Legal
Privacy notice.
How Motekai handles personal data. Written plainly, because privacy notices that nobody can read aren't privacy notices.
This notice covers two quite different things, so it is in two parts. Part One is the website at motekai.ie and the consultancy — enquiries, outreach, and site analytics. Part Two is Motekai Retriever, the desktop app, which works completely differently and in which we receive almost nothing at all.
Last updated: 30 September 2026.
Who we are
The data controller is Motekai Limited, registered in Ireland under company number 814789, registered office 16 The Garden, Coach Road Meadows, Clane, Co. Kildare, W91 X4AE. The company is run by Mohammed Saidu, who is the person who will read your email.
Any privacy question or request goes to hello@motekai.ie. It is the only address we operate.
Part One — the website and the consultancy
The short version
- We process data on three lawful bases: to answer enquiries you send us, to reach out to potential business contacts in a regulated way, and to keep the website running.
- We don't sell data. We don't run advertising profiles. The site uses Cloudflare's cookieless analytics.
- You can ask us to delete what we hold at any time. One email to hello@motekai.ie.
- You can complain to the Irish Data Protection Commission if you don't like our answer.
1. When you contact us
The contact form on motekai.ie/contact collects your name, email address, optionally your company, the service area you're asking about, your message, and optionally timeline or budget notes. We use this to reply to your enquiry and, if it turns into work, to manage the engagement.
Submissions are routed via Cloudflare Turnstile (to filter bots) and delivered to our inbox through the Gmail API. We don't store form data anywhere other than the resulting email thread.
2. When we reach out to you
For business-to-business outreach we may hold limited public information about you: your name, current role and employer, public LinkedIn profile details, business email if you've published one, and references to public material you or your firm have written. We source this from public-domain channels only — LinkedIn public profiles, your firm's website, press coverage. We don't scrape behind authentication.
The purpose is to send a small number of targeted, relevant messages — never bulk marketing. If you tell us to stop, or ignore us, we don't persist.
3. When you visit the site
The site runs on Cloudflare Pages. Cloudflare collects request metadata for security and performance — IP address, browser fingerprint, requested URL — which is standard for any CDN and is processed under Cloudflare's own data-processing terms. We use Cloudflare Web Analytics, which is privacy-preserving and cookieless: it counts page views without tracking individuals across sites.
Clicking a download button for Motekai Retriever passes through a Cloudflare Worker that increments a counter and then redirects you to the installer. It counts downloads and the traffic source in the link, and does not identify you.
Lawful basis
- Contract / pre-contract (Art. 6(1)(b) GDPR) — for answering enquiries you send, delivering work you've engaged us for, and administering a Retriever licence you have bought.
- Legitimate interests (Art. 6(1)(f) GDPR) — for B2B outreach to professional contacts about services we believe are relevant to their role. We've weighed our commercial interest against your rights and concluded the processing is proportionate: public-domain data only, targeted not bulk, easy opt-out, no special-category data, no automated decision-making. You can object at any time and we'll stop.
- Legitimate interests (Art. 6(1)(f) GDPR) — for keeping the website secure and measuring aggregate usage via cookieless analytics.
- Legal obligation (Art. 6(1)(c) GDPR) — for keeping the accounting records Irish tax law requires us to keep.
Who else sees your data
We use a small set of third parties. Each is bound by data-processing terms and, where they act as our processor, processes data only on our instructions:
- Cloudflare, Inc. — hosting, CDN, DDoS protection, Turnstile bot filtering, cookieless analytics, and the download counter.
- Google LLC (Gmail API) — delivers contact-form submissions to our inbox; also hosts our business email.
- LinkedIn (Microsoft Corporation) — when we message you on LinkedIn, the message and your profile data are processed by LinkedIn under their own terms.
- Paddle — our merchant of record for Retriever purchases. Not our processor: an independent controller for the order. See Part Two.
We don't share your data with anyone for advertising, profiling, or resale.
International transfers
Cloudflare and Google are US-headquartered. Where data is transferred outside the EEA we rely on the EU-US Data Privacy Framework and, where applicable, Standard Contractual Clauses under Article 46 GDPR. The decision to use these processors reflects industry-standard tooling for a small studio; if that's a concern for your use case, get in touch and we'll work it through.
How long we keep it
- Contact-form submissions and the resulting email thread: retained for up to 24 months from last contact, then deleted unless the conversation has become an active engagement.
- Engagement records (proposals, invoices, deliverables): up to 7 years from project completion, as required by Irish tax and contract-law obligations.
- Outreach research: deleted within 6 months of last contact unless the conversation is live.
- Support email about a Retriever licence: up to 24 months from the last message, except where an accounting record has to be kept longer.
- Cloudflare and analytics logs: retention controlled by Cloudflare per their published policies.
Cookies and similar technology
The site uses essential cookies only. Cloudflare Turnstile may set a short-lived cookie when verifying that you're not a bot; this is essential to the security function and not used for tracking. Cloudflare Web Analytics is cookieless. We don't use Google Analytics, advertising pixels, or cross-site trackers.
Part Two — Motekai Retriever, the desktop app
Are we even a controller here?
Mostly, no. In its default configuration we do not receive, collect, store or have any means of reaching your personal data from the app, so for that processing there is nothing for us to control. Where we are a controller is narrow and specific: your purchase record (through our merchant of record) and any email you send us. Those are covered at the end of this part.
What stays on your computer
Everything the app creates lives in one per-user folder — %LOCALAPPDATA%\Motekai on Windows — so you can see it, back it up, or delete the lot. It holds:
- The search index built from your documents, including the extracted text of the passages it indexed. This is derived from your files and can be as sensitive as they are. It never leaves the folder.
- The AI engine and model files the app downloads on first run — several gigabytes of general-purpose model weights, nothing to do with you.
- Settings — which folder you picked, and your AI-provider choice. If you chose a cloud provider, this file also holds the API key you entered (see below).
- Licence and trial state — the date you first launched it, the last date it saw, a trial-progress timestamp, and your licence key if you have entered one.
- A rotating local log and, if the app has ever crashed, a crash log. Both are files on your disk. Neither is uploaded anywhere, ever.
- A cached copy of the public revocation list — the same file every install downloads, containing no information about you.
Your documents themselves are not copied into this folder and are not modified. The app reads them where they are and writes only its own index.
What leaves your computer, and when
In the default local configuration, exactly three kinds of network request happen, and all three are the app fetching files — none of them sends anything about you, your documents or your questions.
- On first run: downloading the AI engine and models. The Ollama runtime from GitHub and the reranking model from Hugging Face, each pinned to an exact version and checked against a published checksum; and the language and embedding models through Ollama's own registry, by model name (for example qwen2.5:7b), with Ollama checking every file it downloads against the registry's checksums. This is the one step that needs an internet connection; after it, the app works fully offline.
- Checking for an update. At most once each time you open the app, and no more than once an hour, the app fetches a small file describing the newest release from our release bucket. If there is a newer version it downloads the package from the same place. If the check fails it is silently ignored — it never blocks you and never nags.
- Fetching the licence revocation list. A small signed file from the same bucket, fetched in the same cycle as the update check. It is a plain download, not a licence check. The request carries no licence key, no serial number and no machine identifier; every installation in the world fetches the identical bytes, so the answer cannot single anyone out. Your key is checked against it on your own computer.
What those requests do reveal
We would rather say this than let "no telemetry" be read as "no packets". Any download tells the server serving it your IP address, roughly when you asked, and which file you asked for. That is true of these requests as it is of any download, and it applies to:
- GitHub and Hugging Face and the Ollama registry, for the first-run downloads;
- Cloudflare R2, which hosts our release bucket, for the update check, the update package and the revocation list.
Each of those companies handles that request data as its own controller, under its own policy. We do not receive it: our release bucket is a public file store and we do not read, retain or analyse its access logs to identify users. If you want none of it to happen at all, block the app in your firewall after first run — everything except updates keeps working, permanently and by design.
The optional cloud-AI mode — where things genuinely do leave
Everything above describes the default. The app also offers, as an explicit choice at first run, the option to use your own cloud AI account instead of the local model. This changes the privacy position materially and we are not going to bury it.
It is off by default. The setup screen asks you to choose, local is the default and the recommended option, and nothing switches it on for you. If you do choose it, you supply your own API key for your own account with Anthropic, OpenAI, Azure OpenAI, Google Gemini, AWS Bedrock, or an OpenAI-compatible endpoint of your own.
What is sent, in that mode:
- the text of your question;
- the passages retrieved from your own documents that the question matched — this is real content out of your files, not a summary or a reference to it;
- recent turns of the current conversation, so follow-up questions make sense.
That traffic goes directly from your computer to your chosen provider, using your key and billed to your account. It does not pass through us, and we never see it. What your provider then does with it — how long they keep it, whether they train on it, who can access it — is governed by the contract between you and them, not by this notice. Read their terms before you switch this on.
What still stays local, even in cloud mode: indexing, the embedding of your documents, and the reranking step all continue to run on your machine. Your document set is never uploaded in bulk. Only the passages a given question actually matched are sent, and only when you ask something.
The honest caveat to that: a passage is still your document's content. If a question matches a sensitive paragraph, that paragraph is sent. Over many questions, a meaningful amount of a document can end up having been transmitted, a piece at a time. If that is not acceptable for your material, use the local mode — which is why it is the default.
Your API key is stored in the settings file in the app-data folder described above, as ordinary text — not in the Windows Credential Manager. It is never sent to us and never appears in a log, but anything running under your Windows account can read that file, which is worth knowing before you put a production key into it. You can switch back to local mode at any time.
The free trial
The trial needs no account, no email address and no payment card, and nothing about it is transmitted to us. The 14 days are counted by a small file on your own computer recording when you first launched the app, when it last ran, and how far through the trial it has got. We do not know that you have downloaded the app, started a trial, or stopped using it. The only figure we see is an anonymous count of clicks on the download button.
Your licence key
A licence key contains four things, all of them inside its signed payload: a serial number, the date it was issued, the type of licence, and a format version.
It does not contain your name or your email address, and it contains no personal data of any kind. Our merchant of record maps the serial back to an order if we ever need to look one up. The key stays on your machine; it is not transmitted when the app checks for updates or fetches the revocation list.
Logs, crashes and diagnostics
The app keeps a rotating log on your disk, for your benefit when something goes wrong. It records what the app did and how long things took. It does not record the text of your questions by default. There is an operator setting that adds the first part of each question to the log for troubleshooting; it is off unless you turn it on, and even then the log stays on your machine.
If the app crashes it writes the technical details to a crash log on your disk and shows you where it is. Nothing is uploaded — not the crash, not a report, not a counter. If you want us to look at it, you send it to us.
If you want us to look at a problem, you can email us the log files yourself: they are in the logs folder inside the app-data folder described above. It is entirely your choice and nothing is sent automatically. Have a look before you send them: a log can mention the path to your documents folder and the filename of a document the app had trouble reading. Anything you do send us we keep only as long as it takes to sort the problem out.
Sharing an answer
The app can hand an answer to your email client or to WhatsApp if you press share. That is your own software sending your own message, and it only ever happens because you asked for it. Nothing goes through us. One thing to know about WhatsApp: it is reached through a web link (wa.me), so the question, the answer and the names and paths of the source files travel in that link to WhatsApp's servers, and can stay in your browser's history.
When you buy a licence
Checkout is handled by Paddle, our merchant of record. They are the seller of record and an independent controller of your purchase data, not our processor. They collect and hold your email address, your payment details, your billing country and any VAT number, under their own privacy policy, which you should read at checkout.
We never see your card details. What we can see, through their dashboard, is the order: the email address you bought with, the country, and what was purchased. We use it for exactly three things — sending you your key, re-sending it if you lose it, and handling a refund or a support question.
So what does Motekai actually receive?
Setting the whole thing out in one place:
- From the app: nothing. No account, no telemetry, no analytics, no crash upload, no usage data, no licence check. Not reduced, not anonymised — nothing.
- From a purchase:the order record in our merchant of record's dashboard — your email address, billing country and what you bought.
- From email: whatever you choose to send us, including any log files you send.
- From the website: cookieless analytics and an anonymous download counter, as in Part One.
This is not a design we are describing generously. It is the consequence of a product that runs on your machine and verifies its own licence offline, and it is checkable: the requests the app makes are the three listed above, and you can watch them on your own network.
Your rights
Under the GDPR you can ask us to:
- Confirm what data we hold about you and give you a copy.
- Correct anything that's wrong.
- Delete it.
- Restrict how we use it while we resolve a query.
- Object to processing carried out on legitimate interests.
- Port your data to another provider, where applicable.
- Withdraw consent, where we're relying on consent.
Send any of these to hello@motekai.ie. We'll respond within one calendar month — usually much sooner.
Two practical notes for Retriever users. For the data on your own computer, these rights have nothing to exercise against us: the files are yours, we cannot reach them, and deleting the app-data folder removes them. For your purchase record, we can act on what is in our merchant of record's dashboard, but because they are an independent controller you may also need to go to them for the parts they hold — tell us and we will point you at the right place rather than leave you to work it out.
How to complain
If you're not happy with how we've handled your data, you can complain to the Irish Data Protection Commission:
- dataprotection.ie
- 21 Fitzwilliam Square South, Dublin 2, D02 RD28, Ireland
- +353 (0) 761 104 800
We'd prefer you raised it with us first, but it's your call.
Changes to this notice
We'll update this page when our processing changes. The "last updated" date at the top tracks the current version. We won't materially weaken your rights without telling people who've had recent contact with us.
Part Two describes the behaviour of the current release. If a future version of the app changes what leaves your machine, this page changes in the same release — not afterwards.
Last updated · 30 September 2026
Motekai Limited · Registered in Ireland no. 814789 · Registered office 16 The Garden, Coach Road Meadows, Clane, Co. Kildare, W91 X4AE