The short version
Motily asks you about your body, your habits, and your sex life so it can give you a picture of the lifestyle factors that may relate to male fertility. That is sensitive information, and this policy explains exactly what we collect, where it lives, who else touches it, and how you stay in control.
We do not sell your data, we do not run advertising, and we do not track you across other apps or websites. Two services help us keep the app working, a crash reporter and a usage counter, and both are described below along with everything else that touches your data. Neither ever receives your answers, scores, or report values, and the usage counter can be switched off in Profile, under Privacy and data.
Who is responsible for your data
Motily is built and run by Bosco Foulsham, a sole independent developer based in the United Kingdom. For the purposes of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, Bosco Foulsham is the data controller.
You can reach us about anything in this policy at bosco.foulsham@gmail.com.
What we collect
Account details. When you create an account we store the email address you sign up with. If you choose a password, it is hashed and held by our authentication provider, never stored in plain text. If you sign in with Apple, Apple sends us a sign-in token and, on your very first sign-in only, your name if you chose to share it. If you sign in with Google, Google sends us a token plus your name and a link to your Google profile photo, which we use to prefill your profile. You can optionally add a phone number and a profile photo in Profile, under Account and security.
Onboarding quiz answers. Your goals, first name, date of birth, height and weight (from which we calculate your BMI), and your answers about smoking, alcohol, exercise, sleep, diet, heat exposure, underwear, stress, water intake, and time spent sitting.
Intimate health answers. If you complete the intimate health questions in the Analysis tab, we store your answers about varicocele, undescended testicles, mumps, groin or testicular surgery, sexually transmitted infections, testosterone or steroid use, chemotherapy or radiotherapy, changes in libido or sexual function, family fertility history, and whether you have fathered a child before.
Daily check-ins. Each day you check in, we store your answers across eight categories: Sleep, Hydration, Intercourse, Nutrition, Exercise, Mood and Stress, Heat, and Substances (caffeine, alcohol, cigarettes, and recreational drugs). From these we calculate and store your daily score, your score history, your streak, and any badges or milestones you unlock.
Semen analysis reports. If you add a lab report, we store the date, the name you give it, and the values you enter (volume, concentration, total count, motility, and any optional measures such as morphology, pH, vitality, DNA fragmentation, or antisperm antibodies). If you attach the report itself as a PDF or photo, that file is stored in a private folder that only your account can read.
Apple Health data. Only if you tap Connect Apple Health in Profile, and only on iOS. Motily then reads your sleep and workout data for the current check-in day to prefill two questions. We save the resulting answer bucket (for example, seven to eight hours of sleep) and a note that it came from Apple Health. We do not store the underlying Health samples, and we never write anything back to Apple Health.
Community activity. When you first use Community we generate a pseudonym for you, such as Calm Heron 42, and all your posts and replies carry that handle rather than your name. We store your posts, replies, any photo you attach to a post, the posts you like and save, the users and topics you follow, and any reports you file about other content.
Settings and app state. Your reminder preferences and time, sound and haptics preferences, a list of the reminders the app has scheduled for you, your consent status and the time you gave it, and whether you have tapped Connect Apple Health.
Moderation records. If a Community post or reply you write is rejected by our automated screening (described under Who else touches your data, below), we keep a short excerpt of the text, up to 500 characters, whether it had an image attached, and the reason it was rejected. Rejected images themselves are not kept. This record is linked to your account but is not visible in the app.
Feedback. If you use Send feedback in Profile, we store the message you write, the screenshot you choose to attach (if any), the app version, and your phone's operating system version, linked to your account. Screenshots are kept in a private folder that only we can open. The text of your message, but never the screenshot, is also copied to our crash reporting service so we can see it alongside any errors your account hit.
Crash reports. If the app crashes or hits an error, a report is sent to our crash reporting service: what went wrong in the code, the app version, the phone model and operating system version, and your account id. Reports never include your answers, scores, report values, or anything you typed.
Usage events. So we can see which features are used and where people get stuck, the app records events such as "check-in completed", "paywall viewed", or "report added", with your account id. An event carries the name of the feature and yes/no flags only. It never contains an answer, a score, a report value, free text, or your email. You can switch this off in Profile, under Privacy and data; crash reports stay on because they are how we find and fix problems.
What we do not collect
No advertising SDKs, no ad identifiers, no location, no contacts, no device fingerprinting, and no tracking across other companies' apps or websites. Reminders are scheduled locally on your device, so we do not hold a push notification token for you. The camera and photo library are only accessed when you choose to add a photo or a screenshot, and only for that file.
A few small flags are kept on your device only, such as whether you have seen the Community guidelines, and the signed-in session that keeps you logged in. These never leave your phone.
Health data and your consent
Almost everything Motily stores about you is health data, and some of it concerns your sex life. Under UK GDPR this is special category data, which needs a specific legal basis. We process it on the basis of your explicit consent, which you give on the Privacy first screen when you first open the app. We record the date and time you gave it.
You can withdraw that consent at any time in Profile, under Privacy and data, using Withdraw consent. Because Motily cannot work without this data, withdrawing consent means deleting your account: the moment you confirm, your consent is recorded as withdrawn, and you are then asked to confirm the deletion. If you change your mind at that point, you will be asked to give consent again before you can carry on using Motily. Withdrawing consent does not affect the lawfulness of anything we did before you withdrew it.
A small amount of non-health data, such as your email address and your Community handle, is processed because it is necessary to provide the service you have signed up for, and to keep the app secure and the Community safe. Crash reports and usage events are processed on the basis of our legitimate interest in keeping Motily working and improving it; they contain no health data, and usage events can be switched off at any time in Profile, under Privacy and data.
How we use your data
To calculate your scores, insights, streaks, and suggestions, and to show them back to you. To sign you in and keep your account secure. To send the local reminders you have turned on. To run Community, including screening posts and handling reports. And to respond to you if you contact us.
Your scores are calculated automatically from what you tell us. They are informational only. Motily makes no decisions about you that have legal or similarly significant effects.
Where your data is stored
Your data is stored with Supabase, our backend provider, in its London region (AWS eu-west-2, United Kingdom). That covers your account, every answer and check-in, your Community activity, and your uploaded files.
Every table is protected by row-level security, so the database itself refuses to return your rows to anyone but you. Report files sit in a private bucket that only your account can read. Profile photos and Community post photos are stored in public buckets, which means anyone with the exact link can view them, so please do not attach anything you would not want seen.
All traffic between the app and our servers is encrypted in transit. No system is perfectly secure, and we cannot promise otherwise, but we have designed Motily so that the client never holds administrative access to the database.
Who else touches your data
Supabase (Supabase Inc.) hosts our database, authentication, file storage, and the two server-side functions that delete accounts and screen Community posts. Supabase acts as our processor and stores your data in the UK, as described above.
OpenAI (OpenAI, L.L.C.). Every Community post and reply is sent to the OpenAI Moderation API before it is published, along with any photo attached to the post. OpenAI returns a single flagged or not flagged result. Nothing else about you is sent: no name, no email, no handle, no health answers. OpenAI is based in the United States, so this is an international transfer, covered by the data protection terms in OpenAI's service agreement. OpenAI states that content sent to its API is not used to train its models.
Sentry (Functional Software, Inc.) receives crash and error reports, and the text of any feedback you send, as described under What we collect. We use Sentry's European Union data region, so these reports are stored in the EU. Sentry acts as our processor. It never receives your answers, scores, report values, or screenshots.
PostHog (PostHog, Inc.) receives usage events, as described under What we collect, on its European Union cloud, so they are stored in the EU. PostHog acts as our processor. It never receives your answers, scores, report values, free text, or your email address, and you can switch these events off in Profile, under Privacy and data.
Apple (Apple Inc.) if you use Sign in with Apple, and for Apple Health, which is read on your device and never sent to Apple by us. Google (Google LLC) if you use Google Sign-In. In each case, the provider's own privacy policy governs what it does with your sign-in.
Retailers linked from the Shop tab. Tapping a product opens the retailer's website in an in-app browser. We do not send them anything about you, but once you are on their site, their privacy policy applies. See the Terms of Use for how Shop links work.
We do not share your data with anyone else, and we will not do so without updating this policy first. We would disclose data only if legally required to, for example by a court order.
Community and pseudonyms
Other people in Community see only your generated handle, your posts, replies, and any photos you attach. They never see your name, email, profile photo, or any of your health answers. Your handle is stored alongside your account so that we, and our database, can tell which posts are yours. It is not shared or matched with anyone outside Motily.
Please remember that anything you write in a post or reply is visible to every other Motily user, so the safest approach is not to include details that could identify you.
How long we keep it
We keep your data for as long as your account exists. We do not currently delete accounts for inactivity. You can delete an individual Community post or reply at any time from the post itself, which also removes its photo.
When you delete your account, everything tied to it is removed: your account and login, quiz and intimate health answers, every daily check-in and score, streaks, badges, settings, semen analysis entries and their uploaded files, your profile photo, your Community handle, posts, replies, post photos, likes, saves, follows, reports you filed, moderation records, and any feedback and screenshots you sent. Deletion is immediate and cannot be undone. Supabase's routine backups may hold a copy for a short period before they expire.
Three things can outlast deletion. Reports that other people filed about your content stay in our moderation records, but they no longer contain anything that links to you. Crash reports and usage events already sent to Sentry and PostHog expire on their own retention schedules (90 days for crash reports) and are tied only to an account id that no longer exists. And if you have exported a PDF health summary from the Analysis tab, that file lives wherever you saved or sent it, outside Motily.
Your rights
Under UK GDPR you can ask to see the data we hold about you, ask us to correct it, ask us to erase it, ask for a copy in a portable format, ask us to restrict or object to how we use it, and withdraw consent at any time. Most of your data is visible and editable directly in the app, and you can delete everything yourself in Profile, under Privacy and data (Delete my data), or with Delete account on the Profile screen. For anything else, email bosco.foulsham@gmail.com and we will respond within one month.
If you are unhappy with how we handle your data, you have the right to complain to the Information Commissioner's Office (ICO), the UK regulator, at ico.org.uk or on 0303 123 1113. We would appreciate the chance to help first, but you do not have to come to us before going to the ICO.
Age
Motily is for adults. You must be 18 or over to create an account. We check the date of birth you enter during onboarding, and if it shows you are under 18 we stop there, delete the account you had just created, and keep none of your answers. If an existing account's date of birth shows the person is under 18, we sign the account out and block access, then delete its data. If we learn by any other route that someone under 18 is using Motily, we will delete the account. If you believe someone under 18 is using Motily, please tell us at bosco.foulsham@gmail.com.
Changes to this policy
If we change how we handle your data, for example by adding a new sync source or a new third party, we will update this policy and change the date at the top. For changes that matter, we will tell you in the app and ask for your consent again before the change takes effect. The current version is always available in Profile, under Privacy and data.