Privacy

Browsing Motari needs no account and sets no cookies. This page lists everything the site collects, why, and how long it is kept, as the code that runs it does it.

Analytics

motari.io counts page views with Umami, an open-source analytics tool, loaded from an Umami server run for Motari (analytics-01.2n6.io). It sets no cookies and does not store your IP address. It records the page you view, the page that referred you, and your browser, operating system, device type, screen size, language and country. Motari uses it to see which pages people use. The analytics script only runs on motari.io itself.

Pages load no other third-party scripts or trackers, and the site's fonts are served by Motari.

Signing in with GitHub

You only sign in to maintain a robot page, add a robot or report a build. Sign-in goes through GitHub, which asks you to approve access to your public profile (and, to claim a robot owned by an organization, your organization memberships). GitHub handles your login under its own privacy statement.

  • Motari reads your GitHub account id, username, display name and avatar URL. The access token GitHub returns is used once, to read your profile and, for a claim, your permission on the repository, and is then discarded; it is never stored.
  • Your session is a signed cookie, motari_session, holding that id, username, display name and avatar URL. It is HttpOnly and expires 7 days after it was issued or last renewed; it renews once a day while you use the site. Signing out deletes it.
  • While a sign-in is in progress, short-lived cookies (motari_oauth_state, motari_oauth_return_to, motari_oauth_claim) protect the round trip to GitHub. They expire after 10 minutes.
  • If you call the API with a GitHub token, Motari checks it with GitHub and keeps the result in memory for up to 5 minutes, keyed by a hash of the token. The token is not stored.

What is stored with your GitHub identity

  • Claims. When you claim a robot: your GitHub account id and username, the robot, the claim's status and when it was made. A claimed page shows that a maintainer claimed it.
  • Build reports. When you report that you built a robot: your GitHub account id and username, the evidence link and commit you give, and the review status and dates. An approved report shows your username on the robot page.
  • Robots you add. A repository you add on the site becomes a public catalog page; your account is not stored with it. A repository you push through the API or the command-line tool is recorded with you as its maintainer, as a claim.

These records are kept while the page they belong to exists. Ask for their removal with the form below.

Opt-out and correction requests

The request form stores what you enter: the page or repository, whether you want it removed or corrected, your email address, an optional GitHub username and your message, with the time it was sent. Motari uses them only to act on the request and reply to you. The code does not delete requests automatically yet; ask in a request if you want yours deleted once it is handled.

Server logs

The web server keeps no access log of your requests. When something fails, the application writes an error report (what failed and where, never your cookies or IP address) to the server's system log, which keeps entries for up to 30 days; if error tracking with Sentry is configured, the same report is sent to Sentry. To limit abuse, the server counts requests per IP address in memory for windows of a few minutes; those counters are never written to disk and reset when the server restarts.

Your data, and questions

To ask what Motari holds about you, or to have it corrected or deleted, send a request through the request form with the email address or GitHub username it concerns. The site's operator will publish its legal entity and contact details on the About page.

Last updated 2026-09-30. This page changes when the site's data practices change.