If you actively enable Help improve Motiv, Motiv uses PostHog to receive pseudonymous, event-level usage information. “Pseudonymous” does not mean anonymous: a randomly generated identifier allows events from the same installation to be understood together.
The permitted events describe app launches, onboarding and permission outcomes, feature types and status changes, counts and durations, completion actions, Focus milestones, and limited paywall or membership outcomes. Some block lifecycle and bypass events include a one-way hashed reference so events about the same block profile can be grouped; this is not the block name or its content. Daily-task and Plan Ahead events may include a local calendar date. If you start a routine from one of Motiv’s built-in starter templates, the event records which template it was; this identifier is written by us and is never your own wording, and health-related templates are recorded only as a redacted value.
The PostHog code library inside the app also adds limited technical context to every event:
- the app’s name, version, build, and identifier;
- the operating-system name and version;
- the device manufacturer, model and type, and the screen dimensions;
- the library’s own name and version;
- your language, time zone, and connection type;
- whether the app is running on a Mac, and whether the build came from TestFlight, was sideloaded, or is running in a simulator;
- a rotating session identifier, so the events from a single session can be read together; and
- two flags recording that this installation is not linked to a person profile.
One of these fields is called “device name”, which sounds more revealing than it is: on iPhone and iPad it is the model class — the word “iPhone” or “iPad” — rather than the name you gave your device.
When the SDK starts it also requests its configuration from PostHog. PostHog necessarily observes network metadata, including the connection’s source IP address, while accepting that configuration request or an event.
Events do not include titles, notes, place names, saved coordinates, selected app or website names, payment-card details, or Apple transaction identifiers. PostHog person profiles, surveys, session recording, automatic screen, element and application-lifecycle capture, rage-click capture, automatic error capture, SDK logs, automatic feature-flag loading and feature-flag events, and server-side GeoIP enrichment are disabled. An app allowlist rejects every PostHog event name that Motiv has not reviewed.
Each analytics event also carries the consent-notice version and the date of the relevant grant, reduced to a UTC calendar day. These two fields let us relate retained events to the consent under which they were collected. Motiv does not send the full local consent history, the exact time of the decision, the decision surface, or the Privacy Policy version to PostHog.
Our lawful basis is your consent. Analytics remains off until you make an affirmative choice in the app, and the choice is offered only if you have declared you are 18 or over — see Intended audience and younger users. While analytics is off, analytics events are dropped rather than stored for later delivery. If you later enable analytics, only events created after that choice are eligible to be sent.
You may withdraw consent at any time under Settings → Privacy. This stops the PostHog SDK and deletes its unsent on-device queues and locally stored PostHog identifiers. A durable local deletion marker makes a later opt-in repeat that purge before PostHog can restart, and the exact time of the current grant is checked locally so an older app outbox or SDK record cannot be sent under a later grant. That exact time is not sent to PostHog.
While analytics is on, Settings → Your consent record shows the pseudonymous PostHog identifier your events are stored under, with a control to copy it. It is generated by the PostHog software, not by us, and it is not the installation identifier shown against your consent decisions — PostHog has never seen that one. Send us the analytics identifier and we can find, export, or delete the records it belongs to.
We do not keep a link between that identifier and your identity, and it changes whenever you reset Motiv or turn sharing off and on again. So if you ask after it has changed, we may be unable to identify the earlier records as yours. You may still contact us with any information available to you; we will make reasonable efforts without collecting extra identifying information merely to create a link that did not previously exist.
The production PostHog project uses PostHog Cloud EU in Frankfurt. PostHog’s current free plan guarantees at least one year of data retention and does not let us set a shorter period, so we cannot promise that analytics data is deleted at twelve months. We ask PostHog to delete records on request where you give us the identifier.