Privacy policy

Your memories are yours. This explains how we keep it that way.

Most privacy policies exist to tell you how a company uses your data. This one is mostly about what we can't do: your photos, videos, and words are end-to-end encrypted, so we never see them in the first place. Here is exactly what that means, what little we do hold, and the rights you have over all of it.

Last updated: September 2026 Plain language, no dark patterns

1. The short version

  • Your posts — photos, videos, captions, comments, reactions — are end-to-end encrypted. We store them only as ciphertext and cannot read them.
  • We hold the minimum needed to run the service: your email and name, and unavoidable metadata (who is in a space, when things happen, how much media there is).
  • We show no ads, run no tracking or advertising cookies, and never sell or rent your data.
  • Nothing you write is ever used to train AI. Translation runs on your device wherever possible; cloud AI translation is opt-in and explained below.
  • You can export everything and delete your account at any time.

The rest of this document is the detail behind those five points. For a closer look at how the encryption protects you, see our security whitepaper.

2. Who we are

Moments ("Moments", "we", "us") provides the Moments app — a private, end-to-end-encrypted journal for families to document a child's life. This policy covers the Moments mobile and desktop apps and this website. We are the data controller for the personal data described here.

3. What we cannot see

This is the heart of the policy. Everything you post is encrypted on your device with keys that exist only on your family's devices. Our servers receive and store ciphertext and wrapped (encrypted) keys — never anything they can decrypt.

Because of this design, we have no ability to:

  • view your photos, videos, captions, comments, or reactions;
  • read your child's name or birth date (both encrypted);
  • hand your content to anyone — an employee, an attacker, or an authority with a valid order — because we hold no key that opens it.

A complete breach of our systems would expose the metadata in section 4, and zero content. This is a property of the architecture, not a promise we ask you to take on faith.

4. What we collect

Account information

When you sign up we store your email address and the name you choose. We use passwordless sign-in, so we hold no password for you — there is nothing to leak in a breach.

Your content (as ciphertext)

We store your encrypted posts and media as opaque blobs, plus the encrypted keys that wrap them. We cannot read any of it (section 3).

Metadata we necessarily see

To deliver a shared, structured journal, some information is visible to our servers. We keep it to the minimum the service needs:

Metadata Why it's visible
Space membership & roles To deliver each post to the right members and enforce permissions
Timestamps & a post's event date To order the feed and power the age filter and timeline (the birth date needed to turn a date into an age stays encrypted)
Media type, size, and count To store and serve files and show the right placeholders
Whether a post is marked "Secure" The app must know before it decrypts anything; it reveals one bit and no content

Technical data

Like any online service, our servers process the IP address and basic device/app information attached to requests, and keep short-lived operational logs to run the service, prevent abuse, and diagnose problems. These logs do not contain your content.

5. How we use information

We use the limited data above only to:

  • authenticate you and keep you signed in;
  • deliver posts, comments, and reactions to the people you have chosen, and enforce your permissions;
  • send content-free push notifications (section 8);
  • relay opt-in translation requests (section 7);
  • keep the service secure, reliable, and free of abuse;
  • handle billing for paid plans, through a payment processor (we never see full card numbers);
  • respond to your support requests.

6. What we never do

  • We never show ads and run no advertising or analytics trackers on your content.
  • We never sell, rent, or trade your personal data.
  • We never use your content to train AI or build advertising profiles.
  • We never mine your photos for faces, objects, or locations — we can't; they're encrypted.
  • We keep no copy of your keys. There is no key escrow and no backdoor.

7. Translation & third-party AI

Moments can translate posts and comments into your language, and wherever possible this now happens entirely on your device: on Android, after a small one-time language download, the text is translated locally and never leaves the encrypted envelope — no third party involved.

Cloud AI translation remains for platforms without on-device support yet, and for the optional "Improve with AI" button. Because it needs to read the text, it is the one place where content deliberately leaves the encrypted envelope — so it is strictly opt-in and consent-based.

  • Nothing is sent to the cloud until you ask, and not before a consent dialog that explains this.
  • When you request a cloud AI translation, your device decrypts the text locally and relays it, over an encrypted connection through our servers, to a third-party AI translation service.
  • We do not log or store the text, and it is not used to train models.
  • Every result — on-device or cloud — is cached, encrypted, on your device only.

The honest trade: for the length of a cloud AI call, the text is readable in transit to us and to the AI provider. On-device translation removes this entirely — and if you never use cloud translation, your text never leaves the envelope. We are working on bringing on-device translation to more platforms.

8. Push notifications

Push notifications on Android and iOS go through Google's and Apple's push services, which is unavoidable on those platforms. Our notifications are content-free: a push says only that a member shared a new moment, commented or reacted in a space — the kind of event, the space's name and that member's display name, all information we already hold as metadata — and the app then fetches and decrypts the actual content through the normal, encrypted channels. A notification never carries your photos or text.

If you are in the European Economic Area or the UK, we rely on these legal bases under the GDPR:

  • Performance of a contract — to provide the account and core service you signed up for.
  • Consent — for optional features that carry a trade-off, such as translation; you can withdraw consent at any time.
  • Legitimate interests — to keep the service secure and prevent abuse, balanced against your rights.
  • Legal obligation — where we must retain limited records (for example, billing).

10. Who we share with

We do not sell your data and we share it only with the service providers needed to run Moments, each bound to process it only on our instructions:

  • Cloud hosting and storage — to store the encrypted blobs and run the API. They hold ciphertext they cannot read.
  • Push providers — Apple (APNs) and Google (FCM), for content-free notifications.
  • Email delivery — to send your sign-in links.
  • A third-party AI translation provider — only for text you explicitly ask to translate (section 7).
  • A payment processor — for paid plans; they handle card details, we do not store them.

We may also disclose limited information if legally required — but because your content is encrypted, what we can produce is metadata, never the content itself.

11. International transfers

Some of these providers may process data outside your country. Where personal data is transferred internationally, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses. Your encrypted content remains unreadable wherever it is stored.

12. Retention & deletion

We keep your account information and encrypted content for as long as your account is active. When you delete your account, we delete your personal data and your encrypted content from our active systems, and it falls out of backups on our normal backup cycle. Limited records we are legally required to keep (such as billing) are retained only as long as the law requires.

Because content is encrypted with keys only your family holds, deleting those keys already makes the content permanently unreadable — deletion is reinforced by the cryptography, not just by our policy.

13. Your rights

Subject to applicable law (including the GDPR), you have the right to access, correct, delete, and export your personal data, to object to or restrict certain processing, and to withdraw consent for optional features.

Export is built in. You can download everything — every photo, video, and word — in an easy-to-navigate format, so your memories are never locked in. That is our promise, and it is also your data-portability right in practice.

To exercise any right, contact us (section 17). You also have the right to complain to your local data protection authority.

14. Children & family content

Moments is designed for parents and adults to document a child's life; accounts are for adults (typically 16+, or the minimum age in your country). Much of the content is about children, which is exactly why the whole product is end-to-end encrypted and shared only with the people you choose.

We cannot see that content, and we never process it to profile, identify, or advertise to anyone, child or adult. Parents and guardians decide who is invited to a space and what each person can see, and can remove members or delete content at any time.

15. Security

Content is protected by industry-standard end-to-end encryption (AES-256), with keys that never leave your family's devices and no server-side key escrow. Connections are encrypted in transit, sign-in is passwordless, and each new device must be explicitly approved. The design and its honest limits are described in our security whitepaper.

16. Changes to this policy

We may update this policy as the product evolves. When we make material changes, we will update the date above and notify you in the app or by email before the changes take effect. Continued use after that means you accept the updated policy.

17. Contact us

For any privacy question, or to exercise your rights, contact us at privacy@momentsapp.eu.