operational deletion processes. Deletion from backups, logs, caches, or third-party processors may take additional time.

Deleting your data

You can delete your account from dashboard settings. Deleting your account cancels any active subscription immediately, with no refund for the remaining billing period. Polar, our merchant of record, retains its order and invoice records. You can also delete generations, history items, and library items through the product where deletion controls are available. To remove content you shared through retired community features, contact us. Deletion removes or starts removal of the relevant active-service records and associated stored files, subject to technical cleanup and backups. Some data may be retained where needed for billing, legal compliance, fraud prevention, security, dispute handling, or already-purchased community content. Copies of shared motions or packs that other users obtained before deletion stay in their Libraries.

Training and product improvement

We do not use your private uploaded source files, user materials, or generated outputs to train machine learning models without your explicit consent. We may use de-identified, aggregated, or technical information, such as processing duration, error rates, file format, generation status, and performance metrics, to improve reliability, safety, and product quality.

Cookies

We use essential cookies and similar storage for authentication, session management, security, preferences, and core product functionality. Optional analytics, including Vercel Analytics, Speed Insights, Google Analytics when configured, and campaign measurement, are enabled only after you accept analytics. You can reject analytics and still use the service. Open Privacy settings to change your choice or withdraw consent at any time. We remember your choice for up to 180 days in this browser, using local storage and, when needed to preserve a refusal, an essential preference cookie. Another browser or device may ask you again. If we materially change this notice, we will ask for your analytics choice again. We serve our own videos from our media storage on Cloudflare. A few pages also embed videos from third parties, such as YouTube. These load only after you click to play them, and the provider may then set its own cookies. We do not currently use third-party advertising cookies or sell personal information for cross-context behavioral advertising.

Your privacy choices

Depending on where you live, you may have rights to request access, correction, deletion, portability, restriction, objection, or information about how your personal data is handled. You may also ask us not to send non-essential messages. We may need to verify your identity before completing a request.

To make a request, email privacy@nocapmocap.com with the request you want to make and enough information to locate your account or the content concerned. You can also contact us about personal data in someone else's upload, even if you do not have an account. Do not send passwords, access tokens, or payment card details.

Where the GDPR applies, we respond without undue delay and normally within one month of receiving your request. If a permitted extension is needed because of the complexity or number of requests, we explain the reason within that month. Requests are normally free of charge. You may complain to a data protection authority, including in the country where you live or work or where you believe an infringement occurred. Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal.

Children

NoCapMocap is not intended for children under 13. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided personal information, contact us so we can review and delete it where appropriate.

Security and international transfers

We use technical and organizational safeguards designed to protect personal data, but no online service can be guaranteed completely secure. NoCapMocap and its service providers may process data in countries other than where you live, subject to applicable legal requirements.

Contact

Questions about privacy? Email us at privacy@nocapmocap.com